Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

ANCHOR-CI could fix 20 years of broken government-industry collaboration

By: Greg Otto
23 July 2026 at 06:00

On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven-page notice in the Federal Register that could fundamentally change how the U.S. government works with private companies to protect critical infrastructure from cyber threats and natural disasters.

The notice, “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI),” details a new framework for CISA to build councils that let private partners advise the government on cybersecurity and critical infrastructure issues. This replaces the 20-year framework that the federal government used to work with critical infrastructure partners, formerly known as the Critical Infrastructure Partnership Advisory Council (CIPAC). For at least the next two years, ANCHOR-CI will dictate how the government and industry collaborate to protect critical infrastructure.

When former Homeland Security Secretary Kristi Noem terminated CIPAC in March of last year, Congress and private-sector partners objected immediately. The damage was real. The 16 sector-coordinating councils (SCCs), that brought together private partners from each critical infrastructure sector lost their legal mechanism to meet with the federal government. They could no longer advise and provide group consensus to their federal counterparts without triggering laws that CIPAC exempted. To be sure, CISA still had the Joint Cyber Defense Collaborative. Department of Energy had the Energy Threat Analysis Center. The National Security Agency had the Cybersecurity Collaboration Center. But none, however, replaced what the SCC ’s did: stand as steady forums where industry and government hashed out how to best assist critical infrastructure owners and operators.

Not that the SCCs were flawless. I worked with or alongside SCCs for more than a decade, most recently at CISA, and I am familiar with their shortcomings. SCC membership could be stagnant. The quality of recommendations to the government varied.  New members faced barriers based on each sector’s rules.

The core problem was how the model locked each sector in. DHS built SCCs in an era when critical infrastructure risks were looked at through a sector-specific lens: energy, transportation, water, communications, and so on. Today’s cyber threats jump across these sectors. A vulnerability in a cloud service provider or industrial software platform can harm hospitals, pipelines, manufacturers, water utilities, and financial institutions simultaneously.

To see why ANCHOR-CI works better than the CIPAC structure, we need to go back 20 years and understand what CIPAC was trying to do. Congress didn’t codify CIPAC into law. Instead, Congress authorized DHS to establish advisory committees exempt from the Federal Advisory Committee Act (FACA). This exemption let the federal government and SCCs hold private meetings without public notice, convene quickly without complying with FACA procedural requirements, pick members based on expertise rather than balanced public representation, and skip FACA’s public recordkeeping requirements. (But these FACA exemptions do not exempt records from the Freedom of Information Act, a common misconception.)

ANCHOR-CI carries this power forward. Crucially, ANCHOR-CI end the siloed, sector-by-sector approach by creating four types of councils: Critical Infrastructure Sector Councils; Cross-Sector Councils; Critical Infrastructure Industry Councils; and Regional Coordinating Councils.

Critical Infrastructure Sector Councils: These are basically the old SCCs, but with a change in power.  The CISA director now approves or removes any council member directly.

Cross-Sector Councils: These councils matter most. Specifically, they tackle “current and emerging threats, interdependencies, or other issues impacting multiple critical infrastructure sectors or industries.” Examples might include councils on countering unmanned aerial systems, AI threats, or reducing dependence on foreign supply chains. CISA could also revive and expand the Space Systems Critical Infrastructure Working Group.

Critical Infrastructure Industry Councils: Like cross-sector councils but designed for issues that span sectors in ways that don’t fit neatly into a given sector. After Volt Typhoon—a Chinese campaign that installed malicious malware in critical infrastructure—CISA could establish an Operational Technology council with original equipment manufacturers, software providers, and critical infrastructure owners to address and stop the threat.

Regional Coordinating Councils: CISA says these will help state and local governments tackle regional risks. What that means in practice is unclear. CISA could create 10 councils tied to 10 regional offices. Or it could create councils focused on real regional risks: preparing for the Cascadia subduction zone in the Pacific Northwest, droughts in the Southwest, or hurricane in the South and Mid-Atlantic.

In the end, like any policy, success hinges on how CISA carries it out. If CISA runs ANCHOR-CI thoughtfully and with transparency, it could become the biggest upgrade in of public-private cybersecurity collaboration work in two decades.

The post ANCHOR-CI could fix 20 years of broken government-industry collaboration appeared first on CyberScoop.

CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict

By: djohnson
5 May 2026 at 17:47

The Cybersecurity and Infrastructure Security Agency is urging critical infrastructure owners and operators to plan for delivering essential services under emergency conditions – potentially for months at a time.

The federal government’s top cybersecurity agency warned that state-sponsored hackers, particularly two Chinese groups known as Salt Typhoon and Volt Typhoon, continue to threaten critical sectors like electricity, water, and internet. 

The agency is now working with the private sector to protect operational technology – the systems that control the heavy machinery and equipment that powers most critical infrastructure – from attacks that enter through business IT systems or third-party vendor products.

The initiative  — known as CI Fortify – will include CISA conducting targeted technical assessments of critical infrastructure entities and aims to create plans that “allow for safe operations for weeks to months while isolated” from IT networks and third-party tools, according to the agency’s website.

Nick Andersen, CISA’s acting director, told reporters that the goal is “service delivery [that] can still reach critical infrastructure after the asset owner has disconnected with IT and OT, disconnected from third party vendors and service provider connections and disconnected from third party telecommunications equipment.”

Over the past two years, wars in Ukraine, Gaza, Iran and elsewhere have seen water plants, power substations, data centers and other critical infrastructure targeted by kinetic or cyberattacks.

Andersen said the agency has already begun engaging with some companies to pilot the assessments and expects that work to ramp up considerably as CISA hires additional staff in the coming months.

He declined to name the entities involved in the pilot program, but said they will focus on organizations that support national security, defense, public health and safety and economic continuity. He added that CISA’s assessments will vary from sector to sector depending on their unique needs.

“Water isn’t necessarily designed to prioritize specific customer needs outside of recovery periods, while energy and transportation have more immediate tradeoffs for selecting one load or one set of cargo over another,” Andersen said as an example.

One pillar of CISA’s strategy is isolation: essentially turning off all third-party and business network connections to an OT network when facing an emergency or unknown vulnerability.

Organizations also need to develop an internal plan for what acceptable service levels look like under those conditions and reach understandings with their critical customers, like U.S. military installations and lifeline services.

The second pillar, recovery, involves best practices for organizations: backing up files, documenting systems and having manual backups for operations when normal computer systems are down.

In conversations with cybersecurity specialists who focus on critical infrastructure and operational technology, it is widely assumed that China is not the only nation to have broadly compromised Americans critical infrastructure. That hacking groups tied to other nations have almost surely noticed and exploited the same basic vulnerabilities and hygiene issues found by the Typhoons.

Agencies like the FBI and Federal Communications Commission have touted efforts to purge Chinese hackers and work voluntarily with telecoms to harden their network security. But U.S. national security officials and cybersecurity defenders have consistently said both Salt Typhoon and Volt Typhoon remain active threats to U.S. critical infrastructure.

The post CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict appeared first on CyberScoop.

❌
❌