Anthropic Cyber Mission: What Its Critical Infrastructure Program Does
Anthropic's Cyber Mission launches a critical infrastructure defense program. Here's how it differs from OSS Scanner and what OT operators should verify.
On October 8, 2026, Anthropic introduced the Cyber Mission, a longer-term effort to help defenders secure critical systems and widely used software. Its new Critical Infrastructure Defense Program (CIDP) is the operational-technology track: Anthropic says it will bring Claude models, on-site engineering support, and threat research to security providers that protect power, water, industrial and transportation systems. This is not the same product as OSS Scanner, which serves open-source maintainers. The distinction matters for operators deciding whether this is a practical security initiative or just another AI vulnerability-scanning announcement.
What the Critical Infrastructure Defense Program includes
- Frontier Claude models for security work carried out with specialist providers, rather than an announced self-service tool for every utility.
- On-site engineers and threat research working alongside organizations that already secure industrial systems.
- An initial partner cohort including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
- Early work on identifying and remediating weaknesses; Anthropic says several partners are already using Claude in this work, but has not published an independent impact study or universal rollout date.
CIDP versus OSS Scanner: two different security jobs
Where the Cyber Mission's two launch tracks fit
| Critical Infrastructure Defense Program | OSS Scanner |
|---|---|
| Focuses on operational technology and critical infrastructure through trusted security providers. | Focuses on opt-in security scanning for open-source projects and maintainers. |
| Combines Claude, engineering assistance and threat research within specialized security workflows. | Provides recurring model-generated vulnerability reports and proposed fixes. |
| A small initial partner cohort; wider participation is planned. | Enrolled maintainers receive scans without a fee; reports may require substantial human triage. |
| Success depends on safe operations, remediation planning and reliability constraints. | Success depends on useful findings, maintainer capacity and responsible disclosure. |
Make Better already covers OSS Scanner separately. The new editorial value here is the operational-technology program: a utility or manufacturer cannot handle a vulnerability report the same way a web application team handles a routine patch.
Why operational technology changes the AI-security equation
Operational technology (OT) includes the industrial controllers, networks and systems that monitor or affect physical processes. A software change can affect equipment availability and, in some settings, human safety. NIST's Guide to Operational Technology Security (SP 800-82 Rev. 3) emphasizes performance, reliability and safety alongside cybersecurity. Anthropic makes a similar point: industrial systems often have long lifespans, proprietary components and limited opportunities to take equipment offline. Finding a flaw faster is useful only when the operator can validate and fix it safely.
The announcement does not establish that Claude can autonomously secure a power grid, that every vulnerability can be patched immediately, or that the program has already reduced incidents by a measured percentage. The stated work is underway with a limited cohort, and outcomes should be evaluated as evidence becomes available.
A cautious pilot checklist for infrastructure operators
- Choose a narrow, non-production starting scope, such as analyzing known vulnerabilities or prioritizing existing security findings.
- Agree on access boundaries with the OT security provider: systems, data, model inputs, permitted tools and retention rules.
- Require human review of findings and proposed changes by people who understand the industrial process.
- Validate proposed mitigations in an isolated test environment or approved maintenance workflow before touching live equipment.
- Define success measures before the pilot: confirmed findings, time to triage, safe remediation rate, false-positive workload and operational disruption.
- Keep a rollback plan, change log and incident escalation path; never let an AI-generated recommendation bypass existing safety controls.
The important change is not a promise of autonomous cyber defense. It is the pairing of advanced AI analysis with established OT specialists and operators who can judge real-world consequences. For an organization evaluating AI security tools, the strongest business case will be demonstrated reductions in analyst workload and remediation delays without increasing operational risk. Until those outcomes are published, treat this as a promising program rather than proven protection.
Who can take the next step?
Anthropic invites security vendors, systems integrators and equipment manufacturers serving critical infrastructure to register interest in CIDP as it expands. Open-source maintainers are directed to OSS Scanner, while eligible security teams can apply to the expanded Cyber Verification Program. Operators should verify participation details and eligibility with the official program rather than assume immediate general access.
Anthropic Cyber Mission's CIDP is a partner-led attempt to improve critical-infrastructure cyber defense, not an autonomous patching service. The next meaningful evidence will be verified remediation outcomes and proof that AI-assisted security can operate within industrial safety constraints.
Sources & useful resources
- Anthropic: Introducing the Cyber Mission— Primary announcement, October 8, 2026
- NIST: Guide to Operational Technology Security— NIST SP 800-82 Rev. 3, 2023