Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Protocol Converters: The 2023 SAR Just Got Validated (Again)
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Protocol Converters: The 2023 SAR Just Got Validated (Again)

The 2023 NERC SAR asked whether protocol converters belong inside CIP-002. A new disclosure of 22 CVEs in serial-to-Ethernet hardware, set against a decade of advisories across the category, settles the question. The categorization debate now has its empirical record, and asset owners have CIP-007 R2 and CIP-013 work to do that does not wait for the standard.

Read More
Claude Mythos and the OT Threat Horizon: What Utility Operators Need to Know Now
Deep Dive Patrick Miller Deep Dive Patrick Miller

Claude Mythos and the OT Threat Horizon: What Utility Operators Need to Know Now

Anthropic's Claude Mythos can autonomously discover zero-day vulnerabilities across every major OS and browser, and the same codebases run in OT/SCADA environments. This post breaks down why Mythos-class AI exploitation tools directly implicate utility operators, which NERC CIP obligations are already in play, and what actions defenders should take before the patch window closes.

Read More
Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force

New York's Appendix 5-E cybersecurity regulation for public water systems took effect March 11, 2026, making it the first mandatory, enforceable water cybersecurity framework in the country. This post covers who is in scope, what is required, when it is due, and what resources are available to help. It also examines what New York's action means in the context of a federal policy environment that is actively stepping back from sector-specific cybersecurity regulation.

Read More
Industry Recognition: Patrick Miller Inducted into Industrial Cyber Hall of Fame
Ampyx Arc Patrick Miller Ampyx Arc Patrick Miller

Industry Recognition: Patrick Miller Inducted into Industrial Cyber Hall of Fame

Ampyx Cyber President and CEO Patrick Miller has been inducted into the Industrial Cyber Hall of Fame, joining a distinguished group of practitioners who helped define industrial cybersecurity as a discipline. The recognition highlights over three decades of work in grid security, NERC CIP development, and critical infrastructure protection around the globe.

Read More
National Cyber Strategy: What It Means for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

National Cyber Strategy: What It Means for Critical Infrastructure

The Trump administration released its long-awaited National Cyber Strategy. Six pages, six pillars, and a clear signal that federal cyber policy is shifting toward offensive posture and regulatory streamlining. For critical infrastructure operators, the document raises more questions than it answers. Here is what it says, what it doesn't, and what you should do about it.

Read More
Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook

Virginia moves cyber into DER interconnection. State Corporation Commission (SCC) Staff proposes adopting IEEE 1547.3-2023 and the NARUC/DOE Baselines, requiring utilities to publish minimum cybersecurity standards, audit & report annually, and align Technical Interconnection (TIIR) settings for secure comms/ports. Bottom line: meeting utility cyber controls becomes a condition of interconnection.

Read More
Skills Elevated: More Ways to Build Cyber Resilience
Skill Set Patrick Miller Skill Set Patrick Miller

Skills Elevated: More Ways to Build Cyber Resilience

Ampyx Cyber is expanding its training portfolio with new courses designed for utilities and critical infrastructure teams. From NERC CIP Bootcamp to OT vulnerability management and ICS packet analysis, our offerings provide more ways to build cyber resilience with practical, field-tested learning.

Read More
Foundations for OT Cybersecurity: From Inventory to Impact
Deep Dive Patrick Miller Deep Dive Patrick Miller

Foundations for OT Cybersecurity: From Inventory to Impact

CISA’s new OT asset-inventory guidance puts structure behind “know your system.” This post translates it into action: a practical, prioritized field set and taxonomy you can implement now. We added a lightweight BIA overlay that links asset criticality to mission impact. We also show where to emphasize configuration baselines, change control, and logging to improve monitoring and decision quality.

Read More
Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook

New York has proposed the first mandatory cybersecurity regulation for water and wastewater systems, targeting utilities serving over 3,300 people. With requirements for vulnerability assessments, incident reporting, and executive oversight, this rule signals a shift toward enforceable cyber resilience and other states may soon follow.

