One of the next major national security crises will likely begin on private infrastructure. It could begin in a frontier artificial intelligence lab, on a telecom carrier’s network, or on a factory floor that has run out of a critical mineral it cannot source anywhere else.
When this crisis comes, the U.S. government will dust off a familiar playbook, not much different from the one it ran after the Colonial Pipeline ransomware attack in 2021. Senior officials will convene government-only meetings, work the phones to reach the private industry executives already in their phone book, and try to reconcile conflicting interests on the fly. Much of the engagement with private actors is based on pre-existing relationships between senior leaders and industry and is ad-hoc in nature.
That ad hoc approach is not surprising. The United States has no standing forum where business leaders and national security officials meet regularly across the full range of national security concerns, set a shared agenda, and speak collaboratively with one another. A forum like this is especially necessary in a time when there are near daily developments across technology, supply chains, and critical minerals that are of such interest to both public and private actors. But a standing public-private forum is also critical for planning, coordination, and information sharing in the long term. Congress should build a durable standing forum in the next National Defense Authorization Act.
Unprecedented Threats to the Public Interest from Private Infrastructure
Never before have the decisions of private companies carried such consequences for national security. Private companies, rather than government labs, are building the most consequential strategic technology of the era, and choices about model releases, jailbreak policies, compute allocation, and foreign partnerships are made in boardrooms where the government does not sit. When SpaceX activated Starlink over Ukraine in 2022, a single company became the backbone of a nation’s wartime communications, and its owner’s decisions (including restricting use near Crimea, limiting the service for drone operations, and reportedly cutting coverage during a counteroffensive), shaped the battlefield with no treaty or vote behind them. By early 2025, access to the network had reportedly become a bargaining chip in a U.S. push for a share of Ukraine’s critical minerals. The security and intelligence services of adversary governments are also increasingly targeting privately owned networks, while the intelligence about who is doing the targeting sits inside the U.S. government and is inaccessible to those managing the at-risk networks. The Salt Typhoon penetration of U.S. telecommunications, disclosed in 2024, exposed the problem clearly: the government held intelligence the carriers needed, and the carriers found the first signs of intrusion that only the government could put in context. The impact of this misalignment is both that the carriers were unable to use the government’s intelligence to prevent the penetration and that the intelligence community did not benefit from relevant or real-time information from the carrier to validate their understanding of the threat or inform potential counterintelligence operations.
Coordination within the private sector alone does not close the gap either. When a leading frontier AI company recently concluded that one of its models was too dangerous to release, it stood up a private coalition of critical-infrastructure firms to use the model to harden other companies’ cyber defense, choosing the members and funding the work without a formal government role. The effort surfaced thousands of serious vulnerabilities. The incident showed both the reach of private action and its limits. When private companies are put in a position normally reserved for governments, the public becomes subject to a private company’s remedy and their vision for (de facto) governance. In addition, some companies may rush to establish new coalitions or entities to help lock in their competitive advantages or to exclude certain actors, which is perhaps to the commercial benefit of certain companies but not necessarily a step driven by the public’s best interests. In this case, one company set the terms, with the public interest depending on that firm’s judgment. The answer is a new public-private forum where government and industry both sit to discuss the public consequences of private decisions.
Inadequate Mechanisms
The existing mechanisms of communication between the private sector and government are inadequate and ad hoc. Trade associations and other industry groups advocate for their members, but their requests generally run in one direction. Informal CEO calls with senior officials are episodic, company-specific, and reward whoever has the best Rolodex. The current administration has made unusually heavy use of these channels, from the president calling chief executives directly to the commerce secretary telephoning a steel CEO to stop a plant closure. But this pattern is not new. Every White House brings its own network and idea of whom to call.
The formal bodies that do exist are narrow. The Joint Cyber Defense Collaborative at the Cybersecurity and Infrastructure Security Agency is an essential piece of American cyber defense that Congress created in 2021. But it is a cyber-only body. It conducts operational planning and threat information sharing on digital infrastructure, only; it was never built to take up regulation, investment screening, supply chain exposure, or the other places where public and private interests now collide.
