The Trump administration's chaotic reorganization of the federal government has severely weakened the public-private partnerships that protect America's critical infrastructure from cyberattacks and physical disasters. According to interviews with 14 representatives from four critical infrastructure sectors—healthcare, water, energy, and telecommunications—four former senior government cybersecurity officials, and multiple infrastructure security experts, mass layoffs, widespread mission uncertainty, and persistent leadership vacancies have disrupted collaboration between federal agencies and the businesses and local utilities that operate and protect hospitals, water treatment plants, energy companies, and telecommunications networks.

Government leadership has canceled meetings with infrastructure operators, forced long-time liaisons out of their jobs, stopped attending key industry events, and abolished a coordination mechanism that allowed companies to have sensitive conversations with federal agencies about cyberattacks and other threats.

"This partnership is in a state of suspension," said one healthcare industry representative (who, like most respondents in this article, requested anonymity to discuss sensitive matters). "At the end of last year, this partnership had reached an encouraging level of maturity, but now all of that has been withdrawn."

Experts and industry officials say the result is declining trust between the public and private sectors, less mutual understanding of each other's needs and concerns, a diminished ability to plan for future attacks, and increasing national vulnerability to disruptive hacking activities—all at a time when the Trump administration's intervention in the Israel-Iran war has raised concerns about Iranian retaliatory cyberattacks on U.S. critical infrastructure.

"We are seeing something unprecedented in the cybersecurity field—a government deliberately reducing its own capabilities," said Michael Daniel, president of the Cyber Threat Alliance, who served as cybersecurity advisor to President Barack Obama. "I cannot see how this contraction leads to anything other than making us worse off."

Lost Cyber Protections

In recent years, nation-state hackers and cybercriminals have repeatedly breached and sometimes disrupted U.S. critical infrastructure, including key sectors such as healthcare, energy, water, and telecommunications. These intrusions have heightened concerns about companies' ability to withstand more severe attacks and underscored the urgency of government assistance to them.

But under the Trump administration, the level of engagement between agencies and critical infrastructure partners varies widely, with some dialogues continuing while others have almost completely ceased.

The Department of Homeland Security's abolition of the Critical Infrastructure Partnership Advisory Council (CIPAC) framework in March was the most disruptive change. CIPAC allowed government and industry representatives to discuss sensitive cybersecurity information—including company security breaches—without meeting standard transparency requirements that would make the information public. Without CIPAC, critical infrastructure operators have significantly reduced sensitive cyber dialogues with the government, according to multiple industry representatives, who all described the dissolution of CIPAC as catastrophic.

The absence of CIPAC "creates enormous fear" and poses a "huge risk" for companies wanting to share cyber threat information with the government, said one energy industry representative. "People will wonder, 'Are we sharing too much?'"

The demise of CIPAC has forced the telecommunications industry to suspend or modify several projects with the government, creating a significant impact, according to one communications industry representative. The industry has had to take on more responsibility for an internet routing security initiative previously led by the White House, paused AI-driven threat intelligence research, and frozen cooperation with the National Security Agency on nation-state attacks. These disruptions come as telecommunications companies contend with the massive and alarming intrusion into their networks by China's "Salt Typhoon" operation.

According to multiple industry sources, federal agencies are developing a replacement for CIPAC that would expand the range of private sector participants in meetings, and they say it is urgent for the government to roll out the replacement as soon as possible.

The oil and gas industry is currently refusing to share its cyber working group's products with the government "unless we are confident we have those [CIPAC] protections," said one energy industry representative.

Meanwhile, the industry has canceled its spring meeting with the government because companies are unsure what they can safely share. Industry leaders have scheduled another meeting anticipating the CIPAC replacement, but if the replacement does not materialize, the industry expects cyber dialogues at the meeting will not be productive.

The Department of Homeland Security declined interview requests for this article, and the department did not respond to questions about the CIPAC replacement.

