As some U.S. critical infrastructure operators lose confidence in the federal government's ability and willingness to provide support, several large infrastructure companies are taking it upon themselves to strengthen coordination and prepare for major crises.

In February 2025, corporate giants from the banking, finance, communications, and energy sectors formed the Alliance for Critical Infrastructure (ACI), pledging to take the lead in helping infrastructure industries collaborate more closely to understand and mitigate the cybersecurity risks they collectively face. The alliance's nine founding members include JPMorgan Chase, Mastercard, AT&T, Lumen Technologies, AIG, Berkshire Hathaway Energy, Consolidated Edison, Southern Company, and Xcel Energy.

The message between the lines is clear: the critical infrastructure community, increasingly wary of the Trump administration's retreat from decades of public-private partnership, is trying to fill the gap in coordination and leadership.

Government budget cuts and staff attrition have made it harder for agencies to support and advise infrastructure operators, and the White House has encouraged states to take over responsibilities for protecting local utilities that were historically handled federally. Against this backdrop, infrastructure companies, including ACI's founding members, believe the private sector must act proactively.

Ben Flatgard, chairman of ACI, noted that the vast majority of U.S. infrastructure is managed by the private sector. "We cannot outsource this responsibility and its risk management practices," he said in an interview with Cybersecurity Dive. "We also need to lead the solutions ourselves."

Many experts believe that while the government must retain a leadership role in protecting critical infrastructure, the willingness of private companies to take on more responsibility is a positive sign.

"If the private sector does not proactively organize itself," said Brian Harrell, former assistant director for infrastructure security at the Cybersecurity and Infrastructure Security Agency (CISA), "there will be an unprecedented visibility gap in the nation's most critical systems."

The 'changed landscape' after government cuts

ACI evolved from the Tri-Sector Executive Working Group, which brought together leaders from the energy, financial services, and telecommunications sectors and served as an important private-sector voice during the Biden administration and the first Trump administration.

Tri-sector leaders influenced executive policy and legislation, including influential recommendations from the congressionally chartered Cyberspace Solarium Commission. But despite helping Washington make progress, these companies remained concerned that infrastructure protection was still highly siloed.

"We still haven't touched cross-sector collaboration; we just operate within our own verticals," said Michele Guido, executive director of ACI, in an interview.

Many infrastructure operators, especially the most resource-rich companies, have already "done well within their own lanes," said Flatgard, who oversees cybersecurity policy at JPMorgan Chase. But he added that individual corporate efforts are insufficient to address a truly broad crisis. ACI was established precisely to "start building bridges between our industries," because "we rely heavily on other industries to operate our essential services."

The second Trump administration's changes to long-standing public-private partnership models also prompted these companies to build new mechanisms. Throughout 2025, the Trump administration purged CISA, eliminated the public-private coordination channel known as the Critical Infrastructure Partnership Advisory Council (CIPAC), and considered shutting down the Federal Emergency Management Agency (FEMA). "You're just facing a changed landscape," said Guido, who also serves as director of strategic security policy at energy giant Southern Company.

Seeing the government retreat, infrastructure operators feel a new sense of urgency to shift from a supporting role to a leading one. To that end, the tri-sector companies restructured their group into a nonprofit organization that can recruit more members. ACI is currently creating working groups, defining pilot projects, and reviewing membership applications. In addition to full members, the group will collaborate with government agencies, Sector Coordinating Councils (SCCs), Information Sharing and Analysis Centers (ISACs), and cybersecurity think tanks.

However, ACI will not become a massive organization. Its leaders want to carefully select a group of infrastructure operators with the resources to contribute to its projects. At the same time, the group hopes to consult with a wide range of organizations, including smaller utilities that may offer lessons for larger companies. "Some of them may not be as cyber-mature," Flatgard said, "but most are very good at responding to crises within their business and areas of expertise. I think we can learn a lot from them."

"On a bad day, from a critical infrastructure perspective, who makes the key decisions? We have continuity of government, but what does continuity of critical infrastructure look like?"

— Michele Guido, Executive Director, ACI

A four-part strategy

Over the next 18 months, ACI members will be deeply involved in activities supporting the four pillars of the group's strategic plan.

