What is an Information Sharing and Analysis Center (ISAC)?
An Information Sharing and Analysis Center (ISAC) is a nonprofit, member-driven organization that serves as a central, trusted hub for gathering, analyzing, and sharing cyber and physical threat information within a specific critical infrastructure sector, such as finance, healthcare, energy, or transportation. ISACs enable two-way information sharing between the private sector and government: they collect threat data from their members and from sources like CISA, enrich and analyze it, and disseminate actionable intelligence back to members through secure channels. The guiding principle is collective defense: a threat identified by one organization can protect an entire sector. First established in the United States in 1999 following Presidential Decision Directive 63 (PDD-63), ISACs now operate across dozens of sectors and increasingly around the world.
Key takeaways
- Sector-specific and member-driven. Each ISAC serves one critical infrastructure sector, and membership is typically restricted to verified organizations in that sector.
- Built for collective defense. A threat seen by one member becomes protection for all, turning isolated incidents into sector-wide situational awareness.
- Two-way sharing is the model. ISACs gather intelligence from members and government, analyze and enrich it, then disseminate actionable output back to members.
- Born from PDD-63 (1998). The US government asked each critical infrastructure sector to create one; FS-ISAC was the first, in 1999.
- Standards make sharing work. ISACs rely on the Traffic Light Protocol (TLP) for handling rules and STIX/TAXII for machine-readable, automated exchange.
Why ISACs exist
No single organization can keep pace with the modern threat landscape alone. Attackers reuse the same tools, infrastructure, and techniques against many targets in the same industry, which means an attack on one bank, hospital, or utility is often a preview of attacks to come against its peers.
ISACs turn that dynamic to defenders' advantage. By pooling intelligence within a sector, members gain early warning of campaigns already hitting similar organizations, access to analysis tailored to their specific risks, and a trusted forum to discuss incidents without fear of competitive or legal fallout. Even direct competitors cooperate here, because when one member is under attack, it's in everyone's interest to share what they know. That collective posture is stronger and faster than anything a single organization can build alone: ISACs have a track record of disseminating actionable information more quickly than formal government advisories.
A brief history of ISACs
The concept traces to the late 1990s, when the President's Commission on Critical Infrastructure Protection (1997) highlighted how dependent the United States had become on interconnected digital systems. In response, President Clinton signed PDD-63 on May 22, 1998, asking each critical infrastructure sector to establish an organization to share information about threats and vulnerabilities. The Financial Services ISAC (FS-ISAC) was the first to form, in 1999, followed by the IT-ISAC in 2000.
After the September 11, 2001 attacks, the mission of ISACs expanded from cyber to include physical threats. Subsequent policy reinforced the model: the Homeland Security Act of 2002, Homeland Security Presidential Directive 7 (HSPD-7) in 2003 extending PDD-63, and Executive Order 13636 in 2013, which called for faster, automated sharing between government and critical infrastructure operators. Also in 2003, the National Council of ISACs (NCI) formed to coordinate across sectors; it comprises more than two dozen member organizations today.
How an ISAC works
An ISAC operates as a continuous security loop with four stages:
- Collection: members securely submit data on observed threats, indicators of compromise (IoCs), tactics, techniques and procedures (TTPs), and vulnerabilities, often anonymously, through secure channels.
- Analysis and enrichment: dedicated ISAC analysts with deep sector knowledge correlate submissions against each other, against government feeds such as CISA's Automated Indicator Sharing (AIS), and against open-source intelligence. They remove identifying details and add context, including mapping TTPs to MITRE ATT&CK.
- Dissemination: finished intelligence is distributed under the Traffic Light Protocol (TLP), which sets redistribution limits, via secure portals, alerts, and machine-readable formats like STIX and TAXII that plug directly into members' security tools.
- Feedback: members receive sector-wide situational awareness reports and, in more advanced ISACs, analyst-to-analyst communication during active incidents, feeding the next cycle.
Core functions and services of an ISAC
- Threat intelligence sharing. Timely, relevant, contextualized intelligence tailored to the sector's specific risks.
- Early warning alerts. Immediate notifications about active threats and IOCs so members can harden defenses proactively.
- Analysis and situational awareness. Identification of trends, patterns, and emerging threats across the sector.
- Incident response coordination. During a major attack, ISACs help coordinate the collective response and recovery.
- Best practices and benchmarks. Sector-specific guidelines, frameworks, and assessment tools developed from member input.
- Education and training. Workshops, webinars, tabletop exercises, and annual meetings to raise the whole sector's maturity.
- Regulatory and compliance support. Guidance that helps members align with sector frameworks; membership is often cited as evidence of an active threat intelligence program.
Examples of ISACs by sector
There are dozens of ISACs. A representative sample shows the range:
ISAC vs ISAO vs CERT/CSIRT
ISACs are easy to confuse with adjacent bodies, but the distinctions matter.
An ISAO (Information Sharing and Analysis Organization) is a broader, more flexible category introduced later and codified in the Homeland Security Act. Any group can form an ISAO around any shared interest, not just a government-designated critical infrastructure sector, so every ISAC is effectively an ISAO, but not every ISAO is a sector-based ISAC.
