See It Once, Stop It Everywhere
Cyber Defense Magazine, Monday, July 13th, 2026
Fortra's Bob Erdman makes the case for disciplined threat intelligence sharing through ISACs, peers and law enforcement.
No security team can see everything, so structured information sharing lets organizations augment their own visibility with intelligence from peers.
Sharing happens CISO to CISO, between companies and law enforcement agencies, and through industry ISACs, each governed by codes of conduct, NDAs and the Traffic Light Protocol that defines how far information may travel.
Useful sharing is actionable and relevant to the group, such as fraud accounts among financial institutions or impersonation phishing in aviation. Uncertainty around renewal of the US Cybersecurity Information Sharing Act's legal protections may narrow sharing to the most trusted partners.
Recommended steps: join a relevant ISAC, adopt TLP classification, and build relationships with peers and LEAs for rapid escalation.