Read More
Texas SB 75: A Lone Star Model for Grid Resilience
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Texas SB 75: A Lone Star Model for Grid Resilience

Texas SB 75 establishes a first-of-its-kind Grid Security Commission to evaluate and enhance the resilience of the state’s electric grid and critical infrastructure. With a broad all-hazards focus, from cyber threats to EMPs, this bipartisan law signals Texas’ intent to lead on proactive, cross-sector grid security. Learn what’s required, what’s coming, and why it matters now.

Read More
Broad Scope, Big Impact: NY Mandates Cyber Rules for Public Sector
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Broad Scope, Big Impact: NY Mandates Cyber Rules for Public Sector

New York's new cybersecurity law, Chapter 177 of 2025 (S.7672A / A.6769A), introduces mandatory incident reporting, ransom payment disclosures, annual training, and data protection requirements for public-sector entities. Its broad definitions suggest applicability to both IT and OT systems, signaling a significant expansion in cybersecurity oversight for municipalities and public authorities.

Read More
Help Shape the Future of the NERC CIP Standards
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Help Shape the Future of the NERC CIP Standards

NERC is asking for industry input on the future of CIP Standards. As part of its 2025 Work Plan, NERC has launched a survey to identify and prioritize emerging security risks to the Bulk Power System. The results will directly inform a roadmap for updating the CIP Standards to address today’s evolving threat landscape. What’s happening, why it matters, and how you can participate before the July 22 deadline.

Read More
Canada’s Bill C‑8: A New Era for Cybersecurity Regulation
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Canada’s Bill C‑8: A New Era for Cybersecurity Regulation

Canada is proposing sweeping changes to strengthen its cyber resilience through Bill C‑8. This two-part legislation enhances federal powers over telecom infrastructure and establishes enforceable cybersecurity obligations for critical infrastructure operators. Read our full breakdown of what it means, who it impacts, and what’s next in Parliament.

Read More
Automation and AI Risks in Long Duration Energy Storage Systems (LDES): Risk Mitigation and Regulatory Responsibilities
Deep Dive Patrick Miller Deep Dive Patrick Miller

Automation and AI Risks in Long Duration Energy Storage Systems (LDES): Risk Mitigation and Regulatory Responsibilities

As Long Duration Energy Storage Systems (LDES) become essential to the future of grid resiliency and renewable integration, the infusion of automation and artificial intelligence (AI) into these technologies presents a range of strategic risks. These include cybersecurity vulnerabilities, operational uncertainties, automation-induced failures, and regulatory gaps. This white paper outlines the major categories of risk and identifies key government, regulatory, and standards bodies responsible for managing and mitigating these challenges.

Read More
The Pillars of an Effective Incident Response Plan
Skill Set Patrick Miller Skill Set Patrick Miller

The Pillars of an Effective Incident Response Plan

A strong Incident Response Plan (IRP) is more than just a document—it’s a foundation built on key elements like asset inventory, network diagrams, logging, communication strategies, backups, and clear roles. In this blog, Dan Ricci, Senior Cybersecurity Consultant at Ampyx Cyber, breaks down the critical components every IRP needs to be resilient and effective in the face of cyber incidents.

Read More
FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know
Deep Dive Patrick Miller Deep Dive Patrick Miller

FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know

In its 2024 CIP audit report, the Federal Energy Regulatory Commission (FERC) shared critical lessons learned from the latest round of reliability audits, revealing key areas where NERC-registered entities can strengthen their security posture. While many organizations successfully met compliance requirements, the report highlighted specific gaps in asset categorization, control center segmentation, and data protection that could pose significant operational risks.

Read More
Exploring the Evolving Landscape of ICS/OT Cybersecurity at RSAC 2024
Event Edge Patrick Miller Event Edge Patrick Miller

Exploring the Evolving Landscape of ICS/OT Cybersecurity at RSAC 2024

The RSA Conference 2024 spotlighted the critical importance of ICS/OT cybersecurity, reflecting a significant increase in attention compared to previous years. Ampyx Cyber CEO, Patrick Miller noted the strong presence of AI-driven security tools on the vendor floor and highlighted the conference's rich agenda featuring discussions on the convergence of IT and OT. As digital transformation continues, the industry's commitment to enhancing ICS/OT cybersecurity is more evident than ever.

Read More