The US Department of Homeland Security has formally established a new framework for cooperation between the federal government and the organisations that operate the country’s essential infrastructure.
Launched on 1 July 2026 and managed by the Cybersecurity and Infrastructure Security Agency, the Alliance of National Councils for Homeland Operational Resilience - Critical Infrastructure, or ANCHOR-CI, will bring together infrastructure operators, government agencies, law-enforcement bodies, intelligence organisations and cybersecurity specialists.
Its stated purpose is to provide practical and timely recommendations to the Secretary of Homeland Security through the CISA Director, improve cooperation with Sector Risk Management Agencies and create forums in which government and industry can discuss threats, vulnerabilities and national resilience.
The establishment of ANCHOR-CI repairs a major gap created in March 2025, when DHS terminated the Critical Infrastructure Partnership Advisory Council, known as CIPAC. But the new system is not simply a restoration of the old council under another name.
ANCHOR-CI broadens the organisational model, gives CISA more direct control over participation and places greater emphasis on cross-sector, regional and industry-specific risks. These changes may make the system more responsive, but they also raise questions about representation, independence and the long-term stability of public-private cooperation.
A partnership interrupted after almost two decades
CIPAC was created in 2006 to support implementation of the US critical infrastructure protection framework. It enabled representatives of private infrastructure operators to work with federal, state and local government bodies through Sector Coordinating Councils and Government Coordinating Councils.
The model recognised a basic reality of national cybersecurity: the government possesses intelligence, diplomatic and law-enforcement capabilities, while private companies own and operate much of the infrastructure that an adversary would attempt to disrupt. Neither side has a complete picture by itself.
Government agencies may detect a foreign campaign without understanding the operational consequences for a particular industrial system. An electricity provider, bank, telecommunications company or water utility may identify suspicious activity without knowing that several other sectors are seeing the same pattern.
CIPAC created a recognised environment in which these perspectives could be combined. Its work included cybersecurity planning, information sharing, infrastructure exercises, development of sector strategies and discussions involving sensitive or classified information.
The council’s charter had been renewed for another two years in September 2024. Only months later, DHS terminated it together with several other advisory bodies under a government-wide initiative intended to reduce federal bureaucracy. The termination became effective on 7 March 2025.
The decision surprised many infrastructure operators and industry associations. Companies were concerned that removing the formal partnership mechanism would weaken trusted communication channels that had taken years to develop.
Some cross-sector calls and relationships continued informally, but the absence of an official framework created uncertainty about how sensitive information could be exchanged and how industry recommendations would reach senior government decision-makers.
Not every participant regarded CIPAC as effective. Some industry representatives argued that it had become bureaucratic and was not producing enough measurable security improvement. But even many critics agreed that the underlying partnership function remained necessary.
ANCHOR-CI is DHS’s attempt to restore that function while redesigning how it operates.
Four types of councils
ANCHOR-CI is an umbrella framework rather than a single committee. It can contain four types of councils.
Critical Infrastructure Sector Councils
These councils will represent the nationally designated critical infrastructure sectors. They can include the existing private-sector Sector Coordinating Councils and their government counterparts.
The relevant Sector Risk Management Agency will review proposed membership and make recommendations to the CISA Director. This retains the sector-based model previously used for areas such as energy, financial services, communications, healthcare, transportation, water and critical manufacturing.
Cross-Sector Councils
Cross-sector councils can be created to address risks that affect several sectors simultaneously.
This is one of the most strategically important parts of the new framework. Modern infrastructure incidents rarely remain within a single administrative category. A disruption affecting cloud services, telecommunications, electricity or identity infrastructure can rapidly affect banking, transport, healthcare and government operations.
The councils could be used to address common vulnerabilities, major supply-chain risks, coordinated cyber campaigns, artificial intelligence threats or other problems that cannot be managed effectively by one sector alone.
Critical Infrastructure Industry Councils
ANCHOR-CI also allows councils to be formed for industries that extend across several existing sectors or do not fit neatly into the established classification.
This could become relevant for areas such as data centres, cloud infrastructure, space-based services, managed service providers, digital identity platforms and other technology ecosystems whose failure could affect many traditional infrastructure sectors.
An industry may recommend that a council be established, but the CISA Director retains authority to approve or appoint its participants.
Regional Coordinating Councils
Regional councils are intended to provide a more local picture of infrastructure risks and dependencies.
