DHS Proposes New Framework to Strengthen Public-Private Collaboration on Critical Infrastructure Security
The U.S. Department of Homeland Security (DHS) on Tuesday proposed a new public-private collaborative framework for critical infrastructure to replace the previous framework abolished shortly after President Trump returned to the White House. The new framework, named the "Alliance for National Community Harmony and Operational Resilience - Critical Infrastructure National Council" (ANCHOR-CI), will serve as an umbrella structure for multiple advisory committees, designed to foster cooperation between the government and the private sector on cybersecurity and critical infrastructure resilience. It encompasses four types of committees—sector-specific, cross-sector, industry, and regional—managed by the Cybersecurity and Infrastructure Security Agency (CISA) with an initial term of two years. However, the new framework does not include the liability protections under the former CIPAC framework, raising concerns within the industry.

The U.S. Department of Homeland Security (DHS) proposed a new public-private partnership critical infrastructure collaboration system on Tuesday, replacing the framework that was abolished shortly after President Donald Trump returned to the White House. According to a DHS document to be published in the Federal Register on Wednesday, the new system, named the "Alliance for Homeland Resilience-Critical Infrastructure National Council Consortium" (ANCHOR-CI), will serve as an umbrella structure for multiple advisory councils composed of critical infrastructure operators, government officials, and "organizations directly responsible for cybersecurity and critical infrastructure security and resilience activities."
DHS stated that ANCHOR-CI will "provide forums where federal, state, local, tribal, and territorial cybersecurity, law enforcement, intelligence, national security, and other government representatives can engage with representatives of private sector entities and critical infrastructure owners and operators to review the current threat environment, discuss potential vulnerabilities, and make recommendations on how to secure more resilient critical infrastructure and cyberspace."
The new system replaces the "Critical Infrastructure Partnership Advisory Council" (CIPAC), which the Trump administration abruptly terminated in March 2025. That decision frustrated and shocked critical infrastructure operators, who quickly found that partnerships with federal agencies deteriorated. The government offered little explanation for the termination beyond vague statements that CIPAC was insufficient for the current threat environment. Many cybersecurity experts believed the decision endangered national security.
Under the new ANCHOR-CI framework, critical infrastructure operators and their government partners can establish four types of councils: sector-specific councils, including Sector Coordinating Councils (SCCs) composed of major infrastructure operators and industry associations, and Government Coordinating Councils (GCCs) composed of federal, state, and local agencies responsible for overseeing and assisting these infrastructure providers; cross-sector councils designed to address interdependencies between infrastructure categories; industry councils for industries spanning multiple sectors; and regional councils to establish geographically focused resilience partnerships.
The regional council option reflects the Trump administration's willingness to delegate more cybersecurity resilience responsibilities to the state and local levels, a trend that unsettles infrastructure operators who believe local governments are not yet prepared to handle sophisticated hacker threats. In explaining the rationale for regional councils in the document, DHS stated that "the most effective ownership and management of security and resilience should reside at the state and local levels, supported by an accessible and efficient federal government." The department said councils must "ensure that critical infrastructure entities in rural areas have representation and participation opportunities."
Filling the coordination vacuum
On the surface, the new system closely resembles CIPAC. The CIPAC framework, established in 2006, created the SCC and GCC structure and served for nearly two decades as the foundation for government and industry to jointly anticipate, plan for, and defend against emerging security risks. It also exempted SCC and GCC meetings from federal transparency rules, allowing government and industry representatives to privately discuss sensitive security issues.
Since CIPAC's termination, infrastructure operators and their industry associations have urged DHS to replace it as quickly as possible with an equivalent or stronger system. Multiple industry representatives previously told Cybersecurity Dive that, due to the lack of CIPAC protections, their sectors had stopped discussing certain sensitive issues with the government. Plans for ANCHOR-CI began taking shape in early 2026, but leadership turmoil within DHS delayed the system's approval.
The software industry trade group BSA praised the Trump administration's new partnership structure. "This effort strengthens trusted collaboration between government and industry, enhances timely sharing of cyber and physical threat information, and enables faster, more coordinated responses to significant incidents," said Henry Young, Senior Director of Policy at BSA.
However, the new framework may still not eliminate all concerns within the critical infrastructure community. It does not include the liability exemption protections found in CIPAC, which gave industry organizations confidence to share information without worrying about regulatory issues. "For ANCHOR to achieve its stated goal of reducing risk, the government needs to address the legal risks that often discourage companies from sharing sensitive cyber incident information," said Erol Weiss, Chief Security Officer at the Health Information Sharing and Analysis Center. "Industry leaders relied on the legal protections built into the old CIPAC framework to have candid strategic conversations about sensitive vulnerabilities."
Management and time frame
The Cybersecurity and Infrastructure Security Agency (CISA) will manage ANCHOR-CI's councils, including approving proposed members and appointing additional members as the agency deems appropriate. DHS stated that councils must include a representative cross-section of their respective communities, including members of different sizes and geographic locations.
DHS set the initial establishment period for ANCHOR-CI at two years, but the system can be renewed indefinitely, each time for two years. "I hope ANCHOR-CI brings the level of collaboration that CIPAC once inspired between sector risk management agencies and the private industry, but at first glance, the lack of liability exemption protections and the limited duration seem concerning," said Jennifer Lynn Walker, Director of Infrastructure Cyber Defense at WaterISAC. "Only time will tell."
Editor's note: This story has been updated to include comments.