ANCHOR-CI: Enhancing Partnerships and Intelligence to Protect Critical Infrastructure

0
15

Key Takeaways

  • The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has launched the Alliance of National Councils for Homeland Operational Resilience–Critical Infrastructure (ANCHOR‑CI), replacing the former Critical Infrastructure Partnership Advisory Council (CIPAC).
  • ANCHOR‑CI is designed to operate for an initial two‑year period, with possible extension under Section 871 of the Homeland Security Act, and provides a legal framework for government‑industry collaboration on critical‑infrastructure cybersecurity.
  • The new framework creates four types of councils—sector, cross‑sector, industry, and regional coordinating councils—drawing members from owners/operators, government agencies, cybersecurity‑focused organizations, and other private‑sector entities.
  • ANCHOR‑CI retains the information‑sharing protections of CIPAC but does not extend liability shielding for participants, a notable change from its predecessor.
  • Governance, funding, and administrative support will be housed within CISA, with close coordination from the HHS Office of Cybersecurity and Infrastructure Protection to elevate Healthcare and Public Health (HPH) sector priorities.
  • By enabling open, candid discussions while shielding sensitive deliberations from the Federal Advisory Committee Act, ANCHOR‑CI aims to strengthen national resilience across interdependent critical‑infrastructure sectors such as water, communications, and energy.

Background and Motivation for ANCHOR‑CI
The Department of Homeland Security (DHS) announced the formation of the Alliance of National Councils for Homeland Operational Resilience–Critical Infrastructure (ANCHOR‑CI) on July 3, 2026. This initiative replaces the Critical Infrastructure Partnership Advisory Council (CIPAC), which had facilitated public‑private information exchange on physical and cyber risks since its establishment in March 2006. CIPAC was discontinued by then‑DHS Secretary Kristi Noem in March 2025, leaving a vacuum in formal government‑industry coordination for more than a year. During that gap, several critical‑infrastructure sectors reduced or halted the sharing of cybersecurity data with federal agencies, underscoring the need for a renewed, legally backed partnership framework.

Legal Basis and Duration
ANCHOR‑CI operates under the authority granted by Section 871 of the Homeland Security Act, which permits the DHS Secretary to establish advisory bodies aimed at enhancing homeland security resilience. The alliance is slated for an initial two‑year term, with the possibility of extension by the DHS Secretary should the program prove effective. This statutory foundation provides ANCHOR‑CI with the same legal protections that CIPAC enjoyed, allowing participants to exchange sensitive information without fear of inadvertent disclosure under standard freedom‑of‑information provisions.

Organizational Structure: Four Council Types
To broaden participation and address diverse challenges, ANCHOR‑CI establishes four distinct council categories:

  1. Critical Infrastructure Sector Councils – Focused on individual sectors such as energy, transportation, and communications.
  2. Cross‑Sector Councils – Designed to tackle interdependencies that span multiple sectors, facilitating coordinated responses to cascading threats.
  3. Critical Infrastructure Industry Councils – Comprised of trade associations and private‑sector entities that represent specific industries within the critical‑infrastructure landscape.
  4. Regional Coordinating Councils – Geographically oriented bodies that align state, local, tribal, and territorial efforts with national objectives.

Each council type is tasked with delivering strategic and actionable recommendations that support a unified national approach to strengthening critical‑infrastructure cybersecurity.

Membership Composition and Recruitment Process
ANCHOR‑CI councils will draw members from four primary groups:

  • Critical‑infrastructure owners, operators, and their trade associations – Ensuring that those who operate essential services have a direct voice.
  • Federal, state, local, tribal, and territorial government agencies – Providing regulatory, policy, and operational perspectives.
  • Organizations with direct responsibility for cybersecurity and infrastructure resilience – Bringing specialized technical expertise to the table.
  • Other private‑sector entities – Including technology providers, consultants, and academia that can contribute innovative solutions.

Under the new arrangement, the Cybersecurity and Infrastructure Security Agency (CISA) will vet and approve proposed council members, retaining the authority to appoint additional participants as needed. This represents a shift from CIPAC, where private‑sector councils themselves selected their representatives, thereby centralizing oversight while still striving for broad representation.