The Federal Register notice specifically calls for representation of rural infrastructure entities, which are often less visible in national-level cybersecurity programmes despite operating essential energy, water, transportation, healthcare and communications services.
The regional structure also reflects the administration’s broader policy that resilience should be owned and managed more actively at state and local levels, with federal agencies providing accessible support rather than attempting to control every preparedness activity from Washington.
More direct control for CISA
The most significant organisational difference between the old and new systems is the authority given to the CISA Director. Under ANCHOR-CI, the Director must approve member entities, individual representatives and participating subject-matter experts. Members serve at the Director’s pleasure, and additional participants can be appointed according to the needs of the federal government.
Sector Risk Management Agencies can recommend participants for sector councils, and industries can propose representatives for industry councils. Final approval, however, remains with CISA.
Under the previous model, private-sector coordinating councils generally had greater autonomy to organise themselves and select their own representatives. Former CISA official Bob Kolasky described the new structure as giving CISA greater authority over who participates and how the partnership is directed.
Greater central control could allow CISA to correct gaps in representation, remove inactive members and bring specialised expertise into discussions quickly. It could also prevent councils from being dominated by a small group of large companies or established trade associations.
At the same time, it creates a governance risk.
Infrastructure operators must be able to challenge government assumptions and communicate uncomfortable operational realities. If participation is perceived as dependent on maintaining a favourable relationship with current agency leadership, companies may become less willing to provide independent advice.
The credibility of ANCHOR-CI will therefore depend on whether CISA adopts transparent and consistent membership criteria, even though many of the council’s activities will not be public.
The establishment notice calls for diverse representation based on expertise, company size, geography and other relevant factors. It nevertheless places particular emphasis on entities of national significance or consequence.
This balance will require careful management. Nationally significant operators must be represented, but smaller organisations often have weaker security capabilities and may provide the clearest evidence of systemic vulnerabilities.
Confidentiality is necessary, but should not be misunderstood
ANCHOR-CI is exempt from the Federal Advisory Committee Act, the law that normally imposes transparency, public-meeting and administrative requirements on federal advisory bodies.
DHS justified the exemption by referring to the sensitive nature of operational risks, vulnerability assessments and whole-of-government cooperation with private infrastructure operators. Participants may also be required to sign non-disclosure agreements.
Some early reporting described this exemption as a major difference between ANCHOR-CI and CIPAC. In fact, CIPAC was also exempt from the same law under the same statutory authority. The ability to hold protected discussions outside normal public-meeting requirements is therefore largely a continuation of the previous model rather than a new departure.
Confidentiality is important. Companies will not disclose exploitable vulnerabilities, architectural weaknesses, continuity limitations or classified threat information in a fully public meeting.
But exemption from public-meeting rules and the use of non-disclosure agreements do not automatically resolve every legal concern surrounding information sharing.
Companies will still need clarity about how information may be used, whether it could be provided to regulators or law-enforcement agencies, how commercially sensitive material will be protected and what protections apply to incident, vulnerability and operational data. Trust depends not only on keeping meetings private. It depends on predictable rules governing what happens to information after it has been shared.
ANCHOR-CI is advisory, not regulatory
The new framework does not give CISA operational control over privately owned infrastructure. Its duties are expressly advisory. Councils may submit advice, recommendations and reports, but they do not issue binding orders to companies and do not replace the regulatory authorities responsible for specific sectors.
ANCHOR-CI also does not replace Information Sharing and Analysis Centers, sector associations, emergency coordination bodies or direct relationships between companies and agencies such as the FBI. Those organisations perform different functions. An ISAC may distribute operational threat intelligence among members, while an ANCHOR-CI council may make recommendations concerning a common national vulnerability, an interdependency between sectors or a government policy that is obstructing resilience.
The framework should also be distinguished from mandatory cyber incident reporting. ANCHOR-CI provides a cooperation mechanism; it is not itself an incident-reporting regulation.
This distinction matters because creating a council does not automatically improve cybersecurity. The framework will have value only if its discussions result in faster warnings, coordinated mitigation, realistic exercises, practical technical assistance or changes to policy and investment.
From information sharing to collective action
The wider US resilience policy now calls for government to move beyond information sharing toward action. Executive Order 14239 directed federal agencies to replace broad all-hazards planning with a more risk-informed approach, review national critical infrastructure policy and strengthen the role of state and local authorities. It also called for the development of a National Risk Register to identify and quantify risks to infrastructure and related systems. ANCHOR-CI appears designed to support that direction.
