Skip to content

Big Banks, Big Tech, Big Networks, Big Water team up on CNI security amid AI concerns

JPMorgan's Jamie Dimon chairs rapidly growing private sector group

The Alliance for Critical Infrastructure,
A water treatment plant. Image credit: https://unsplash.com/@photoken123

A private sector group focussed on security US critical national infrastructure (CNI) has added a heavyweight roster of tech CEOs – including Amazon’s Andy Jassy, Apple’s John Ternus and Microsoft’s Sundar Pichai – to its membership base as it looks to take the lead on improving national resilience to cybersecurity threats. 

The Alliance for Critical Infrastructure, founded in February and chaired by JPMorganChase CEO Jamie Dimon, has grown five-fold since its launch. It now includes CEOs from what it describes as six “lifeline sectors”: communications, energy, financial services, information technology, transport, water and  wastewater. 

“Strong public-private partnership has always been one of the country’s greatest strengths,” said Jamie Dimon, JPMorganChase’s CEO and chairman, and ACI Chairman of the Board, adding. “It is of utmost and immediate urgency that we come together to help protect our national security and all the people who depend on it.”

ACI’s membership now includes the CEOs of all the largest US banks (e.g. David Solomon of Goldman Sachs and Jane Fraser of Citi) and other CNI providers. 

ACI members, as of September 30, 2026.

It described its mandate on launching earlier this year as follows:

Identify systemic risks and develop strategies to strengthen the resilience of critical infrastructure sectors.
Develop and test robust resilience plans for a prioritized cross-sector response to emerging threats.
Facilitate understanding and coordinated action against risks to critical infrastructure.
Coordinate crisis response through cross-sector and public-private collaboration focused on consequence management.

See also: CISA hacked CNI org. through web shell from previous engagement

It describes itself as working alongside government to address emerging threats. But the ACI’s launch and growth comes amid concern in some quarters that the federal government’s own efforts to ensure CNI security are disjointed and deteriorating. 

In 2024 the Government Accountability Office (GAO) found that CISA has just two federal staff working on its OT-specific threat hunting and/or incident response services for example. Since then, CISA has faced sweeping job and budget cuts. 

This month it began rolling back several services that support critical infrastructure, including its ransomware readiness assessments, and external dependencies management assessments or cyber infrastructure surveys. (CISA described this as “retiring some legacy questionnaire assessments,” but critics warned that alongside its cuts – that have seen the agency mothball regional roles that interfaced with local officials and CNI providers – the government was reducing local cyber-resilience.)

Amid mounting geopolitical risk – and with cybersecurity risk rising as frontier AI models make it easier to find novel software vulnerabilities and map attack paths – only a “well-organized and coordinated effort by like-minded and capable companies… will successfully navigate these challenges,” said John Stankey, AT&T Chairman and Chief Executive Officer in a canned statement today (September 30.) 

“We are standing at the threshold of a profound technological shift that will reshape critical infrastructure, making deep collaboration essential to manage this disruption safely and responsibly,” concluded FedEx CEO Rajesh Subramaniam, also a member.

See also: The Pentester's VMware 0days

Add The Stack on Google