Information Sharing Protections and Limitations
ANCHOR‑CI preserves the core benefit of CIPAC: a legal shield that permits the exchange of sensitive, potentially classified information among members without triggering inadvertent public disclosure. Participants can discuss threats, vulnerabilities, and incident‑response strategies in a protected environment. However, a notable departure from CIPAC is the absence of liability protection for council members. Under CIPAC, executives could engage in frank discussions of incidents without exposing themselves to antitrust or regulatory claims. ANCHOR‑CI does not extend this safeguard, meaning participants must rely on existing corporate policies and legal counsel to mitigate risk when sharing detailed operational data.

Governance, Funding, and Administrative Support
The alliance will be governed jointly by DHS and CISA, with CISA serving as the host organization responsible for providing funding, staffing, and logistical support. This centralization aims to ensure consistency in procedures, reporting, and accountability across all council types. Additionally, the Department of Health and Human Services (HHS) Office of Cybersecurity and Infrastructure Protection (CIP) will collaborate closely with DHS and CISA to prioritize the Healthcare and Public Health (HPH) sector’s unique challenges, helping to elevate its concerns within the broader national resilience agenda.

Impact on the Healthcare and Public Health Sector
Given the increasing frequency of ransomware attacks and supply‑chain disruptions affecting hospitals and public‑health agencies, the HPH sector stands to benefit significantly from ANCHOR‑CI’s structure. By integrating HPH representatives into sector‑specific, cross‑sector, and regional councils, the framework seeks to align cybersecurity initiatives with clinical‑operations needs, improve threat intelligence sharing, and foster joint exercise planning. The HHS CIP office’s involvement ensures that sector‑specific guidance, regulatory considerations, and resource allocation are factored into the alliance’s deliberations.

Facilitating Open Dialogue While Protecting Sensitive Discussions
ANCHOR‑CI is expressly exempted from the Federal Advisory Committee Act (FACA), which traditionally requires advisory committees to conduct meetings in public and maintain detailed records. This exemption allows the alliance to hold closed, confidential sessions where members can discuss classified threat intelligence, vulnerability assessments, and incident‑response tactics without the obligation to disclose proceedings publicly. At the same time, the framework permits select meetings to be opened to stakeholders or the public when appropriate, thereby balancing transparency with the necessity of protecting sensitive operational details.

Strengthening Cross‑Sector Resilience
One of ANCHOR‑CI’s core objectives is to enhance resilience across interdependent critical‑infrastructure sectors. For example, a cyber incident affecting the energy grid could have cascading effects on water treatment facilities, telecommunications, and healthcare services. By convening cross‑sector councils, the alliance aims to develop joint risk‑assessment methodologies, establish shared situational‑awareness platforms, and create coordinated response playbooks that mitigate the likelihood of domino‑effect failures. Regional councils further tailor these strategies to local geographic realities, accounting for varying threat landscapes, resource availability, and jurisdictional authorities.

Challenges and Considerations Moving Forward
While ANCHOR‑CI addresses many of the gaps left by CIPAC’s dissolution, several challenges warrant attention. The removal of liability protection may deter some executives from participating fully in candid discussions, potentially limiting the depth of information shared. Ensuring that the vetting process for council members remains transparent and inclusive will be critical to maintaining trust among private‑sector partners. Additionally, the alliance must demonstrate tangible outcomes—such as reduced incident response times, improved information‑sharing metrics, and measurable enhancements in sector‑specific cybersecurity postures—to justify any potential extension beyond the initial two‑year period.

Conclusion: A Renewed Commitment to Public‑Private Partnership
The launch of ANCHOR‑CI marks a deliberate effort by DHS and CISA to rebuild a robust, legally supported platform for government‑industry collaboration on critical‑infrastructure cybersecurity. By structuring participation around sector, cross‑sector, industry, and regional councils, and by retaining key information‑sharing protections while adjusting liability provisions, the alliance seeks to foster a more resilient national infrastructure. Continued engagement from the HPH sector, alongside energy, water, communications, and other vital industries, will be essential to achieving the shared goal of safeguarding the systems that underpin American society against evolving cyber and physical threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here