Ampyx Cyber Blog

The Intersection of Regulation & Resilience

CIP-002-8, Decoded: Who’s In, Who’s Out Under the New 2.12
Deep Dive Patrick Miller Deep Dive Patrick Miller

CIP-002-8, Decoded: Who’s In, Who’s Out Under the New 2.12

Upcoming NERC CIP-002 grid rules change which control centers fall under stricter cybersecurity protections. This post explains the new test in plain language, who is likely covered, and when local, load-serving areas can qualify for an exception. We also share a quick checklist to help utilities document what they have today and avoid surprises later.

Read More
NERC CIP-002 Standards Authorization Request - Project 2021-03
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC CIP-002 Standards Authorization Request - Project 2021-03

NERC’s CIP-002 Project 2021-03 (Phase 2) introduces key updates to improve clarity and consistency in identifying and classifying BES Cyber Systems. The revisions address long-standing ambiguities by clarifying functional entity roles, refining the treatment of communication protocol converters, revising Criterion 1.3 to establish objective criteria for high-impact control centers, and expanding Criterion 2.6 to include control centers operated by Generator Operators and Transmission Owners. These changes aim to eliminate gaps in protection, align risk-based categorizations across all entities, and support more consistent compliance with CIP standards.

Read More
FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know
Deep Dive Patrick Miller Deep Dive Patrick Miller

FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know

In its 2024 CIP audit report, the Federal Energy Regulatory Commission (FERC) shared critical lessons learned from the latest round of reliability audits, revealing key areas where NERC-registered entities can strengthen their security posture. While many organizations successfully met compliance requirements, the report highlighted specific gaps in asset categorization, control center segmentation, and data protection that could pose significant operational risks.

Read More
Inverter-Based Resources - Guide to Potential NERC CIP Impacts of Upcoming Regulatory Changes
IBR Patrick Miller IBR Patrick Miller

Inverter-Based Resources - Guide to Potential NERC CIP Impacts of Upcoming Regulatory Changes

Upcoming NERC regulatory changes are expected to result in a significant increase in registrations of inverter-based resources, resulting in the likelihood of control centers to be categorized as North American Electrical Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Medium-Impact Control Centers and/or Low-Impact Control Centers and correspondingly to meet the relevant NERC CIP requirements.

Read More

Ask An Expert

GOT A TOUGH QUESTION?

Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no hassle and no commitment. We will not put you on a contact list and our sales team won’t harass you. We will always respect your privacy. We promise. Just real answers from real experts for real problems.