IC Technology & Cyber — 2026-07-02
CISA Establishes ANCHOR-CI Advisory Council Replacing Trump-Disbanded CIPAC for Critical Infrastructure Cybersecurity Coordination
BLUFDHS's deliberate omission of liability protections from ANCHOR-CI makes it very unlikely by December 31, 2026 that critical infrastructure operators will share incident data at levels CIPAC sustained.
DHS published a Federal Register notice on Wednesday establishing the Alliance of National Councils for Homeland Operational Resilience-Critical Infrastructure, or ANCHOR-CI, to replace the Critical Infrastructure Partnership Advisory Council that then-Secretary Kristi Noem disbanded in March 2025 12. CISA will manage the program and its director must approve membership across four council types: sector, cross-sector, industry, and regional 234. DHS exempted ANCHOR-CI from the Federal Advisory Committee Act, citing the sensitive nature of the risk assessments involved, and is establishing the body for an initial two-year term renewable in two-year increments 34. Secretary Markwayne Mullin said the council will "ensure we have the right people in the room" to keep critical infrastructure secure 4. Cybersecurity Dive reported the new framework omits the liability protections that shielded industry information-sharing under CIPAC, a gap flagged by the Health-ISAC and WaterISAC 2.
AnalysisDHS is
very unlikely to amend ANCHOR-CI to restore CIPAC-style liability protections before the initial two-year term expires in December 2026, leaving the gap Health-ISAC and WaterISAC flagged unresolved; the FACA exemption paired with the CISA director's expanded membership authority signals DHS traded liability shielding for administrative control, a design choice unlikely to reverse without legislative pressure. Sector operators are likely to keep withholding sensitive incident data in response, narrowing the threat intelligence CISA can draw from the councils and leaving it reliant on mandatory regulatory reporting rather than voluntary sharing. High confidence rests on DHS's filing addressing risk-assessment secrecy while omitting liability language entirely, pointing to deliberate policy rather than oversight, though the gap could instead reflect unresolved interagency antitrust disagreement DHS might still close through subsequent guidance. Multiple independently corroborating outlets, anchored to the primary Federal Register notice, support the reading.
4 sources
- Establishment of the Alliance of National Councils for Homeland Operational Resilience—Critical Infrastructure (ANCHOR-CI) - Federal Register / DHS
- DHS proposes new system for public-private infrastructure security collaboration - Cybersecurity Dive
- DHS to unveil replacement council for critical infrastructure cybersecurity - CyberScoop
- DHS Launches ANCHOR-CI Critical Infrastructure Councils - GovInfoSecurity
View in full brief →