Information Sharing 'Eroding'

The Trump administration's changes have also weakened some cyber information sharing, which is the cornerstone of the public-private partnership that keeps critical infrastructure safe from hackers.

Because the private sector operates most critical infrastructure, it understands better than the government how that infrastructure works, the cyberattacks it is suffering, and the impact of successful intrusions, said John Riggi, national advisor for cybersecurity and risk at the American Hospital Association and a former FBI cyber partnership official. In turn, industry relies on the government for unique foreign intelligence and cyber threat information that would otherwise need to be purchased from private companies. Smaller infrastructure operators with tight security budgets are especially dependent on this free information.

But information sharing "is taking a hit," said Errol Weiss, chief security officer at Health-ISAC. Alerts from the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI "do seem to be slowing down," Weiss said. Riggi described delays in getting threat intelligence from CISA due to "leadership changes," but said sharing with the FBI "remains very strong."

Industry sources say threat briefings are still happening, but they have become erratic as relationships with agencies have strained and federal workers have retired or been fired. "They have definitely tapered off," said one water industry representative. (EPA press secretary Bridget Hirsch said the agency continues to provide briefings at the "same cadence" as in the past.)

Trump's federal travel restrictions have also made it harder for government employees to attend industry events and visit infrastructure facilities. "Getting them to meetings is difficult," Weiss said. Government officials took a long time to get permission to attend the industry's annual tabletop exercise held on Thursday, which simulated how the U.S. would respond to a major cyberattack on healthcare facilities.

Meanwhile, Trump has continued a program launched by former President Joe Biden last year to speed up briefings. The Critical Infrastructure Intelligence Initiative, run by CISA and the intelligence community, provides cleared industry officials with classified threat briefings on the first Wednesday of each month. A second water industry representative said this is an improvement over briefings held for a smaller group of industry leaders at semi-annual industry leadership meetings.

A Transformed CISA

According to experts and industry sources, no agency has undergone more changes under Trump than CISA.

Congress created CISA in 2018 (during Trump's first term) as the hub of the government's cybersecurity partnership with U.S. infrastructure operators. But CISA's efforts to combat disinformation during the 2020 election made it a target of conservatives, and the second Trump administration quickly began targeting the agency, freezing its election security work, forcing about a third of its 3,300-person workforce out, terminating threat hunting contracts, and proposing even deeper cuts.

Now, infrastructure operators say they barely recognize the new but ambitious agency they had grown familiar with over the past six years.

"With CISA, there is no partnership. It's gone," said a second energy industry representative. "We can't even seem to meet with the necessary people there."

CISA's recent cuts "have severely impacted the agency's ability to engage meaningfully with industry stakeholders," said Jen Sovada, public sector general manager at operational technology security company Claroty.

CISA spokesperson Marcy McCarthy said the agency "remains fully committed to its core mission of protecting the nation's critical infrastructure and enhancing cybersecurity resilience," adding that "public-private partnership is defined by outcomes, such as risk reduction, improved response, and strengthened trust, not by the number of meetings."

But CISA employees say they are deeply frustrated by the changes and cuts at the agency. "We are kind of stalled," said one CISA staffer, who requested anonymity to speak freely. "People are adjusting to losing a large portion of our workforce... We are trying to find a new 'normal' under departures and [changing] mission parameters."

The agency's Joint Cyber Defense Collaborative (JCDC), launched in 2021 to make its public-private partnership less conversational and more operational, appears to have gone quiet. "I haven't heard anything from JCDC in the past few months," said the first energy industry representative. The industry spent two years working with JCDC on a "multi-part" effort to address state-sponsored cyberattacks targeting midstream natural gas pipelines, this person said, but the nearly completed project hit bureaucratic obstacles late last year, "and now I don't know its status."

A public-private working group co-led by CISA and the IT and telecommunications industry, focused on protecting the technology supply chain, has effectively shut down following the loss of CIPAC. The working group's high-level meetings "are being canceled every week," said one telecommunications industry representative.

