Ampyx Cyber Blog

The Intersection of Regulation & Resilience

An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind

Water utilities in at least seven states reported cyber incidents this summer, and Congress now has two answers that point in opposite directions. One bill gives EPA direct authority. The other certifies a sector-led body to write and enforce the requirements, modeled on the electric sector. A close read of what H.R. 2594 borrows from the Federal Power Act, where it departs, and what twenty years inside that model cost.

Read More
Executive Order 14420 and the Bulk-Power System Supply Chain
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Executive Order 14420 and the Bulk-Power System Supply Chain

An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.

Read More
The Computational Load Entity Just Became Two
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

The Computational Load Entity Just Became Two

NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.

Read More
CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline

FERC approved Reliability Standard CIP-015-2 on August 10, 2026 in a delegated letter order, uncontested and about as short as FERC orders get. The order says the approval is effective as of the date of the order, and that line has caused more confusion than anything else in it. It sets the effective date of the Commission's action, not of anyone's compliance obligation. The internal network security monitoring clock lives in the implementation plan, and it was fixed by CIP-015-1's schedule long before FERC signed. This post walks the two prongs of the effective date calculation, lays out all four compliance dates from October 1, 2028 through October 1, 2031, and explains why the second phase is a carried-forward obligation rather than the one-year extension some entities have read it as.

Read More
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

The AI Reliability Boundary: A Black Hat Debrief for the Grid

Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.

Read More
Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend

There is no rulebook for securing an OT environment, and there never could be. Two utilities can make entirely different choices and both be defensible. Here is how to build an OT risk management program you can stand behind: map your environment, rank the consequences you will not tolerate, choose controls deliberately, and document why, so you can defend every decision an auditor asks about.

Read More
Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network
Deep Dive Patrick Miller Deep Dive Patrick Miller

Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network

A second Polish combined heat and power plant was hit the same morning as the December 2025 attacks. CERT Polska's follow-up report describes something no one had seen in the wild, an attacker pivoting into an operational technology network across a shared private cellular network (a private APN). It explains how the chain worked, why the weak link sat on infrastructure the plant did not control, and what every operator relying on a private APN should check now.

Read More
What Is a Computational Load Entity?
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

What Is a Computational Load Entity?

A large AI data center used to be just a customer of the grid. On July 16, 2026, FERC changed that, directing NERC to create the Computational Load Entity, a new class of registered entity subject to mandatory federal reliability standards. A plain-English guide to what the category is and why it exists, and the anchor for the AI Reliability Boundary series.

Read More
NERC Computational Load Alert: August 3 Deadline for Utilities 2026
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC Computational Load Alert: August 3 Deadline for Utilities 2026

The NERC Level 3 alert on computational load looks voluntary, but Rule 810 makes the August 3 response mandatory, and a July FERC order turns the guidance into standards due by the end of 2026. What to file before the deadline, which gaps to start closing by role, and why unpriced AI load risk surfaces in prudency reviews, interconnection revenue, and daily penalties.

Read More
Ampyx Cyber Joins the E-ISAC Vendor Affiliate Program
Ampyx Arc Patrick Miller Ampyx Arc Patrick Miller

Ampyx Cyber Joins the E-ISAC Vendor Affiliate Program

Ampyx Cyber has joined the Electricity Information Sharing and Analysis Center (E-ISAC) Vendor Affiliate Program. For a services firm that sits across a wide cross-section of the electric sector, membership formalizes something we already believed: grid threat intelligence is only as good as its willingness to move in both directions.

Read More
NERC Computational Load Standards: FERC Sets December 2026 Deadlines
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC Computational Load Standards: FERC Sets December 2026 Deadlines

FERC did not accelerate NERC's timeline, it made the calendar a directive and moved registration onto the critical path. The order creates the computational load entity, sets the December 31 and March 1 deadlines, and leaves the AI Reliability Boundary, the line between what the grid must command and what it leaves to private contract, for Phase II to draw. What is settled, what is not, and what to do in the next ninety days.

