Ampyx Cyber Blog

The Intersection of Regulation & Resilience

An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind [Updated]
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind [Updated]

Water utilities in at least seven states reported cyber incidents this summer, and Congress now has two answers that point in opposite directions. One bill gives EPA direct authority. The other certifies a sector-led body to write and enforce the requirements, modeled on the electric sector. A close read of what H.R. 2594 borrows from the Federal Power Act, where it departs, and what twenty years inside that model cost.

Read More
Executive Order 14421 and the Bulk-Power System Supply Chain
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Executive Order 14421 and the Bulk-Power System Supply Chain

An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.

Read More
Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network
Deep Dive Patrick Miller Deep Dive Patrick Miller

Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network

A second Polish combined heat and power plant was hit the same morning as the December 2025 attacks. CERT Polska's follow-up report describes something no one had seen in the wild, an attacker pivoting into an operational technology network across a shared private cellular network (a private APN). It explains how the chain worked, why the weak link sat on infrastructure the plant did not control, and what every operator relying on a private APN should check now.

Read More
Ampyx Cyber Joins the E-ISAC Vendor Affiliate Program
Ampyx Arc Patrick Miller Ampyx Arc Patrick Miller

Ampyx Cyber Joins the E-ISAC Vendor Affiliate Program

Ampyx Cyber has joined the Electricity Information Sharing and Analysis Center (E-ISAC) Vendor Affiliate Program. For a services firm that sits across a wide cross-section of the electric sector, membership formalizes something we already believed: grid threat intelligence is only as good as its willingness to move in both directions.

Read More
ANCHOR-CI: The Partnership Framework Returns, the Liability Shield Does Not
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

ANCHOR-CI: The Partnership Framework Returns, the Liability Shield Does Not

DHS just reopened the closed-door forum where critical infrastructure operators and federal agencies compare notes on cyber threats in private. The legal protection that once made those conversations safe did not come back with it. ANCHOR-CI restores the room and leaves the shield behind, and here is what that changes for anyone who plans to speak in it.

Read More
Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure

Documented load losses approaching one thousand megawatts in seconds. A Level 3 Essential Action Alert. A final Reliability Guideline. Proposed registration of a new Computational Load Entity. NERC's May 2026 actions mark a structural shift in how data centers, hyperscale AI training, and cryptocurrency mining are treated under the North American grid reliability framework.

Read More
Funded, Not Secured: The April 20 DPA Determinations & the Bulk Electric System
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Funded, Not Secured: The April 20 DPA Determinations & the Bulk Electric System

Two April 20 Defense Production Act determinations expand domestic capacity for grid components and large-scale energy infrastructure. Neither addresses cybersecurity. For the electric sector, NERC CIP and Order 693 standards still apply. A practitioner's view of intersections with CIP-013, CIP-014, PRC, FAC, and TPL, and why domestic capacity is not domestic assurance.

Read More
Is Something Weird Happening on Your System?
Deep Dive Patrick Miller Deep Dive Patrick Miller

Is Something Weird Happening on Your System?

Learn how critical infrastructure operators can spot the early signs of cyber intrusions directly from the control room. Drawing on the latest NERC and CISA guidance, this updated guide details specific physical hardware, workstation, and SCADA anomalies to watch for. Empower your frontline staff with a proactive "See Something, Say Something" cyber defense strategy tailored for OT environments.

Read More
Claude Mythos and the OT Threat Horizon: What Utility Operators Need to Know Now
Deep Dive Patrick Miller Deep Dive Patrick Miller

Claude Mythos and the OT Threat Horizon: What Utility Operators Need to Know Now

Anthropic's Claude Mythos can autonomously discover zero-day vulnerabilities across every major OS and browser, and the same codebases run in OT/SCADA environments. This post breaks down why Mythos-class AI exploitation tools directly implicate utility operators, which NERC CIP obligations are already in play, and what actions defenders should take before the patch window closes.

Read More
Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force

New York's Appendix 5-E cybersecurity regulation for public water systems took effect March 11, 2026, making it the first mandatory, enforceable water cybersecurity framework in the country. This post covers who is in scope, what is required, when it is due, and what resources are available to help. It also examines what New York's action means in the context of a federal policy environment that is actively stepping back from sector-specific cybersecurity regulation.

Read More
Industry Recognition: Patrick Miller Inducted into Industrial Cyber Hall of Fame
Ampyx Arc Patrick Miller Ampyx Arc Patrick Miller

Industry Recognition: Patrick Miller Inducted into Industrial Cyber Hall of Fame

Ampyx Cyber President and CEO Patrick Miller has been inducted into the Industrial Cyber Hall of Fame, joining a distinguished group of practitioners who helped define industrial cybersecurity as a discipline. The recognition highlights over three decades of work in grid security, NERC CIP development, and critical infrastructure protection around the globe.

Read More
National Cyber Strategy: What It Means for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

National Cyber Strategy: What It Means for Critical Infrastructure

The Trump administration released its long-awaited National Cyber Strategy. Six pages, six pillars, and a clear signal that federal cyber policy is shifting toward offensive posture and regulatory streamlining. For critical infrastructure operators, the document raises more questions than it answers. Here is what it says, what it doesn't, and what you should do about it.

Read More
Humans, Engineering Shifts, Required Investment, and Commitment for Operational Security
Deep Dive Patrick Miller Deep Dive Patrick Miller

Humans, Engineering Shifts, Required Investment, and Commitment for Operational Security

New secure connectivity guidance describes a greenfield target architecture, but most OT environments are brownfield reality. True resilience isn't achieved through technology alone. Human expertise, manual operating capability, physical engineering controls, and sustained investment are equally critical. Without these foundations, digital security layers risk becoming expensive new failure modes.

Read More
New Joint Agency Guidance: Secure Connectivity Principles for OT
Deep Dive Patrick Miller Deep Dive Patrick Miller

New Joint Agency Guidance: Secure Connectivity Principles for OT

A Five Eyes plus European intelligence coalition has published a new doctrine for securing OT connectivity against nation-state threats. This Deep Dive examines what the NCSC principles mean for utilities and industrial operators, what breaks in legacy environments, and the safety, cost, and engineering realities of moving from compliance-driven security to true operational resilience.

Read More
Volt Typhoon and the Quiet Pre-Positioning of the U.S. Power Grid [Updated]
Deep Dive Patrick Miller Deep Dive Patrick Miller

Volt Typhoon and the Quiet Pre-Positioning of the U.S. Power Grid [Updated]

Volt Typhoon represents a quiet but strategic cyber threat to U.S. electric utilities, characterized by long-term access and persistence rather than immediate disruption. Rather than deploying malware, the actor relies on legitimate administrative tools to maintain durable access inside critical infrastructure networks. This blog examines what makes Volt Typhoon different and why early detection depends on behavioral context, not signatures.

Read More
New NSA UEFI Guidance: Trust Starts Before the OS
Deep Dive Patrick Miller Deep Dive Patrick Miller

New NSA UEFI Guidance: Trust Starts Before the OS

UEFI Secure Boot is widely assumed to be enabled and enforcing, yet recent vulnerabilities show how easily trust at boot time can silently fail. NSA’s new guidance breaks down how Secure Boot actually works, where configurations commonly go wrong, and how organizations can validate and recover trust in the earliest stages of system startup.

Read More