Ampyx Cyber Blog

The Intersection of Regulation & Resilience

The E-ISAC's 2025 Report: Real Progress, Remaining Constraints
Deep Dive Patrick Miller Deep Dive Patrick Miller

The E-ISAC's 2025 Report: Real Progress, Remaining Constraints

The E-ISAC's 2025 End-of-Year Report shows real growth in membership, engagement, and threat intelligence output. But a structural challenge rooted in its funding and governance relationship with NERC continues to limit the incident sharing that collective defense depends on. Comparing E-ISAC's reported numbers against peer ISACs in health and financial services reveals how much ground remains.

Read More
Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking

The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) on April 4, 2024 published its proposed rules requiring critical infrastructure entities to report significant cyber incidents and ransom payments to CISA. The proposed regulations are intended to consolidate, fortify, and strengthen the United States’ cyber defenses in critical infrastructure (CI) sectors.

Read More