Building Cyber Resilience Through Trust, Collaboration, and Shared Intelligence
In this interview, Ben Lane, CIPRNA event manager, speaks with Scott Algeier, Executive Director of the Information Technology ISAC (IT-ISAC) and the Food and Agriculture ISAC.
Drawing on more than two decades at the center of public-private collaboration, Scott shares candid insights into trusted threat-intelligence sharing, cyber resilience, interdependencies across critical infrastructure sectors, and what the next five years may demand of operators and policymakers alike.
You can also watch the full conversation on YouTube: https://youtu.be/YYSXYK09Fts
Ben Lane: Scott, thank you for joining us today. It’s great to have you here. To start, could you tell our readers a little about yourself and how you came to work in critical infrastructure protection?
Scott Algeier: Thank you, Ben. I appreciate the opportunity to be here. I currently serve as Executive Director of the IT-ISAC and also the Food and Agriculture ISAC. I’ve been in this role for just over 20 years, and before that I was working at the U.S. Chamber of Commerce starting around 2000, helping to build what were then very new public-private partnerships focused on critical infrastructure security.
At the time, even before September 11th, there was growing recognition that critical infrastructure, although largely owned and operated by private industry, was fundamentally tied to national security. The question was how to bring industry and government together in a way that improved security without undermining trust. That question has shaped my career for the past 25 years.
Ben Lane: For readers who may be new to the concept, how does an ISAC, specifically the IT-ISAC, facilitate trusted and actionable threat-intelligence sharing among critical infrastructure operators?
Scott Algeier: ISAC stands for Information Sharing and Analysis Center. These organizations were created to provide a trusted forum where companies within a sector can share cyber and physical threat intelligence with one another. The IT-ISAC was established in 2000 and focuses on companies that design, build, and operate information technology.
Trust is the foundation. We establish that trust through clear legal frameworks, non-disclosure agreements, and a rigorous membership process. But trust doesn’t come from paperwork alone, it comes from relationships. Our analysts spend a great deal of time engaging with members, hosting calls, meeting one-on-one, and building confidence that shared information will be handled responsibly.
Once companies see value and when they receive intelligence that helps them mitigate a real threat, they’re far more likely to share in return. Over time, that creates a self-reinforcing cycle where intelligence flows more freely and becomes more actionable for everyone involved.
Ben Lane: How would you describe the IT-ISAC as an organization? Is it an association, a non-profit, or something else?
Scott Algeier: The IT-ISAC is a U.S.-based 501(c)(6) nonprofit association funded by membership dues. While we’re headquartered in the United States, our membership is global. Our primary mission is threat intelligence sharing, but as a nonprofit we also provide thought leadership and serve as a trusted resource for policymakers.
We don’t lobby, but we do help decision-makers understand the operational realities of cybersecurity. Our members bring decades of experience, and part of our value is helping translate that experience into practical insights that inform policy discussions.
Ben Lane: Cyber resilience has become a major theme across the sector. What does cyber resilience mean to the ISAC community, particularly beyond traditional cybersecurity?
Scott Algeier: When this field began, the mindset was largely about prevention, build a wall and keep attackers out. Over time, we learned that no wall is perfect. Today, cyber resilience is about assuming that incidents will happen and preparing to recover quickly and effectively.
At the organizational level, resilience means maintaining business operations during an incident or restoring them as fast as possible. At the national level, it’s about ensuring that cyber incidents don’t cascade across sectors and disrupt essential services.
Resilience also means containment. How do we stop a localized cyber event from becoming a systemic crisis that impacts energy, communications, transportation, or food systems? That shift, from pure prevention to resilience and recovery, has been one of the most important evolutions in our field.
Ben Lane: Public-private collaboration is another cornerstone of critical infrastructure protection. How does the IT-ISAC work with governments and regulators without compromising member trust?
Scott Algeier: We’ve worked closely with government partners for many years, particularly at the federal level. But we maintain a strict firewall when it comes to threat-intelligence sharing. Government agencies are not members of the IT-ISAC, and that separation is intentional.
Our members need confidence that sensitive information won’t automatically end up with regulators or be subject to disclosure. That said, members can always choose to share directly with government or allow us to anonymize and share trends and analysis without identifying details.
One challenge we’re facing right now is the erosion of legal frameworks that historically enabled this collaboration. For example, protections under the Cybersecurity Information Sharing Act of 2015, which provide liability and disclosure protections, are at risk of expiring. These frameworks are widely seen as effective, and their potential loss creates uncertainty that could discourage sharing.
Ben Lane: Turning to emerging threats, what cyber risks concern you most today, especially in terms of interdependencies and cascading failures?
Scott Algeier: Artificial intelligence is probably the most significant factor reshaping the threat landscape right now. AI enables adversaries to scale their operations, automate reconnaissance, and lower the barrier to entry for less sophisticated actors. That means we’re seeing more capable attacks from a wider range of threat actors.
Interdependencies are another major concern. While individual companies often understand their own dependencies, on power, water, communications, we lack a comprehensive national level understanding of how sectors depend on one another. We’ve been talking about this challenge for 25 years, and while there has been progress, it remains a gap.
What’s also changed is how nation-states view critical infrastructure. Increasingly, infrastructure is seen as a strategic asset in conflict, including cyber operations designed to pre-position access for future disruption. That reality raises the stakes considerably.
Ben Lane: Finally, looking ahead five years, what capabilities will be essential for critical infrastructure protection?
Scott Algeier: Five years is a long time in cybersecurity, but some trends are clear. Threat actors will continue to become more sophisticated, networks more interconnected, and defensive challenges more complex.
No organization can succeed alone. Access to threat intelligence is important, but engagement with peer companies is essential. Understanding common environments, shared constraints, and sector-specific threats makes defense far more effective.
We see this every day. Sometimes a single, seemingly minor data point shared by one member helps others identify and disrupt a broader campaign. That collaborative model, sharing early, learning collectively, and responding together, will be even more critical in the years ahead.
Ben Lane: Scott, thank you for sharing your insights. This has been an extremely valuable discussion, and I’m sure it will spark further conversation within the critical infrastructure community.
Scott Algeier: Thank you, Ben. I appreciate the opportunity and look forward to continuing the dialogue.
Watch the full conversation on YouTube: https://youtu.be/YYSXYK09Fts

