A narrow vote for a broadly popular law
On July 22, 2026, the House passed its version of the FY2027 National Defense Authorization Act by a bare 216-212 margin — a $1.15 trillion Pentagon policy bill that drew almost no Democratic support, mostly over unrelated objections to the chamber's silence on the president's use of military force, including the Iran war (The Record). Tucked inside it, though, was a provision with genuine bipartisan pedigree: the Widespread Information Management for the Welfare of Infrastructure and Government (WIMWIG) Act, which would reauthorize the Cybersecurity Information Sharing Act of 2015 (CISA 2015) for another decade.
WIMWIG — introduced as H.R. 5079 by House Homeland Security Chairman Andrew Garbarino (R-NY) with Rep. Michael McCaul (R-TX) — cleared the Homeland Security Committee last year and is formally described in its own text as legislation "to reauthorize the Cybersecurity Act of 2015, and for other purposes" (H.R. 5079, GovInfo). It rode into law-making relevance by attaching itself to the must-pass NDAA (H.R. 8800), the annual defense authorization vehicle (H.R. 8800, GovInfo).
Why the underlying law matters
CISA 2015 is not glamorous, but it is load-bearing. It gives companies legal cover — from antitrust liability, from certain lawsuits, from FOIA disclosure of what they share — to hand cyber threat indicators (malware signatures, malicious IP addresses, intrusion patterns) to the federal government and to each other in something close to real time. Take that shield away and general counsels tell security teams to stop sharing, because the legal risk no longer pencils out. That is not hypothetical: the statute's original ten-year sunset hit on September 30, 2025, and it lapsed. As The Record put it, the expiration "left federal officials in the dark about the full scope of digital threats to U.S. critical infrastructure" before Congress patched it with a stopgap.
That patch has itself become a pattern of whiplash. A November 2025 continuing resolution pushed the deadline to January 30, 2026; the Consolidated Appropriations Act, signed in early February 2026, pushed it again to September 30, 2026 (Davis Wright Tremaine). Each stopgap buys a few months of certainty and then evaporates. WIMWIG's pitch is to end that cycle with one clean decade-long fix, while adding modest updates — provisions for AI-flagged threat indicators and outreach to small and rural infrastructure operators — that the 2015 original didn't anticipate.
A rider aimed at the wrong target
The obstacle is Sen. Rand Paul (R-KY), who chairs the Senate Homeland Security Committee and has said he will block any CISA 2015 reauthorization unless it bars the Cybersecurity and Infrastructure Security Agency from doing any work to "counter online disinformation." The Senate's own NDAA draft, notably, carries no matching extension provision at all.
The demand rests on a real category error. CISA 2015 is a statute governing private-public threat-data sharing; it contains no disinformation mandate and never did. The agency people call "CISA" — the Cybersecurity and Infrastructure Security Agency — is a separate creation of the Cybersecurity and Infrastructure Security Agency Act of 2018, three years after the information-sharing law it shares an acronym with. Blocking the 2015 law's renewal would not touch whatever content-related work the agency does under its own 2018 authority; it would only strip liability protection from companies sharing malware signatures with the government.
That said, the underlying free-speech worry Paul is gesturing at is not manufactured from nothing. Government agencies leaning on platforms to moderate speech under the banner of "misinformation" was a live, contested question through the Missouri v. Murthy litigation, and a publication with our editorial priors — skeptical of government-coordinated speech pressure — should take that concern seriously on its own terms. It simply isn't the fight WIMWIG is having. Legislating disinformation-mission limits on a 2018 agency by holding hostage a 2015 information-sharing statute conflates two different laws and two different harms, and virtually guarantees neither gets a clean, well-drafted answer.
The steelman worth keeping
CISA 2015 also has an older set of critics worth taking seriously for different reasons. When the original bill passed, the Electronic Frontier Foundation opposed it as, in its words, "a surveillance bill in disguise," warning that its liability shield and broad definitions could let companies route more user data to intelligence and law-enforcement agencies than genuine threat response requires, without addressing the more mundane causes of breaches — unpatched systems, weak architecture, phishing (EFF). That critique argues for tighter scoping and real oversight of what gets shared and with whom — a legitimate proportionality question a ten-year reauthorization should confront directly, in daylight, rather than skate past inside a defense-spending megabill.
The proportionate path
Congress does not need to choose between cybersecurity and free speech here, because the two questions are not actually linked. The information-sharing shield has demonstrated value and a bipartisan committee record; it deserves an up-or-down vote on its own merits, ideally with the oversight tightening EFF-style critics have long asked for. The agency's disinformation posture, if lawmakers think it needs statutory guardrails, deserves its own hearings and its own bill. Bundling both into a single NDAA rider, as the House has now done, all but ensures the Senate spends the next two months relitigating a 2018 agency dispute on the back of a 2015 statute that has nothing to do with it — while the September 30, 2026 clock keeps running toward a third lapse.