Anthropic launches Cyber Mission, puts Claude inside 11 critical-infrastructure security vendors
Anthropic put Claude directly into the security teams that keep power grids and water systems running, naming 11 named partners on October 8, 2026, for a new Critical Infrastructure Defense Program (CIDP), per Anthropic's announcement.
What
The CIDP is the critical-infrastructure half of a broader initiative Anthropic calls the Cyber Mission. Founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation, per the announcement. The program pairs frontier Claude access with on-site Anthropic engineers and threat research, aimed at operational technology, the controllers and industrial networks running power grids, water utilities, and transportation systems that often cannot be taken offline to patch. Several partners are already using Claude to fix vulnerabilities for customers, Anthropic said. The Cyber Mission's other track folds in the free, opt-in OSS Scanner that Pondero covered separately on October 9, plus earlier funding Anthropic gave to the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation. The announcement also references a $15 million cyber defense program Anthropic launched in June for state, local, tribal, and territorial governments, which the company says has since reached more than half of US states, per StateScoop.
A vendor shortlist now decides who gets Claude's help first
For an operator running a water utility or a rail system, this does not open a self-serve door to Claude for security work. It routes through one of 11 named vendors, so the practical move for a security buyer is to check whether an existing contractor, such as CrowdStrike, Dragos, or one of the Big Four consultancies on the list, already sits inside the program before assuming they need a new vendor relationship. Anthropic is still running a small-cohort phase to learn which workflows hold up, per the announcement, so broader access beyond these 11 firms is not yet available. Companies that build security products for critical infrastructure and are not on the list can register interest through a form Anthropic linked in the post, with no stated timeline for when or whether more partners get added.
Context and reactions
Partner quotes in Anthropic's own post lean toward urgency framing rather than results. CrowdStrike's Daniel Bernard said critical infrastructure facing "machine-speed threats requires machine-speed defense," and Palo Alto Networks' Sam Rubin said threat actors are "using AI to find and exploit exposures at machine speed," both per Anthropic's announcement; these are vendor quotes Anthropic selected for its own launch post, not independently verified outcomes. Anthropic also disclosed that its earlier Project Glasswing initiative found many vulnerabilities but did not yet achieve, in the company's words, "a sufficient reduction in cyber risk," and that Glasswing has since been absorbed into an expanded Cyber Verification Program. No partner or Anthropic has published a measured reduction in incident response time or exploited-vulnerability count tied to CIDP work so far.
What to watch next
Watch for the first CIDP partner to publish a case study with a specific before-and-after metric, such as patch time or detected-but-unexploited vulnerability counts, rather than a quote in Anthropic's own materials. Also watch whether Anthropic names additional partners beyond the initial 11 as the program moves past its early cohort phase.
Sources
- Introducing the Anthropic Cyber Mission: Anthropic, Oct 8, 2026
- Anthropic launches $15M cyber defense program for state, local, tribal and territorial governments: StateScoop
