Home Cybersecurity Breaking the 20-Year Gridlock in Government-Industry Collaboration

Breaking the 20-Year Gridlock in Government-Industry Collaboration

0
2

Key Takeaways

  • On July 1, CISA issued a Federal Register notice establishing the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR‑CI), which replaces the two‑decade‑old Critical Infrastructure Partnership Advisory Council (CIPAC) framework.
  • ANCHOR‑CI retains the FACA exemption that allowed private‑sector advisors to meet with the government without public notice, but it reorganizes collaboration into four council types: Sector, Cross‑Sector, Industry, and Regional Coordinating Councils.
  • The new structure is designed to break down siloed, sector‑specific approaches and better address cross‑sector cyber threats such as supply‑chain risks, AI‑enabled attacks, and unmanned aerial systems.
  • CISA directors now have direct authority to approve or remove members of Sector Councils, increasing federal oversight while still relying on industry expertise.
  • Success of ANCHOR‑CI will depend on thoughtful implementation, transparency, and the agency’s ability to balance rapid, expert‑driven advice with accountability to Congress and the public.

Background: The End of CIPAC and the Rise of ANCHOR‑CI
On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven‑page notice in the Federal Register titled “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR‑CI).” The notice formally replaces the Critical Infrastructure Partnership Advisory Council (CIPAC), a framework that had guided federal‑private collaboration on critical infrastructure for roughly 20 years. ANCHOR‑CI will govern how the government and industry work together to protect the nation’s essential services from cyber threats and natural disasters for at least the next two years. The shift follows the termination of CIPAC by former Homeland Security Secretary Kristi Noem in March 2023, a move that prompted immediate pushback from Congress and private‑sector partners who lost the legal mechanism that allowed sector‑specific advisory groups to convene and advise the government.


Why CIPAC Needed Replacement
When CIPAC was ended, the 16 sector‑coordinating councils (SCCs) that had brought together private partners from each critical infrastructure sector lost their statutory exemption from the Federal Advisory Committee Act (FACA). Without that exemption, the SCCs could no longer hold private meetings, issue consensus recommendations, or engage with federal counterparts without triggering FACA’s procedural requirements. Although CISA retained other collaborative bodies—such as the Joint Cyber Defense Collaborative, the Energy Threat Analysis Center, and the NSA’s Cybersecurity Collaboration Center—none replicated the SCCs’ role as standing forums where industry and government jointly shaped policy, shared threat intelligence, and developed mitigation strategies for sector‑specific risks.


Limitations of the Old Sector‑Centric Model
Having worked with or alongside SCCs for over a decade—most recently at CISA—I observed several structural shortcomings. Membership often became stagnant, with long‑standing representatives dominating discussions and limiting fresh perspectives. The quality of recommendations varied widely across sectors, sometimes reflecting the narrow interests of incumbent members rather than broader infrastructure resilience. New entrants faced barriers imposed by each sector’s internal governance rules, making it difficult to incorporate emerging technologies or diverse viewpoints. Most fundamentally, the SCC model locked collaboration into sector‑specific silos at a time when cyber threats routinely transcend those boundaries. A vulnerability in a cloud service provider, industrial control software, or supply‑chain component can simultaneously affect energy grids, water utilities, hospitals, financial institutions, and transportation networks, demanding a more integrated response.


Legal Foundation: FACA Exemptions Carried Forward
Congress never codified CIPAC into law; instead, it authorized the Department of Homeland Security (DHS) to establish advisory committees exempt from FACA. That exemption allowed the federal government and SCCs to convene quickly, hold non‑public meetings, select members based on expertise rather than balanced public representation, and avoid FACA’s record‑keeping and reporting burdens. Importantly, the FACA exemption does not shield records from the Freedom of Information Act (FOIA), a common misconception. ANCHOR‑CI expressly preserves this FACA‑exempt status, ensuring that CISA can continue to draw on private‑sector expertise without the procedural delays that would accompany a fully FACA‑compliant advisory process.


ANCHOR‑CI’s Four‑Tier Council Structure
To overcome the siloed nature of the SCCs, ANCHOR‑CI creates four distinct council types, each with a specific focus:

  1. Critical Infrastructure Sector Councils – These are the direct successors of the old SCCs, covering the traditional sectors (energy, transportation, water, communications, etc.). The key change is that the CISA director now holds explicit authority to approve or remove any council member, thereby increasing federal oversight while retaining sector‑level expertise.

  2. Cross‑Sector Councils – These bodies are tasked with addressing “current and emerging threats, interdependencies, or other issues impacting multiple critical infrastructure sectors or industries.” Examples include councils focused on countering unmanned aerial systems, mitigating AI‑driven threats, reducing reliance on foreign supply chains, or reviving the Space Systems Critical Infrastructure Working Group. By design, they cut across sector lines to tackle systemic risks.

  3. Critical Infrastructure Industry Councils – Similar to cross‑sector groups but organized around industry‑wide concerns that do not map neatly onto a single sector. For instance, after the Volt Typhoon campaign—where Chinese actors implanted malware in operational technology—CISA could establish an Operational Technology council comprising original equipment manufacturers, software providers, and infrastructure owners to develop coordinated defenses.

  4. Regional Coordinating Councils – Intended to bring state, local, tribal, and territorial governments into the collaborative process, these councils will address geographically specific hazards. CISA envisions either aligning them with its ten regional offices (e.g., Pacific Northwest, Southwest, Southeast) or forming ad hoc groups around particular risks such as the Cascadia subduction zone, prolonged droughts in the arid West, or hurricane preparedness along the Gulf and Atlantic coasts.

Implementation Will Determine Success
The effectiveness of ANCHOR‑CI hinges on how CISA executes the new framework. If the agency leverages the FACA exemption to convene experts swiftly, maintains transparency about council activities and outcomes, and actively seeks diverse representation—including smaller firms, academic researchers, and civil‑society stakeholders—the model could mark the most significant upgrade to public‑private cybersecurity collaboration in two decades. Conversely, if membership becomes overly centralized, if cross‑sector councils lack clear mandates or resources, or if regional councils remain ill‑defined, the initiative risk reproducing the very shortcomings it seeks to fix. Ongoing congressional oversight, periodic public reporting, and mechanisms for stakeholder feedback will be essential to ensure that ANCHOR‑CI delivers resilient, adaptive protection for the nation’s critical infrastructure in an era of increasingly interconnected threats.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here