ISA: Announces CISO Based, Cross Sector Study on AI in Critical Infrastructure
By Larry Clinton, Skytop Contributing Author and Host of “Fixing Cybersecurity”, SkytopTV Talk Show Series / August 21, 2026
Larry Clinton is President of the Internet Security Alliance (ISA). The ISA is a multi-sector trade association that focuses on thought leadership, policy advocacy and developing best practices for cyber security. Mr. Clinton holds a certification on Cyber Risk management for Corporate Boards from Carnegie Mellon University, He is on the faculty of the Wharton School where he teaches a graduate Executive Education course in cyber security.
The National Association of Corporate Directors has twice named Mr. Clinton as one of the 100 most influential people in the field of corporate governance. He is a two term Chair of the IT Sector Coordinating Council and serves on the Cybersecurity Advisory Board for the Center for Audit Quality and the Cyber Advisory Board for the Better Business Bureau. He is widely published and has been a featured spokesman in virtually all major media outlets from WSJ, USA Today Fox News, NBC, CBS, NYT, PBS Morning Edition CNN & even MTV in India. He testifies often before Congress. He has briefed industry and governments world-wide including NATO and the OAS. ISA was also the only trade association to be part of the official cyber security briefing for the Republican National Convention in Cleveland.
ISA recently published the Cyber Social Contract (Vol. 3), which outlines 106 recommendations for the President and Congress. The previous editions of the ISA Social Contract were endorsed by the House GOP Task Force on Cyber Security and were the basis for President Obama’s Executive Order 13636 on Cyber Security. He is the industry co-chair – DHS is the government co-chair– of the Policy Leadership Working Group on Cyber Security Collective Defense featured at the National Cyber Security Summit in New York in July.
He literally “wrote the book” — the Cyber Risk Handbook for corporate boards which is the only private sector publication endorsed by both DHS and DOJ. PWC has independently evaluated the Cyber Risk Handbook and found it substantially changed how corporate director’s address cyber risk management leading to higher budgets, better risk management, closer alignment of cyber security with business goals and helping to create a culture of security. In 2017 ISA adapted the Handbook for the UK and Germany. As in the US, the German edition has been endorsed by the German government. ISA is now working with the OAS on a Latin American version of the handbook; as well as an edition for India and Japan, in partnerships with industry groups.
Today the Internet Security Alliance (ISA) is releasing the first in a series of blog posts detailing a cross-sector assessment by critical infrastructure CISOs of the security challenges and gaps being created by AI adoption in five critical sectors.
These posts will outline the results of the first two phases in ISA’s program “Defining an Effective and Sustainable Model for AI Deployment in Critical Infrastructure.” Full results of phases one and two in this study will be presented in a congressional briefing on September second.
Purpose of the Project
Top cybersecurity professionals from five critical infrastructure sectors – defense, financial services, healthcare, energy and IT -- were asked to analyze the cybersecurity challenges and gaps they are currently experiencing as artificial intelligence is deployed across their operating environments.
The ultimate goal of the research is to construct a CISO-experiential, AI-infused, cross-sector model that supports a cybersecurity policy approach that is both effective and economically sustainable, and that can be applied to governance in government and private industry alike.
The assessment was grounded in operational experience of Chief Information Security Oficers (CISOs) from these sectors. Each participant is accountable for defending an enterprise that already runs AI at production scale. Each was asked what is failing today, which governance practices have proven insufficient, and what would have to change for security to keep pace with deployment.
Key Questions Analyzed in the Study
Each of the five sector reviews was structured against the same four questions.
What are the cybersecurity policy gaps and challenges that the introduction of AI is presenting to these privately owned and operated critical infrastructures in the United States?
What policy initiatives need to be developed to facilitate a cybersecurity model that addresses those gaps and challenges in the AI era, and that is both effective and economically sustainable for industry and government?
What policy initiatives need to be implemented to address gaps and challenges within the specific infrastructure sectors identified?
How can industry and government best assure effective cybersecurity governance in the AI era?
Creating a Policy Framework for Effective and Sustainable Policy
The project uses the Cybersecurity Social Contract as its template. That model is based on two central facts. First, the overwhelming majority of critical infrastructure in the United States is privately owned and operated. Second, market forces alone will not generate the level of security the national interest requires, because much of the threat emanates from better funded nation-state, or state affiliated actors and benefit of private security investment accrues to parties other than the investing firm.
The model therefore pairs industry commitments to demonstrated security practice with government commitments to incentives, legal certainty, and shared capability, rather than relying primarily on prescriptive mandates. The Social contract model has served as a core principle of several successful public policy efforts, including the Cyberspace Policy Review and the bipartisan, bicameral Cyberspace Solarium Commission.
AI does not change that logic. It intensifies it, because AI simultaneously accelerates the threat, expands the attack surface, concentrates dependence on a few providers, and raises the cost of adequate defense.
A social contract model which creates a more fulsome partnership between industry and government enabling a true national approach to cyber defense in the AI era, would differ from the traditional industrial age model. The current research suggests a cross-sector approach with an evolved governance structure will be more responsive to and effective in the AUI environment as the same models, providers, and deployment patterns appear in all five sectors, and addressing one shared problem through five separate regulatory regimes multiplies cost without adding security.
Next: Identifying Areas of Convergence Across the Industry Sectors