The first pillar will focus on analyzing cross-sector dependencies—that is, organizations that support essential services across multiple industries. "Within verticals, you have all these plans, but there's no plan that really integrates to understand the cross-sector piece," Guido said. ACI plans to publish a white paper providing a high-level overview of how each industry operates and how multiple industries can collaborate, helping infrastructure operators better understand each other's needs.

The second pillar will test joint infrastructure industry responses to a "polycrisis"—a national-level emergency that simultaneously threatens broad infrastructure and carries both physical and digital consequences. "We want to develop an actionable national response protocol for events," Guido said. "On a bad day, from a critical infrastructure perspective, who makes the key decisions? We have continuity of government, but what does continuity of critical infrastructure look like?" Success in this area means infrastructure operators can "work in the fog of war" and smoothly take steps to maintain, rebuild, and restart critical services, Flatgard said. As part of this pillar, Guido said ACI is working with CISA to expand the agency's cybersecurity incident response playbook to reflect cross-sector collaboration.

The third pillar involves the private sector providing operational support to the government in countering adversary malicious activity, including expanding information sharing. The fourth pillar involves advising policymakers on legislation and regulations, which ACI leaders say will remain important even as companies take more action on their own.

'That's not how we plan'

The emphasis on cross-sector dependencies—risk areas that no single industry can fully understand or mitigate—sets ACI apart from other groups. ACI members will focus on assessing technologies that invisibly underpin multiple aspects of daily life, from GPS satellites critical to smartphones, airplanes, and tractors, to undersea cables connecting global AI and cloud computing data centers.

The resulting analysis could help various companies in the critical infrastructure community better prepare for major cybersecurity incidents.

Natnael Habtesion, chief security officer at ACI founding member Lumen Technologies, said the new group's unique value lies in its recognition that "a threat to one industry rarely remains isolated and can have adjacent impacts."

ACI places particular emphasis on collaborative planning for polycrises. Guido described a scenario where a natural disaster strikes a region of the United States while that same region suffers a major cyberattack. "That's not how we plan," she said. During tri-sector annual exercises over the past few years, infrastructure operators realized that the same playbooks they had prepared for, say, a geographically limited Category 5 hurricane were not very useful in a polycrisis. An environment with multiple simultaneous emergencies "stretches our capabilities very thin," Flatgard said.

Proactive action, with allies and limitations

Although ACI is still in its infancy, it is already thinking about how to test ideas proposed by members. This could include regional pilot projects—covering topics such as incident response, information sharing, and service restoration—involving the most important organizations in a specific area, from water treatment plants to health clinics to military bases.

Partnerships with sector-specific groups are critical to ACI's success. The group has held discussions with ISACs and SCCs to ensure they understand their roles. "We don't want this to duplicate existing industry functions and mechanisms," Flatgard said.

Errol Weiss, chief security officer at Health-ISAC, said ACI must integrate with information-sharing groups like his. "ISACs already provide operational threat intelligence and sector-specific context," he said. "Duplicating or bypassing that ecosystem would risk confusion for operators."

"This is a great time to discuss the resilience of the technology infrastructure that underpins all industries in the nation."

— Ben Flatgard, Chairman, ACI

ACI leaders also want to build strong relationships with federal agencies. "We need the government's help to succeed," Flatgard said. CISA recently released guidance to help infrastructure operators maintain services during crises. The agency also plans to assess operator resilience through targeted outreach, but CISA staff cuts may limit the scope of that work.

Moreover, in the absence of the CIPAC framework, broader government-industry relations are currently suffering. CIPAC had allowed government and industry leaders to meet privately without antitrust concerns. The Trump administration abruptly eliminated CIPAC with little explanation, and although the Department of Homeland Security is developing a replacement, the government has not responded to infrastructure operators' related questions.

"We still need to keep moving forward," Guido said. ACI hopes for a replacement for CIPAC, "but I don't think we can let it hold us back right now."

Experts say the lack of strong federal partnership will inevitably hinder corporate efforts. "Independent industry alliances can theoretically move faster than federal bureaucracies to address interconnected risks," Harrell said, but "without federal oversight, these groups lack the sovereign intelligence sources and antitrust exemptions that once underpinned their operations."

ACI leaders acknowledge these challenges. But as the group gets off the ground, they also say they see many opportunities to play a constructive role. "This is a great time to discuss the resilience of the technology infrastructure that underpins all industries in the nation," Flatgard said. "Within our own companies, there will also be some hard truths about what that means, but that's why we formed this group."