The policy world has noticed this gap. Jared Cohen, the president of global affairs at Goldman Sachs and Ian Bremmer, President and Founder of Eurasia Group, have argued that “unless governments become able and willing to design new institutions that include all stakeholders, the world will become much harder to govern.” The Special Competitive Studies Project has proposed a public-private partnership for open-source intelligence, acknowledging that the government no longer holds a monopoly on collection. The Center for a New American Security has proposed a national economic and technology security intelligence center at the Office of the Director of National Intelligence to map foreign supply chain and economic dependencies. The National Security Commission on Artificial Intelligence proposed shared research infrastructure to widen access to computing power and data beyond the largest firms. Each proposal addresses one or a few aspects of the problem, but none provides a recommendation for a comprehensive standing institution to facilitate public and private dialogue; each is relatively narrow and specific in scope.
Ensuring Longevity
Neither government nor industry will invest in a shared forum unless they believe it will outlast the administration that creates it. Durability is a design choice, and the record of the past eighteen months shows where it comes from. When the Trump administration cleared out various advisory bodies in early 2025, the Cyber Safety Review Board, created by executive order to examine major cyber security incidents and providing non-binding recommendations, was among the first to be terminated. The Critical Infrastructure Partnership Advisory Council was terminated in March 2025. It had convened industry and government since 2006 under a discretionary exemption from the Federal Advisory Committee Act (the 1972 transparency law that requires that the government only access external advice via public sessions, in the absence of an exemption). It fell as part of a broader effort to shrink federal bureaucracy rather than for any failure of its own.
The Joint Cyber Defense Collaborative survived the same purge because Congress had written it into the Fiscal Year 2021 National Defense Authorization Act as an operational component of CISA rather than an advisory committee. Institutions built on executive authority can be dissolved for reasons that have nothing to do with how well they work. And both government officials and industry representatives are well aware of this, disincentivizing significant investment in these potentially term-limited initiatives.
The Trump administration has proposed a replacement for the terminated Critical Infrastructure Partnership Advisory Council, which further sharpens the point: the filing published this July omits the prior liability protections companies had relied on and gives DHS approval over who sits at the table. In other words, it is a less attractive (and accessible) framework from the viewpoint of industry and might itself be disbanded in a few years. None of this produces a durable, comprehensive public-private forum at the level actually needed to protect U.S. national security.
Designing a Public-Private National Security Forum
To address this significant gap, this article proposes a public-private national security forum with a straightforward design. This forum should be established by legislation and incorporate an official charter that is binding upon its members. It should include the following key features:
- Joint Board: The forum should be co-chaired by a board split evenly between a senior business leader elected by industry peers and by a national security official designated by the president, an arrangement that leaves neither side fully owning the table. The chairs should be responsible for executing their mission as outlined in the congressionally mandated charter and overall serving as ambassadors between the public and private sectors.
- Permanent Secretariat: A small permanent secretariat would report to both co-chairs and would be responsible for organizing sessions, supporting the drafting of reports, managing logistics, and keeping the machinery running between meetings.
- Funding: The forum should be funded jointly, through congressional appropriation and membership contributions, with neither side’s money dominant, because whoever pays for the table eventually decides who sits at it.
- Forum Membership: The joint board should select forum members against published criteria tied to their importance to the broader public interest, weighing whether a company’s decisions or disruption would cascade into other sectors, rather than its size or its influence in Washington. Around a core of such firms, the establishing charter for the forum should reserve a rotating cohort of seats for startups working at the technological frontier and a block of seats for mid-cap companies that carry critical dependencies while lacking major national and international presences. A regional utility or a specialty chemicals producer can matter more to national security than a consumer goods conglomerate. The forum membership should also tilt away from the government’s existing major vendors, without excluding them, since major government and defense contractors already have clear channels of communication with government officials. The forum would benefit from a diverse array of financial firms, industrial conglomerates, logistics operators, the firms that run internet infrastructure, agriculture and pharmaceutical suppliers, frontier startups and laboratories, and energy utilities and operators. The companies that most need increased engagement with the government are the ones that currently don’t have a consistent, steady channel.
- Public Sessions: The forum should engage in regular public sessions with an agenda set by the joint board. These sessions should be open to the media and cover the threats companies are seeing, the unclassified intelligence the government wants industry to absorb, and the enforcement priorities firms want clarified.
- Closed Sessions: Running alongside the public track, the forum should hold closed sessions under the Chatham House Rule, where industry executives and government officials can express what neither can say on camera. Either co-chair could convene an emergency session, so that when a crisis breaks, both sectors walk into a room that already exists instead of rebuilding a phone tree under pressure.
