Vulnerabilities

CISA's ANCHOR-CI Framework

July 26, 2026 12:12 · 12 min read
CISA's ANCHOR-CI Framework

The Cybersecurity and Infrastructure Security Agency (CISA) has published a notice in the Federal Register that could fundamentally change how the U.S. government works with private companies to protect critical infrastructure from cyber threats and natural disasters. The notice, “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI),” details a new framework for CISA to build councils that let private partners advise the government on cybersecurity and critical infrastructure issues.

Replacing a 20-Year Framework

This new framework replaces the 20-year framework that the federal government used to work with critical infrastructure partners, formerly known as the Critical Infrastructure Partnership Advisory Council (CIPAC). The termination of CIPAC in March of last year by former Homeland Security Secretary Kristi Noem led to immediate objections from Congress and private-sector partners, resulting in the loss of a legal mechanism for the 16 sector-coordinating councils (SCCs) to meet with the federal government.

Shortcomings of the Old Framework

The old framework had its shortcomings. The quality of recommendations to the government varied, and new members faced barriers based on each sector’s rules. The model also locked each sector in, with DHS building SCCs in an era when critical infrastructure risks were looked at through a sector-specific lens. Today’s cyber threats, however, jump across these sectors, making the old framework inadequate.

How ANCHOR-CI Works

ANCHOR-CI carries forward the power of the old framework while ending the siloed, sector-by-sector approach. It creates four types of councils: Critical Infrastructure Sector Councils, Cross-Sector Councils, Critical Infrastructure Industry Councils, and Regional Coordinating Councils. Critical Infrastructure Sector Councils are similar to the old SCCs but with a change in power, where the CISA director now approves or removes any council member directly.

Cross-Sector Councils tackle “current and emerging threats, interdependencies, or other issues impacting multiple critical infrastructure sectors or industries.” Examples might include councils on countering unmanned aerial systems, AI threats, or reducing dependence on foreign supply chains. Critical Infrastructure Industry Councils address issues that span sectors in ways that don’t fit neatly into a given sector, such as an Operational Technology council with original equipment manufacturers, software providers, and critical infrastructure owners.

Success Hinges on Implementation

The success of ANCHOR-CI hinges on how CISA carries it out. If CISA runs ANCHOR-CI thoughtfully and with transparency, it could become the biggest upgrade in public-private cybersecurity collaboration work in two decades. The new framework has the potential to improve collaboration between the government and private companies, ultimately leading to better protection of critical infrastructure from cyber threats and natural disasters.

For the next two years, ANCHOR-CI will dictate how the government and industry collaborate to protect critical infrastructure. The framework's implementation will be crucial in determining its success. With its new approach, ANCHOR-CI could be the solution to 20 years of broken government-industry collaboration.

With its potential to improve collaboration and protect critical infrastructure, ANCHOR-CI is a significant development in the cybersecurity landscape. Its success will depend on how CISA implements the framework, but if done thoughtfully and with transparency, it could be a major upgrade in public-private cybersecurity collaboration.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free