About Us

Who We Are…

We are a specialized firm who have seen the industrial world from every seat. Our ethos is to provide the straight and honest advisory required to secure the systems that power our societies, without wasting time or compromising integrity. We prioritize the safety and reliability of the operation above all else, translating complex global regulations and deep technical security practices into pragmatic, field-hardened strategies that work.


Ampyx Cyber is a specialized, services-only, international consulting firm with operations in North America and Europe. We focus on industrial control systems (ICS) and operational technology (OT) security. Protecting critical infrastructure is our craft.

We set out to build a different kind of firm with a unique concentration on the industrial ecosystem, comprised of people who have dedicated their careers to it. Our consultants are carefully selected for their productivity, professionalism, and integrity as well as their deep industry technical knowledge and cybersecurity experience.

We understand the industrial world because we come from it. We have been operations staff, security practitioners, and management at industrial asset owners. We’ve worked within equipment and technology manufacturers. We have drafted and influenced regulations and international standards. We have even been the federal regulator performing the audits and issuing the violations. We’ve seen it from all sides at all levels. But most importantly, we tell it to you plain and simple, straight and honest - without wasting your time.

We are 100% independent and technology-agnostic. We don’t sell or promote any hardware or software. We have firmly decided to receive no compensation whatsoever tied to recommending any solution or product to our clients. No channel partnerships, no kickbacks, no profit sharing, no referral bonus - zero means zero. This allows us to meet you where you are and work with what you have. It ensures our recommendations are truly free from influence. We can work with all available options to provide you with the best fit for your unique situation.

We operate fluently across the global regulatory landscape. Whether you are navigating NERC CIP in North America, NIS2 (all transpositions), CER and CRA in Europe, or international frameworks like IEC 62443 or ISO 27001, we understand how these requirements intersect and where they diverge. We don't just track the rules; we help you normalize them into a single, defensible security program that satisfies auditors across borders without duplicating effort.

Our EU operations run through two independently owned and operated European companies: Ampyx Cyber GmbH, registered in Hamburg, Germany, and AmpyxCyber OÜ, registered in Tallinn, Estonia. They operate under the same brand and share the same integrity and professional standards that come with the global Ampyx Cyber name. Neither sits under a US corporate parent or investor. For European clients weighing data residency and jurisdictional exposure across their technology partners and service providers, both entities are EU-registered, governed by European law, with your work and data kept in Europe. Learn more about our EU-sovereign services.

Resilience over hype. Physics over fear. Actions over checklists.

 Our Credentials

Professional Certifications

  • CIPC: Critical Infrastructure Protection Credential - Ampyx Cyber

  • CDEC: OTSEC Cyber Defense Expert Certification - Cyber Defense Center

  • CDAC: OTSEC Cyber Defense Associate Certification - Cyber Defense Center

  • GCIP: GIAC Critical Infrastructure Protection - SANS Institute

  • GICSP: Global Industrial Cyber Security Professional - SANS Institute

  • GSEC: GIAC Security Essentials Certification - SANS Institute

  • GSLC: GIAC Security Leadership Certification - SANS Institute

  • CISSP: Certified Information Systems Security Professional - International Information Systems Security Certification Consortium (ISC2)

  • ISSAP: Information Systems Security Architecture Professional, CISSP Concentration - International Information Systems Security Certification Consortium (ISC2)

  • SSCP: Systems Security Certified Practitioner - International Information Systems Security Certification Consortium (ISC2)

  • CISM: Certified Information Systems Manager - Information Systems Audit and Control Association (ISACA)

  • CISA: Certified Information Systems Auditor - Information Systems Audit and Control Association (ISACA)

  • CRISC: Certified in Risk and Information Systems Control - Information Systems Audit and Control Association (ISACA)

  • CASP+ ce: CompTIA Advanced Security Practitioner Certification - CompTIA

  • Security+: CompTIA Security+ - CompTIA

  • Network+: CompTIA Network+ - CompTIA

  • DHS-CVI: Department of Homeland Security Certified Chemical-terrorism Vulnerability Information Authorized User - DHS

  • CEH: Certified Ethical Hacker - EC Council

  • CHFI: Certified Hacking Forensic Investigator - EC-Council

  • CCISO: Certified Chief Information Security Officer - EC-Council

  • CCSFP: Certified HITRUST CSF Practitioner - HITRUST Alliance

  • ISO 27001 LA: ISMS Lead Auditor, ISO/IEC 27001 - International Organization for Standardization

  • HISP: Holistic Information Security Practitioner

  • ITIL: Information Technology Infrastructure Library

  • NSA IAM: National Security Agency Information Assessment Methodology - INFOSEC Assessment Training and Rating Program (IATRP)

  • ACE: AccessData Certified Examiner - AccessData (Exterro)

  • CBCI: Certificate of the Business Continuity Institute - Business Continuity Institute (BCI)

  • PMP: Project Management Professional - Project Management Institute (PMI)