- Published Assessments: Once a year, the joint board should publish its assessment of key emerging issues or where coordination is failing. Because these kinds of reports can often fall away in the saturated media environment, the establishing charter should oblige the government co-chair to answer recommendations in writing, on the record, within ninety days. While the forum would technically decide nothing, its dialogue and findings would be difficult to ignore.
Operationalizing Genuine Public-Private Cooperation and Engagement
This kind of structure and distinct organization will require specific legal protection primarily in three areas of the law. First, the Federal Advisory Committee Act, passed in 1972 to make government advisory bodies transparent to the public, requires open meetings, published notice, public records, and balanced membership. Those requirements serve an important purpose, but they are incompatible with a forum whose value depends on candid discussion of sensitive vulnerabilities between senior officials and corporate leaders. Accordingly, the proposed public-private forum will need a FACA exemption. Next, the Sherman Act and related antitrust laws limit how competitors may gather and share information. (NOTE: The Justice Department and Federal Trade Commission withdrew their guidance on collaborations among competitors in late 2024 and are now rewriting this guidance, demonstrating how fickle this sort of guidance can be between administrations). Finally, companies that disclose sensitive information to the government face the risk that it will be used against them by the agencies that regulate them.
Congress should address each. To start, a statutory exemption from the open-meeting and membership provisions of the Federal Advisory Committee Act would enable this public and private forum to operate in a better suited manner for its subject matter. In addition, Congress should create antitrust protection for companies that participate, as well as limits on civil liability for companies that share sensitive information in good faith.
Safe harbor, antitrust protection, and liability limits sound like giveaways to corporations. But they are more similar to what the Federal Aviation Administration has run for decades, where airline employees who voluntarily report safety problems receive limited legal protections, with carveouts that allow legal action for deliberate misconduct and criminal acts. The protection relates to the disclosure of information within the forum, not the conduct disclosed. A company that reports a vulnerability or a supply chain dependency should not face a private suit, an antitrust claim, or a regulatory action premised on having reported it, and would remain fully exposed for the underlying conduct.
Congress has done this before. The Cybersecurity Information Sharing Act of 2015 built roughly the same architecture for cyber threat data. However, the act lapsed at its ten-year sunset in September 2025, returned through a stopgap, lapsed again, and was revived retroactively in February. It expires again on September 30, 2026. No general counsel worth their salary will clear full participation in a public-private forum if the protections could sunset or be withdrawn.
Beyond Crisis and Coordination
A standing body can lay the foundation for other productive public-private engagements as well. As the forum matures, it could serve as a venue for joint exercises across sectors, extending what the electric grid does through GridEx and finance does through the Treasury Department’s private Hamilton Series. More generally, the hope is that this organization can also spur informal and other positive engagement between government and business leaders, building trust and cooperation across the public-private divide.
Some industry leaders will argue that the government already convenes relevant business leaders when necessary. This isn’t completely false, as the Trump administration and the Biden administration before it regularly engaged with CEOs and companies. But especially now, a privileged few sit on speed dial while other industry leaders are not directly engaging with the government. Which industry leaders get the call is somewhat arbitrary under any administration. And the executives on that list rarely represent the full range of industry or know what matters most in every crisis. A standing forum would widen that circle and build the infrastructure for engagement in advance, so that coordination in a crisis is not improvised.
Other critics will say that a forum like this decides nothing and would become another talking shop, a distraction for busy executives and better left to think tanks or academics. But this lack of concrete, binding authority is also one of the reasons that establishing legislation could pass with bipartisan support. Government and industry leaders recognize that new threats have precipitated the need for closer dialogue. Neither has settled on a regular means of engagement, with too much running through a handful of founders whose access rests on personal standing with whichever administration holds power. This forum, with relatively few rules or requirements, would let the government and industry build the collaboration they both know they need.
Conclusion
Given the evolving landscape and diverse threats to the public that now run through private infrastructure, this is a relatively modest proposal. Government and industry each know they need the other more than before. Legislation in the annual defense bill could create a charter, provide the necessary legal protections to permit fulsome participation, and fund a small staff, enough to support information sharing, coordinated planning, and the working relationships a future crisis will demand. Its modesty is what makes it achievable, and the record shows what the alternative produces: bodies that arrive by memo and leave the same way.
Competition with China, the race in artificial intelligence, and the contest over supply chain chokepoints are national problems that run through private hands. Congress should build the table before the crisis, rather than assembling it after.