A CERT or CSIRT (Computer Emergency Response Team / Computer Security Incident Response Team) is an operational team that responds to and manages security incidents for a specific organization or constituency, whereas an ISAC is a sharing community for an entire sector. The two are complementary: many organizations belong to an ISAC for intelligence and run or rely on a CSIRT for response.
Terminology also varies internationally. In France, for example, sectoral CSIRTs play a role similar to ISACs, providing a platform for organizations in the same sector to share attack intelligence.
Benefits of joining an ISAC
For a security team, membership converts the wider sector into an early-warning system. Members gain access to actionable, sector-specific cyber threat intelligence (CTI) they couldn't produce alone, often enriched and ready to load directly into their tools.
Beyond the intelligence itself, membership means peer collaboration in a trusted, legally comfortable environment, and early alerts that let teams harden defenses before a campaign reaches them. Participation supports regulatory and compliance narratives, strengthens incident response through shared playbooks and coordination, and raises team capability through training. More than anything, it shifts an organization from defending in isolation to defending as part of a community. Against well-resourced, persistent adversaries, that's a decisive advantage.
Challenges and considerations
ISACs are valuable, but joining one isn't a turnkey fix. Many charge membership fees and are historically dominated by large, well-resourced organizations, which can leave smaller entities with different priorities underserved. The value a member extracts depends heavily on participation: an organization that only consumes alerts gets far less than one that actively contributes and engages.
Intelligence also has to be operationalized. Raw indicators and reports deliver value only when they're ingested, correlated with internal telemetry, and turned into detection and response actions. And sharing itself requires trust and discipline around handling rules (hence TLP) to protect sensitive information. These are the practical reasons ISAC membership works best when paired with the tooling and processes to act on what is shared.
Expert insight: Sharing only pays off when you can operationalize it
Here's the point that gets lost between the policy history and the org charts. An ISAC produces intelligence; it doesn't defend your network. The value of membership is realized only at the moment a sector alert becomes a detection rule firing in your own environment, or a shared indicator gets retro-hunted across your last ninety days of logs. Plenty of organizations join an ISAC, receive a steady stream of high-quality intelligence, and then let most of it sit in an inbox because they lack the pipeline to turn it into action. Collective defense is real, but only for members who can operationalize what they receive.
This is where Sekoia's design philosophy lines up naturally with the ISAC model. Sekoia has long argued, through its own work with sectoral CSIRTs in France and the wider European community, that sharing threat information across an ecosystem is in every organization's direct interest, because attacks rarely target a single isolated player. Sekoia Intelligence produces and consumes CTI in native STIX 2.1, the same standard ISACs use, and supports TAXII for automated exchange, so intelligence from an ISAC flows directly into detection rather than a PDF. On the Sekoia SOC platform, shared indicators and TTPs are correlated against your telemetry through 300-plus integrations, matched to roughly 1,000 detection rules mapped to MITRE ATT&CK in Sekoia Defend, and every new IOC is automatically retro-hunted across historical events. Because Sekoia is a European vendor with a data-sovereignty posture and a track record serving public-sector and sector-level bodies, it's a natural fit for the ISACs, national CERTs, and regulated operators for whom sovereignty isn't optional.
The takeaway: join the ISAC for the intelligence, but make sure you have the platform to turn that intelligence into detection and response.
Frequently asked questions
What is an Information Sharing and Analysis Center (ISAC)?
An ISAC is a nonprofit, member-driven organization that acts as a central, trusted hub for collecting, analyzing, and sharing cyber and physical threat information within a specific critical infrastructure sector. It enables two-way sharing between the private sector and government so that a threat identified by one member helps protect the whole sector.
What does ISAC stand for?
ISAC stands for Information Sharing and Analysis Center. The name captures its two core activities: sharing threat information among members and across the public-private divide, and analyzing that information to produce actionable, sector-specific intelligence.
When and why were ISACs created?
ISACs were created following US Presidential Decision Directive 63 (PDD-63), signed in 1998, which asked each critical infrastructure sector to form a sector-specific organization to share threat and vulnerability information. The first, FS-ISAC, launched in 1999. After the September 11, 2001 attacks, their mission expanded to include physical as well as cyber threats.
How does an ISAC work?
An ISAC runs a continuous loop: members submit threat data, often anonymously; ISAC analysts correlate and enrich it against member reports, government feeds, and open sources, adding context like MITRE ATT&CK mapping; finished intelligence is disseminated under the Traffic Light Protocol via portals, alerts, and STIX/TAXII feeds; and members feed observations back in, driving the next cycle.
What are some examples of ISACs?
Prominent examples include FS-ISAC (financial services, the first ISAC), H-ISAC (healthcare), E-ISAC (electricity, tied to NERC), MS-ISAC (US state, local, tribal, and territorial governments, supported by CISA), and IT-ISAC (information technology). Newer ones like Auto-ISAC, Aviation ISAC, and RH-ISAC (retail and hospitality) show the model expanding into more sectors.