On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven-page notice in the Federal Register that could fundamentally change how the U.S. government works with private companies to protect critical infrastructure from cyber threats and natural disasters.
The notice, “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI),” details a new framework for CISA to build councils that let private partners advise the government on cybersecurity and critical infrastructure issues. This replaces the 20-year framework that the federal government used to work with critical infrastructure partners, formerly known as the Critical Infrastructure Partnership Advisory Council (CIPAC). For at least the next two years, ANCHOR-CI will dictate how the government and industry collaborate to protect critical infrastructure.
When former Homeland Security Secretary Kristi Noem terminated CIPAC in March of last year, Congress and private-sector partners objected immediately. The damage was real. The 16 sector-coordinating councils (SCCs), that brought together private partners from each critical infrastructure sector lost their legal mechanism to meet with the federal government. They could no longer advise and provide group consensus to their federal counterparts without triggering laws that CIPAC exempted. To be sure, CISA still had the Joint Cyber Defense Collaborative. Department of Energy had the Energy Threat Analysis Center. The National Security Agency had the Cybersecurity Collaboration Center. But none, however, replaced what the SCC ’s did: stand as steady forums where industry and government hashed out how to best assist critical infrastructure owners and operators.
Not that the SCCs were flawless. I worked with or alongside SCCs for more than a decade, most recently at CISA, and I am familiar with their shortcomings. SCC membership could be stagnant. The quality of recommendations to the government varied. New members faced barriers based on each sector’s rules.
The core problem was how the model locked each sector in. DHS built SCCs in an era when critical infrastructure risks were looked at through a sector-specific lens: energy, transportation, water, communications, and so on. Today’s cyber threats jump across these sectors. A vulnerability in a cloud service provider or industrial software platform can harm hospitals, pipelines, manufacturers, water utilities, and financial institutions simultaneously.
To see why ANCHOR-CI works better than the CIPAC structure, we need to go back 20 years and understand what CIPAC was trying to do. Congress didn’t codify CIPAC into law. Instead, Congress authorized DHS to establish advisory committees exempt from the Federal Advisory Committee Act (FACA). This exemption let the federal government and SCCs hold private meetings without public notice, convene quickly without complying with FACA procedural requirements, pick members based on expertise rather than balanced public representation, and skip FACA’s public recordkeeping requirements. (But these FACA exemptions do not exempt records from the Freedom of Information Act, a common misconception.)
ANCHOR-CI carries this power forward. Crucially, ANCHOR-CI end the siloed, sector-by-sector approach by creating four types of councils: Critical Infrastructure Sector Councils; Cross-Sector Councils; Critical Infrastructure Industry Councils; and Regional Coordinating Councils.
Critical Infrastructure Sector Councils: These are basically the old SCCs, but with a change in power. The CISA director now approves or removes any council member directly.
Cross-Sector Councils: These councils matter most. Specifically, they tackle “current and emerging threats, interdependencies, or other issues impacting multiple critical infrastructure sectors or industries.” Examples might include councils on countering unmanned aerial systems, AI threats, or reducing dependence on foreign supply chains. CISA could also revive and expand the Space Systems Critical Infrastructure Working Group.
Critical Infrastructure Industry Councils: Like cross-sector councils but designed for issues that span sectors in ways that don’t fit neatly into a given sector. After Volt Typhoon—a Chinese campaign that installed malicious malware in critical infrastructure—CISA could establish an Operational Technology council with original equipment manufacturers, software providers, and critical infrastructure owners to address and stop the threat.
Regional Coordinating Councils: CISA says these will help state and local governments tackle regional risks. What that means in practice is unclear. CISA could create 10 councils tied to 10 regional offices. Or it could create councils focused on real regional risks: preparing for the Cascadia subduction zone in the Pacific Northwest, droughts in the Southwest, or hurricane in the South and Mid-Atlantic.
In the end, like any policy, success hinges on how CISA carries it out. If CISA runs ANCHOR-CI thoughtfully and with transparency, it could become the biggest upgrade in of public-private cybersecurity collaboration work in two decades.
The post ANCHOR-CI could fix 20 years of broken government-industry collaboration appeared first on CyberScoop.