Ampyx Cyber Blog

The Intersection of Regulation & Resilience

The E-ISAC's 2025 Report: Real Progress, Remaining Constraints
Deep Dive Patrick Miller Deep Dive Patrick Miller

The E-ISAC's 2025 Report: Real Progress, Remaining Constraints

The E-ISAC's 2025 End-of-Year Report shows real growth in membership, engagement, and threat intelligence output. But a structural challenge rooted in its funding and governance relationship with NERC continues to limit the incident sharing that collective defense depends on. Comparing E-ISAC's reported numbers against peer ISACs in health and financial services reveals how much ground remains.

Read More
Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)
Deep Dive Patrick Miller Deep Dive Patrick Miller

Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)

In the world of Bulk Electric System (BES) cybersecurity, signals of risk don’t always arrive with alarms blaring or malware lighting up dashboards. Sometimes, the signs are quieter—brute force login failures, odd port scans, or a sudden spike in account lockouts. The annual CIP-008-6 report, filed March 21, 2025 by NERC, shines a small but telling light on just such signals.

Read More