July 2, 2026 | Policy Brief
Washington Aims To Get Cyber Collaboration Back on Track
July 2, 2026 | Policy Brief
Washington Aims To Get Cyber Collaboration Back on Track
After more than a year without a formal framework for government-industry coordination on critical infrastructure cybersecurity, the Department of Homeland Security (DHS) finally unveiled the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure (ANCHOR-CI) on July 1.
ANCHOR-CI comes at a critical time, as Chinese cyber actors are seeking persistent access to U.S. critical infrastructure. U.S. officials have warned that these intrusions are intended not only for espionage but also to provide options to disrupt critical services during a future crisis. Trusted forums for rapidly exchanging threat information and coordinating responses are essential for thwarting the worst-case scenarios.
The Return of Government-Industry Cyber Coordination
For nearly two decades, the Critical Infrastructure Partnership Advisory Council (CIPAC) enabled critical infrastructure owners and operators to exchange sensitive information with the federal government about physical and cyber risks. The CIPAC structure provided exemptions from certain Federal Advisory Committee Act requirements, like those requiring meetings be open to the public, so that companies could candidly discuss cyber risks.
In March 2025, then-DHS Secretary Kristi Noem eliminated CIPAC, disrupting that trust. In January 2026, DHS finally confirmed the department was working on a replacement. However, without clear legal protections around information sharing, some critical infrastructure sectors curtailed their engagement with the federal government. The oil and natural gas sector, for example, halted sharing its cyber working group findings with the federal government until DHS could restore legal protections.
ANCHOR-CI Gives Government a Larger Role
While ANCHOR-CI preserves CIPAC’s advisory mission and legal protections, it also makes several important structural changes that could make the body nimbler.
Under CIPAC, industries selected their own representatives. Under ANCHOR-CI, federal agencies responsible for coordination with specific industries — known as sector risk management agencies (SRMAs) — can recommend members, but the director of the Cybersecurity and Infrastructure Security Agency (CISA) has final approval over participants in sector, regional, cross-sector, and industry councils. This shift could also allow CISA to convene stakeholders more quickly as cyberthreats emerge, rather than relying on lengthy industry consensus processes.
The top-down approach also addresses a problem that CISA’s cybersecurity advisory council of industry representatives hinted at back in 2022: the existing structure resulted in “variation in the collective capability of each sector to support national risk efforts.” The council urged greater focus on including stakeholders whose disruption would have disastrous effects on U.S. national security.
ANCHOR-CI also expands coordination beyond traditional sector-based councils by creating regional and cross-sector councils. These new forums recognize that cyber incidents frequently affect multiple sectors simultaneously and that infrastructure operators in a geographic area may face common physical security risks.
Implementation Will Determine ANCHOR-CI’s Success
ANCHOR-CI’s expanded authority also comes with greater responsibility to rebuild the trust that the previous DHS secretary squandered.
CISA should publish clear eligibility requirements, establish transparent processes, allow sectors to nominate representatives, and explain how membership decisions are made. Companies are more likely to share sensitive operational information when they understand and trust the selection process. CISA will also need to work with SRMAs that have existing relationships with sectors and unique sector-specific expertise.
DHS must also ensure that ANCHOR-CI’s new regional and cross-sector councils add value rather than bureaucracy. Many critical infrastructure operators already participate in national and regional coordination bodies through the Federal Emergency Management Agency, regional transmission organizations, and industry information-sharing organizations. Without clearly defined roles, additional councils risk creating duplicative meetings and activities for companies with limited personnel. DHS should clearly define each council’s purpose and consolidate existing efforts wherever possible.
As Chinese cyber actors target the systems that underpin America’s critical infrastructure, restoring formal public-private coordination is an important step forward. Whether ANCHOR-CI strengthens U.S. cyber resilience will depend on CISA’s ability to improve coordination. Otherwise, it risks replacing one framework with another but failing to address the underlying requirement for collaboration: trust.
Annie Fixler is the director of the Center on Cyber and Technology Innovation (CCTI) and a senior fellow at the Foundation for Defense of Democracies (FDD). Nidhi Ummettala is a CCTI intern. For more analysis from the authors and CCTI, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.