Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
ANCHOR-CI Myths: What Risk Managers Get Wrong About LiabilityRegulatory Bodies
5 min readFor Risk Managers

ANCHOR-CI Myths: What Risk Managers Get Wrong About Liability

When CISA launched ANCHOR-CI in July 2026, the security community immediately focused on one missing piece: the liability protections that made CIPAC work for nearly two decades. Your legal team is asking questions. Your executives want to know if participation creates new exposure. And you're trying to figure out what "no liability protection" actually means for your information-sharing strategy.

Let's clear up the misconceptions. These myths persist because the framework change happened quickly, because people conflate different types of legal risk, and because "liability protection" sounds simpler than it is.

Myth 1: Without Liability Protection, Any Information You Share Can Be Used Against You

Reality: ANCHOR-CI maintains exemption from the Federal Advisory Committee Act, which means sensitive discussions remain shielded from public disclosure requirements. The framework explicitly supports "open and candid discussions of sensitive information" through closed sessions.

What changed isn't disclosure protection. It's the specific safe harbor CIPAC provided for executives discussing incidents in group settings without antitrust or regulatory exposure. That's a narrower issue than "everything you say can be subpoenaed."

Here's what you still have: protection from Freedom of Information Act requests for meeting content, the ability to mark information as sensitive, and CISA's administrative controls over who attends which discussions. What you don't have: explicit statutory language saying "statements made here cannot trigger antitrust scrutiny" or "incident admissions here don't constitute regulatory violations."

The practical difference? You need to review what your executives say about market coordination or compliance gaps, not whether you can share threat intelligence.

Myth 2: CIPAC's Liability Protection Made It Effective, So ANCHOR-CI Will Fail

Reality: CIPAC stopped functioning in March 2025 when then-DHS Secretary Kristi Noem eliminated it. For more than a year, critical infrastructure sectors operated without any formal framework, and some stopped sharing cybersecurity data with the federal government entirely. ANCHOR-CI launched in July 2026 specifically to address that gap.

The framework didn't collapse because liability protection was insufficient. It ended through administrative decision. The question isn't whether ANCHOR-CI can match CIPAC's legal protections; it's whether the new council structures and CISA governance model create enough value that participants accept slightly higher legal risk.

Consider what ANCHOR-CI adds: four council types instead of one monolithic structure, explicit regional coordinating councils, and the ability to establish cross-sector councils that address interdependencies (like healthcare's reliance on water and communications infrastructure). These operational improvements may matter more than the liability question for day-to-day participation.

Myth 3: Your Company Should Wait for Liability Protections to Return Before Participating

Reality: ANCHOR-CI operates for two years initially but may be extended by the DHS Secretary. If you wait for statutory liability protection to reappear, you'll spend those two years outside the room where threat intelligence gets shared and where your sector's priorities get elevated to federal decision-makers.

The Healthcare and Public Health sector offers a clear example. The HHS Office of Cybersecurity and Infrastructure Protection will work closely with DHS and CISA to ensure HPH sector priorities are elevated through ANCHOR-CI councils. If your health system isn't participating, someone else is defining what "healthcare priorities" means to federal policymakers.

You don't need to share everything. You need a participation strategy that distinguishes between threat intelligence (low legal risk, high operational value) and incident admissions (higher legal risk, case-by-case value assessment). Most organizations can contribute meaningfully while keeping sensitive compliance discussions internal.

Myth 4: CISA Appointing Council Members Means Less Private Sector Influence

Reality: Under ANCHOR-CI, CISA approves proposed council members and may appoint additional participants. Under CIPAC, private sector councils chose their own representatives. This looks like a loss of autonomy until you consider what it solves.

CIPAC's self-selection model created echo chambers. The same trade associations and large operators dominated discussions. Smaller critical infrastructure owners, state and local agencies, and organizations without established relationships stayed out. CISA's approval authority lets them ensure regional representation, include entities that lack Washington lobbying presence, and balance sector interests.

Your concern should be whether CISA uses this authority to pack councils with politically favored participants or to genuinely broaden the tent. The framework allows councils to recruit from four groups: critical infrastructure owners and operators, government agencies, organizations with direct cybersecurity responsibility, and other private sector entities. That's wider than CIPAC's typical membership.

Track who gets appointed to your sector council. If it's the usual suspects, push back. If it includes operators you've never met, that's the point.

Myth 5: The Lack of Liability Protection Is a Bug, Not a Feature

Reality: Removing liability protection may be deliberate policy. CIPAC's safe harbor let executives discuss incidents without regulatory exposure, which was valuable. It also created moral hazard: participants could acknowledge compliance failures in closed settings without consequence, then return to their organizations and do nothing.

ANCHOR-CI shifts the calculus. You can still share threat intelligence and coordinate defensive measures. You just can't treat council participation as a confessional where admissions don't count. That's a feature if you believe information sharing should lead to actual security improvements, not just cathartic venting sessions.

The framework's flexibility supports this. Critical infrastructure sector councils can focus on strategic priorities. Cross-sector councils can address interdependencies. Regional coordinating councils can tackle location-specific risks. You choose which councils to join based on what you need to accomplish, not which group offers the best legal cover.

What to Do Instead

Stop debating whether ANCHOR-CI is "better" or "worse" than CIPAC. Ask what you need from government-industry coordination and whether this framework delivers it.

Map your participation strategy to council types. If you operate healthcare facilities in multiple states, regional coordinating councils matter more than the national HPH sector council. If you depend on water and communications infrastructure, cross-sector councils are where you'll get early warning about upstream failures.

Separate your threat intelligence sharing from your incident disclosure process. Threat intelligence (indicators of compromise, attacker techniques, vulnerability patterns) carries minimal legal risk and belongs in ANCHOR-CI discussions. Incident disclosures that reveal compliance gaps or regulatory violations need legal review before you share them in any setting, with or without liability protection.

Document your participation boundaries. What can your representatives discuss without legal review? What requires approval? What stays internal? ANCHOR-CI's exemption from the Federal Advisory Committee Act protects meeting content from public disclosure, but it doesn't protect you from saying something your general counsel wishes you hadn't.

Finally, recognize that the two-year timeline creates urgency. ANCHOR-CI may be extended, or it may be replaced with something else entirely. The organizations that shape its evolution will be the ones participating now, not the ones waiting for perfect legal conditions.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like