Read More
Cloud Comes to NERC CIP: The 100-Series and Project 2023-09
Deep Dive Patrick Miller Deep Dive Patrick Miller

Cloud Comes to NERC CIP: The 100-Series and Project 2023-09

NERC did not revise the CIP Standards for the cloud. It forked them. Project 2023-09 introduces a parallel 100-Series, an entity can elect into per system, built on a new foundation called BES Cyber Services and Systems (BCSS), with System Security Plans replacing asset lists and Cyber Security Zones replacing the Electronic Security Perimeter. Here is how the parallel track works, what the first drafts actually say, and the open problems worth commenting on before August 21.

Read More
Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs

NERC CIP compliance is no longer a checklist exercise. Internal controls are now how the ERO Enterprise measures whether an entity can sustain compliance over time. This post breaks down what internal controls are, the preventive, detective, and corrective types, how entities test and evidence them, and how WECC's ICDCT and the December 2025 ERO Guide put controls at the center of audit scoping.

Read More
ANCHOR-CI: The Partnership Framework Returns, the Liability Shield Does Not
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

ANCHOR-CI: The Partnership Framework Returns, the Liability Shield Does Not

DHS just reopened the closed-door forum where critical infrastructure operators and federal agencies compare notes on cyber threats in private. The legal protection that once made those conversations safe did not come back with it. ANCHOR-CI restores the room and leaves the shield behind, and here is what that changes for anyone who plans to speak in it.

Read More
Using the Work of Others in NERC CIP and O&P Compliance
Deep Dive Patrick Miller Deep Dive Patrick Miller

Using the Work of Others in NERC CIP and O&P Compliance

The work of others lets you lean on someone else's assessment as compliance evidence. It does not transfer accountability. This breakdown maps the ERO guidance stack, the two-part test auditors apply, worked examples for CIP-013 vendor assessments and BCSI in the cloud, the FERC FY2025 findings on delegation gone wrong, and the audit prep questions to answer first.

Read More
NERC MSPP Rules of Procedure: Standards Committee Retired in May 2026 Draft
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC MSPP Rules of Procedure: Standards Committee Retired in May 2026 Draft

NERC's May 2026 draft Rules of Procedure revisions retire the Standards Committee, eliminate ballot pools, restructure the Registered Ballot Body, and create a new Reliability Standards Body under the RISC. The MSPP Task Force implementation package is the most consequential governance change to NERC standards development since the ERO model was certified in 2006.

Read More
Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure

Documented load losses approaching one thousand megawatts in seconds. A Level 3 Essential Action Alert. A final Reliability Guideline. Proposed registration of a new Computational Load Entity. NERC's May 2026 actions mark a structural shift in how data centers, hyperscale AI training, and cryptocurrency mining are treated under the North American grid reliability framework.

Read More
What Multi-Region Entities Need to Know About Coordinated Oversight in 2026 [Updated]
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

What Multi-Region Entities Need to Know About Coordinated Oversight in 2026 [Updated]

NERC's Coordinated Oversight Program lets multi-region entities consolidate compliance monitoring under one Lead Regional Entity, eliminating duplicate audits across six footprints. New for 2026: Category 2 GO/GOP eligibility opens May 15, annual asset verification becomes formal, periodic group reviews go standard. Breakdown of qualifications, modification paths, and audit prep questions.

Read More
Protocol Converters: The 2023 SAR Just Got Validated (Again)
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Protocol Converters: The 2023 SAR Just Got Validated (Again)

The 2023 NERC SAR asked whether protocol converters belong inside CIP-002. A new disclosure of 22 CVEs in serial-to-Ethernet hardware, set against a decade of advisories across the category, settles the question. The categorization debate now has its empirical record, and asset owners have CIP-007 R2 and CIP-013 work to do that does not wait for the standard.

Read More