  • CCNA: Cisco Certified Network Associate - Cisco

  • MCSE: Microsoft Certified Systems Engineer - Microsoft

  • Prosci CMP: Certified Change Management Practitioner - Prosci

  • CSSYB: Certified Six Sigma Yellow Belt

  • CTT+: CompTIA Certified Technical Trainer - CompTIA

  • Server+ / A+ / I-Net+: CompTIA

  • MCDBA: Microsoft Certified Database Administrator - Microsoft

  • CIWP / CIWA: Certified Internet Webmaster Professional & Associate - ProSoft

  • SCP: Snort Certified Professional - SourceFire

  • TCP: Tripwire Certified Professional - Tripwire

Why the Industry Trusts Us

  • Member of the NERC E-ISAC Vendor Affiliate Program

  • First NERC CIP auditor in North America

  • First Manager of NERC CIP Compliance Audits and Investigations at WECC

  • Original CIP Architect: drafting of sections of NERC UAS 1200/1300 and NERC CIP versions 1/2/3

  • Drafting of multiple NERC CIP Interpretations

  • Led and/or participated in >100 NERC CIP Audits in all NERC Regions

  • Contributing member to NERC CIP Supply Chain Working Group (SCWG) guidance publications

  • Contributing member to NERC Security Integration and Technology Enablement Subcommittee (SITES) guidance publications

  • Contributor to NERC/ERO Auditor Manual and Guidance

  • Speaker/contributor to multiple FERC Technical Committees

  • Regular public commentary on FERC NOPRs and Orders

  • SANS ICS456 GCIP instructor

  • Expert Witness Testimony: 2025 U.S.-China Economic and Security Review Congressional Commission (USCC) on Global Energy Infrastructure Security

  • Advisor, Senate 119th Congress, 2nd Session: Bill - Quantum Grid Utility Assurance and Resilient Defense Act of 2026

  • EnergySec NERC CIP Bootcamp instructor and content developer

  • EnergySec Founder, Director and President Emeritus

  • Centro de Ciberseguridad Industrial (CCI) US Coordinator

  • Cyber Senate Steering Member for Industrial Control Cyber Security

  • DOE National Electric Sector Cybersecurity Organization (NESCO) Principal Investigator

  • NARUC/NASEO Cybersecurity Advisory Team for State Solar (CATSS) Advisory Group

  • NARUC/DOE Cybersecurity Advisory Group: Cybersecurity Baselines for Electric Distribution and DER Aggregators

  • National Telecommunications and Information Administration (NTIA) and Idaho National Lab (INL) Software Bill of Materials (SBOM) Energy POC Stakeholders

  • DOE Solar Energy Technology Office (SETO) and National Renewable Energy Lab (NREL) Industry Advisory Board (IAB) for the Securing Solar for the Grid (S2G)

  • Named contributor to DHS CISA Cyber Performance Goals (CPGs)

  • State of Colorado Licensed Professional Investigator

  • NIST CSF to NERC CIP mapping: contributing author to the NIST National Online Informative Reference (OLIR) Program alignment of the NIST Cybersecurity Framework to the NERC CIP Standards

  • Positions cited directly in FERC Order 791 through industry comment submissions

  • Member and E-ISAC liaison to the NERC Cyber Security Analysis Working Group (SCAWG)

  • Participant in the NERC CIP-013 Supply Chain Risk Management Task Force

  • Participant in the E-ISAC Cybersecurity Risk Information Sharing Program (CRISP)

  • Chair of a NERC Regional Entity Critical Infrastructure Protection Sub-Committee, with more than a decade of continuous sub-committee membership

  • DOE National Laboratory Principal Investigator for the DOE EERE Cyber SHIELD program supporting small and mid-sized renewable energy asset owners

  • Co-author of the first Idaho National Laboratory Malcolm deployment guide for solar power generation

  • Tiger Team lead for Safety and Grid Security in the Long Duration Energy Storage (LDES) Consortium, producing the first industry recommendations addressing DOE Pathways to Commercialization findings

  • Founder of the ICS Advisory Project, a free public dashboard suite for CISA ICS advisories used across the OT community

  • Advisory Board & Program Committee for Key Industry Conferences: RSAC, LevelZero, ISC CPH, CyberTek, SANS ICS Summit

Corporate Information

Legal and Corporate Information

Ampyx Cyber operates as a global firm with legal entities established in the United States and Germany to support clients across multiple regions and regulatory environments. For those seeking additional detail, our Legal & Corporate Information page outlines the entities behind the Ampyx Cyber brand and explains how services are delivered across jurisdictions.

Impressum

As part of our operations in Germany and the European Union, Ampyx Cyber GmbH provides legally required corporate disclosures under German law. The Impressum contains official registration, management, and contact information for our German entity and supports transparency for clients, partners, and regulators in the region.

Privacy Policy

Trust is central to our work. Protecting sensitive information and handling data responsibly is foundational to how Ampyx Cyber operates. Our Privacy Policy describes how personal data is collected, used, and safeguarded across our global activities, including how data protection obligations are addressed for users in different regions.

Yellow industrial pipes on the side of a modern building under a clear blue sky.

Our Clients

Client confidentiality is very important to us. Accordingly, we do not list our clients on our website. We typically work with small to large industrial asset owners, hardware and software vendors that serve the industrial sectors, and various municipal and government agencies around the world. We're happy to connect you with references relevant to your industrial sector and/or regulatory environment upon request.

Close-up of a laptop keyboard on grass with a blurred outdoor background.

Careers

A Different Kind of Firm for a Different Kind of Expert.

We value our people because we are our people. There are no corporate egos or sales quotas here, just mission-critical work and the professional autonomy to do it right. We are a diverse, international team that prioritizes integrity, honesty, and the rewarding work of securing the global industrial footprint. If you’re ready to solve real-world challenges, let’s talk.

See our current openings here.