Trump's cuts have also forced many CISA regional advisors to leave—field liaisons who connected infrastructure operators with the agency's free guidance and services. As a result, CISA is "disconnected" in many states, said the first water industry representative. "If all the CISA people in your state have left, who do you call? ... No one is communicating that."

The loss of CISA advisors has weakened infrastructure operators' preparedness against cyberattacks, with industry representatives recalling that these advisors provided briefings, participated in tabletop exercises, promoted CISA's free services (such as vulnerability scanning), and served as emergency resources.

"Water system operators were trained to contact those CISA contacts," said the first water industry representative. "Now they don't know who to contact. So either information that needs to get to the government doesn't get there, or it takes longer."

Sector Risk Management Agencies Under Strain

Beyond CISA's troubles, infrastructure operators also report problems with Sector Risk Management Agencies (SRMAs), which are designed to help specific industries address cyber and physical threats.

Around the time of the administration change, the EPA and CISA canceled a series of planned meetings with state water regulators, according to a third water industry representative. Such setbacks have compounded what industry leaders describe as the EPA's already weak capacity to help the industry fend off attacks.

EPA press secretary Hirsch said the agency "will continue to prioritize cybersecurity-supporting staff and resources," adding that the EPA views cybersecurity as "one of its highest priorities."

Meanwhile, the healthcare community is deeply concerned about future cyber assistance from the Department of Health and Human Services (HHS). The Trump administration is downgrading and reorganizing the HHS office responsible for the department's SRMA work. "It looks like they took a step back," said one healthcare industry representative. The industry used to meet frequently with HHS—sometimes weekly—to discuss critical infrastructure cybersecurity, Weiss said, "but since the new administration came in, that has all disappeared."

HHS did not respond to multiple interview and comment requests for this article.

Members of the energy industry say their cyber partners at the Department of Energy and the Transportation Security Administration (TSA), which is responsible for protecting oil and gas pipelines, are doing their best but face political headwinds. "The Department of Energy is trying desperately hard" to help the industry, said the second energy industry representative, despite a lack of leadership support, while TSA's remaining staff "are trying to save the ship."

The Department of Energy and TSA did not respond to requests for comment.

"Support is degrading," said Caitlin Durkovich, who served as Biden's deputy homeland security advisor for resilience and response.

'Empty Seats'

As Trump appointees push to shrink agencies, infrastructure operators' key contacts have left the government, leaving companies and their trade groups in the dark about who to turn to for cybersecurity help.

These departures have eroded important trust relationships between the public and private sectors.

"If I get a call from someone at CISA who has worked with me on incident response, I drop everything to take it because I know it's important... Likewise, if I call them, they pick up my call," Weiss said. "If we can't interact regularly like that, [and] if there's turnover, we won't have those relationships."

And it's not just trust that takes time to build. Departing employees "have accumulated a great deal of knowledge about the industries they served," said Daniel, the former White House cyber advisor. "The government is now losing the benefit of that expertise, which will be hard to replace."

Concerns About Response to Future Cyberattacks

In response to canceled meetings and missing contacts, industry officials say they will not sit back and wait for the government to tell them how to protect their sectors.

"Because of all these cuts, it has become more apparent that the private sector has to play an active role," Weiss said.

Infrastructure operators proudly point out that they, not government agencies, already possess most of the technical expertise needed to operate and protect their systems. But they worry about filling the information-sharing gap left by the shrinking government.

Some critical infrastructure communities now worry about what would happen in the event of a devastating cyberattack.

"If there is a major industry event, I worry about the government's ability to respond," Weiss said. At the current level of government support, one water industry representative said a widespread intrusion into water systems "could be catastrophic." When asked about the government's ability to help contain a major hack in the natural gas industry, the second energy industry representative said, "I don't know anymore."

Such industry pessimism only adds to the alarm many cyber experts feel about recent events.

"We really cannot afford to lose the capability and strength that comes from public-private cooperation," said Phil Reitinger, president and CEO of the Global Cyber Alliance. "The risks are too great."