Cross-sector councils could examine how the failure of one provider would affect several essential services. Regional councils could identify dependencies that are not visible from Washington. Industry councils could bring emerging infrastructure categories into national planning before they are formally assigned to an established sector.
But moving from sharing to action requires more than producing recommendations. Councils will need to identify responsible parties, define expected outcomes and track whether agreed risk-reduction measures are implemented. Otherwise, ANCHOR-CI could reproduce one of the common weaknesses of advisory structures: valuable discussion without sufficient operational follow-through.
The official notice states that recommendations should be specific, proactive, actionable, timely and strategic. That language creates an appropriate expectation against which the programme can be assessed.
The relaunch comes as critical infrastructure operators face increasingly interconnected cyber and physical risks.
Nation-state groups are conducting long-term reconnaissance and pre-positioning inside infrastructure networks. Ransomware groups continue to target organisations that cannot tolerate extended downtime. Artificial intelligence is reducing the cost of discovering and exploiting vulnerabilities. Cloud concentration and software supply chains create common points of failure across many industries.
At the same time, operational technology remains difficult to update. Many industrial systems were designed for long service lives and high availability rather than continuous exposure to hostile networks.
US infrastructure cybersecurity also remains fragmented. Some sectors operate under detailed mandatory requirements, while others rely primarily on voluntary guidance, contractual controls and incident reporting.
These conditions make structured cooperation essential.
A government agency cannot independently map every dependency between a telecommunications provider, regional electricity distributor, hospital network, cloud platform and local water utility. Operators themselves often understand only their direct suppliers and customers, not the wider national consequences of a shared failure.
ANCHOR-CI’s strongest potential contribution is therefore not simply the distribution of threat indicators. It is the creation of a common operational picture across organisations that normally manage risk separately.
What remains unresolved
The establishment notice defines the structure but leaves important implementation questions open. It does not yet explain in detail how CISA will select the initial participants, how existing sector councils will transition into the framework or how frequently the different councils will meet.
It remains unclear how recommendations will be prioritised, who will track implementation and how the effectiveness of the framework will be measured.
The notice also does not provide a complete operational model for exchanging classified information or handling highly sensitive company data. Additional charters, bylaws and procedures will be required.
Continuity is another concern. ANCHOR-CI is established for two years. The Secretary of Homeland Security may extend it for additional two-year periods, but the structure is still dependent on administrative renewal rather than permanent statutory authorisation.
The abrupt termination of CIPAC showed that trust-based security mechanisms can be damaged quickly when they depend too heavily on changing executive priorities.
Industry groups have broadly welcomed the restoration of a formal partnership. BSA described the framework as an opportunity to improve trusted government-industry collaboration and enable faster, more coordinated responses. Other stakeholders have expressed concern about whether ANCHOR-CI will reproduce CIPAC’s practical benefits and whether the new membership model will provide sufficiently independent industry representation.
Organisations should not treat ANCHOR-CI as an initiative relevant only to government-relations teams
Critical infrastructure operators should identify which sector, regional and industry councils are relevant to their operations and determine how their organisation is represented through sector associations or coordinating councils.
They should also define in advance what information can be shared during a significant threat or incident. Legal, cybersecurity, operational technology, communications and executive teams should agree on escalation procedures before urgent government requests arrive.
Participation should focus on operational value. Companies should bring concrete dependencies, recovery constraints, supplier risks and policy obstacles into the discussion rather than limiting engagement to general statements about threat trends.
They should also examine cross-sector exposure. An organisation may be well represented within its own industry but still depend on electricity, communications, cloud, transport and third-party technology providers that are discussed in other councils.
Finally, operators should expect reciprocity. Public-private cooperation cannot consist only of companies sending information to government. Government partners must provide timely, contextualised intelligence and communicate what action organisations should take.
Rebuilding the structure is only the first step
ANCHOR-CI restores an essential part of the US critical infrastructure security model. Its four-council structure acknowledges that national risks are simultaneously sector-specific, cross-sector, regional and increasingly shaped by industries that do not fit established classifications.
The framework also gives CISA the authority to broaden participation and direct attention toward emerging threats more quickly.
But institutional design alone will not rebuild the trust lost when CIPAC was terminated. That will require stable membership rules, meaningful protection of shared information, useful government intelligence, measurable follow-through and a willingness to include operators whose views may not always align with federal policy.
The United States has recreated a formal table at which government and infrastructure owners can meet. The strategic question is whether the people around that table will be able to act together before the next major disruption.
