showing great promise. ISAOs had their start in February 2015, when US President Barack Obama issued Executive Order 13691 (Promoting Private Sector Cybersecurity Information Sharing) to 1 encourage the creation of these organizations. Since then, numerous entities in the public and private sectors have formed ISAOs or have announced plans to do so. Examples include the Commonwealth of Virginia ISAO (see sidebar), The Legal Services ISAO, Retail Industry ISAO, The National Credit Union ISAO, and the Maritime & Port Security Information Sharing and Analysis Organization, among others.2 1 Whitehouse.gov, Executive Order — Promoting Private Sector Cybersecurity Information Sharing, February 13, 2015 2 The ISAO Standards Organization, Information Sharing Groups, accessed October 18, 2016. Impact of collaboration with external organizations 50% 45% 42% 40% 39% Share with & Share with & Improved Share with & Share with & receive more receive more threat receive more receive more actionable actionable intelligence & actionable actionable information information awareness information information from industry from ISACs from ISAOs from peers government entities Source: PwC, CIO and CSO, The Global State of Information Security® Survey 2017, October 5, 2016 18 Key findings from The Global State of Information Security® Survey 2017 © 2016 PwC

Toward new possibilities in threat management - Page 19 Toward new possibilities in threat management Page 18 Page 20