Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Top 10 Computational Load Accountability Mapping Questions for Leaders
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Top 10 Computational Load Accountability Mapping Questions for Leaders

NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.

Read More
An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind [Updated]
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind [Updated]

Water utilities in at least seven states reported cyber incidents this summer, and Congress now has two answers that point in opposite directions. One bill gives EPA direct authority. The other certifies a sector-led body to write and enforce the requirements, modeled on the electric sector. A close read of what H.R. 2594 borrows from the Federal Power Act, where it departs, and what twenty years inside that model cost.

Read More
Executive Order 14421 and the Bulk-Power System Supply Chain
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Executive Order 14421 and the Bulk-Power System Supply Chain

An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.

Read More
The Computational Load Entity Just Became Two
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

The Computational Load Entity Just Became Two

NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.

Read More
Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend

There is no rulebook for securing an OT environment, and there never could be. Two utilities can make entirely different choices and both be defensible. Here is how to build an OT risk management program you can stand behind: map your environment, rank the consequences you will not tolerate, choose controls deliberately, and document why, so you can defend every decision an auditor asks about.

Read More
What Is a Computational Load Entity?
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

What Is a Computational Load Entity?

A large AI data center used to be just a customer of the grid. On July 16, 2026, FERC changed that, directing NERC to create the Computational Load Entity, a new class of registered entity subject to mandatory federal reliability standards. A plain-English guide to what the category is and why it exists, and the anchor for the AI Reliability Boundary series.

Read More
NERC Computational Load Alert: August 3 Deadline for Utilities 2026
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC Computational Load Alert: August 3 Deadline for Utilities 2026

The NERC Level 3 alert on computational load looks voluntary, but Rule 810 makes the August 3 response mandatory, and a July FERC order turns the guidance into standards due by the end of 2026. What to file before the deadline, which gaps to start closing by role, and why unpriced AI load risk surfaces in prudency reviews, interconnection revenue, and daily penalties.

Read More
NERC Computational Load Standards: FERC Sets December 2026 Deadlines
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC Computational Load Standards: FERC Sets December 2026 Deadlines

FERC did not accelerate NERC's timeline, it made the calendar a directive and moved registration onto the critical path. The order creates the computational load entity, sets the December 31 and March 1 deadlines, and leaves the AI Reliability Boundary, the line between what the grid must command and what it leaves to private contract, for Phase II to draw. What is settled, what is not, and what to do in the next ninety days.

Read More
Cloud Comes to NERC CIP: The 100-Series and Project 2023-09
Deep Dive Patrick Miller Deep Dive Patrick Miller

Cloud Comes to NERC CIP: The 100-Series and Project 2023-09

NERC did not revise the CIP Standards for the cloud. It forked them. Project 2023-09 introduces a parallel 100-Series, an entity can elect into per system, built on a new foundation called BES Cyber Services and Systems (BCSS), with System Security Plans replacing asset lists and Cyber Security Zones replacing the Electronic Security Perimeter. Here is how the parallel track works, what the first drafts actually say, and the open problems worth commenting on before August 21.

Read More
Using the Work of Others in NERC CIP and O&P Compliance
Deep Dive Patrick Miller Deep Dive Patrick Miller

Using the Work of Others in NERC CIP and O&P Compliance

The work of others lets you lean on someone else's assessment as compliance evidence. It does not transfer accountability. This breakdown maps the ERO guidance stack, the two-part test auditors apply, worked examples for CIP-013 vendor assessments and BCSI in the cloud, the FERC FY2025 findings on delegation gone wrong, and the audit prep questions to answer first.

Read More
NERC MSPP Rules of Procedure: Standards Committee Retired in May 2026 Draft
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

NERC MSPP Rules of Procedure: Standards Committee Retired in May 2026 Draft

NERC's May 2026 draft Rules of Procedure revisions retire the Standards Committee, eliminate ballot pools, restructure the Registered Ballot Body, and create a new Reliability Standards Body under the RISC. The MSPP Task Force implementation package is the most consequential governance change to NERC standards development since the ERO model was certified in 2006.

Read More
Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure

Documented load losses approaching one thousand megawatts in seconds. A Level 3 Essential Action Alert. A final Reliability Guideline. Proposed registration of a new Computational Load Entity. NERC's May 2026 actions mark a structural shift in how data centers, hyperscale AI training, and cryptocurrency mining are treated under the North American grid reliability framework.

Read More
FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do

FERC unanimously approved Order Nos. 918 and 919 on March 19, 2026, finalizing CIP virtualization standards and new low-impact BES Cyber System controls, plus an updated "Control Center" definition. All CIP-registered entities are affected. Implementation windows are 24 and 36 months respectively. Compliance programs should begin gap assessments now.

Read More
Redesigning the Machine: NERC Board Accepts Transformational Standards Modernization Plan
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Redesigning the Machine: NERC Board Accepts Transformational Standards Modernization Plan

The NERC Board has approved a historic transformation of the standards development process to meet the speed of the modern grid. Aiming for a 12–18 month timeline, the new framework re-engineers how NERC addresses risks from data centers, IBRs, and VPPs. Read our deep dive into the 2027 roadmap, the new SME pool, and the upcoming shift in voting eligibility.

Read More
FERC 2025 CIP Audit Findings: DER Impact Ratings, Vendor Oversight Gaps, and Cloud Compliance Risk
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC 2025 CIP Audit Findings: DER Impact Ratings, Vendor Oversight Gaps, and Cloud Compliance Risk

FERC’s latest CIP audit lessons for 2025 highlight three rising compliance risks. Entities are undercounting DERs in GOP control center impact ratings, outsourcing compliance work without adequate oversight, and moving EACMS or PACS functions to the cloud without a defensible evidence path. These issues now represent real audit exposure across the US bulk power system.

Read More
Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management

FERC Order 912 marks a shift in supply chain cybersecurity for the Bulk-Power System. It directs NERC to strengthen supply chain protections by closing gaps in risk identification, reassessment, and response, and by extending coverage to Protected Cyber Assets. Vendor data validation is encouraged but not mandated, and NERC has 18 months to deliver new or revised standards.

Read More
Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains

FERC’s September 2025 actions reshaped grid reliability standards by tightening security requirements for low-impact assets, adding authentication, encryption, and monitoring; new requirements and new definitions to support secure adoption of virtualization technologies; and expanding supply chain protections to cover Protected Cyber Assets and other connected systems.

Read More
CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope

FERC Order 907-A clarifies CIP-015 on shared networks. INSM must monitor only east-west traffic used for access monitoring of EACMS and PACS. Non-CIP assets and data flows are out of scope, even in mixed-use or commingled PACS/EACMS environments. Learn practical patterns to filter collection, segment analytics, and produce audit-ready evidence.

Read More