Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Foundations for OT Cybersecurity: From Inventory to Impact
Deep Dive Patrick Miller Deep Dive Patrick Miller

Foundations for OT Cybersecurity: From Inventory to Impact

CISA’s new OT asset-inventory guidance puts structure behind “know your system.” This post translates it into action: a practical, prioritized field set and taxonomy you can implement now. We added a lightweight BIA overlay that links asset criticality to mission impact. We also show where to emphasize configuration baselines, change control, and logging to improve monitoring and decision quality.

Read More
Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook

New York has proposed the first mandatory cybersecurity regulation for water and wastewater systems, targeting utilities serving over 3,300 people. With requirements for vulnerability assessments, incident reporting, and executive oversight, this rule signals a shift toward enforceable cyber resilience and other states may soon follow.

Read More
The Pillars of an Effective Incident Response Plan
Skill Set Patrick Miller Skill Set Patrick Miller

The Pillars of an Effective Incident Response Plan

A strong Incident Response Plan (IRP) is more than just a document—it’s a foundation built on key elements like asset inventory, network diagrams, logging, communication strategies, backups, and clear roles. In this blog, Dan Ricci, Senior Cybersecurity Consultant at Ampyx Cyber, breaks down the critical components every IRP needs to be resilient and effective in the face of cyber incidents.

Read More
Proactive Cyber Defense: Recognizing Cyber Intrusions for Critical Infrastructure System Operators
Skill Set Patrick Miller Skill Set Patrick Miller

Proactive Cyber Defense: Recognizing Cyber Intrusions for Critical Infrastructure System Operators

Leveraging Guidance from the Electric & Water Sectors and Broadening for all Critical Infrastructure. In an era marked by rapid digital transformation and increasing cyber threats, whether electric, water and wastewater systems, chemical, or any other of the critical infrastructure sectors, it is imperative for control system operators to be well-versed in recognizing and responding to cyber intrusions.

Read More
Exploring the Evolving Landscape of ICS/OT Cybersecurity at RSAC 2024
Event Edge Patrick Miller Event Edge Patrick Miller

Exploring the Evolving Landscape of ICS/OT Cybersecurity at RSAC 2024

The RSA Conference 2024 spotlighted the critical importance of ICS/OT cybersecurity, reflecting a significant increase in attention compared to previous years. Ampyx Cyber CEO, Patrick Miller noted the strong presence of AI-driven security tools on the vendor floor and highlighted the conference's rich agenda featuring discussions on the convergence of IT and OT. As digital transformation continues, the industry's commitment to enhancing ICS/OT cybersecurity is more evident than ever.

Read More
Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking
Patrick Miller Patrick Miller

Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking

The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) on April 4, 2024 published its proposed rules requiring critical infrastructure entities to report significant cyber incidents and ransom payments to CISA. The proposed regulations are intended to consolidate, fortify, and strengthen the United States’ cyber defenses in critical infrastructure (CI) sectors.

Read More
Ampere Industrial Security Evolves into Ampyx Cyber
Patrick Miller Patrick Miller

Ampere Industrial Security Evolves into Ampyx Cyber

Ampere Industrial Security, renowned for its expertise in industrial security, announces its rebranding to Ampyx Cyber, marking a new chapter in its global presence with offices in Portland, OR, USA, and a new European base in Tallinn, Estonia. This strategic change represents an expanded commitment to providing top-tier cybersecurity solutions across continents.

Read More
The European Union's Upgraded NIS2 Cybersecurity Framework
NIS2 Patrick Miller NIS2 Patrick Miller

The European Union's Upgraded NIS2 Cybersecurity Framework

The European Union, with its commitment to digital governance and cyber protection, has recently updated its foundational cybersecurity framework, repealing the previous Network and Information Systems Directive (“NIS”) with the NIS2 Directive. Take a dive into the notable changes, implications, and suggested actions for businesses that fall under its scope.

Read More
Is SBOM the answer?
SBOM Patrick Miller SBOM Patrick Miller

Is SBOM the answer?

Government and industry experts have recently pointed to software bill of materials (SBOM) as a requirement for organizations, but what are you getting? David Foose spends some time exploring aspects of SBOM fever.

Read More
S4x23 Trip Report
Conference Patrick Miller Conference Patrick Miller

S4x23 Trip Report

This year, the S4 event hosted by Dale Peterson (DigitalBond) was bigger than ever. New venue, new content, new challenges, new theme, and a new feel. Here’s a report of my experience with some bad, some good and some great things that happened.

Read More
20 years of NERC CIP - What's next?
NERC CIP Patrick Miller NERC CIP Patrick Miller

20 years of NERC CIP - What's next?

Two industry veterans who cultivated NERC CIP over the past 20 years discuss how it all started, and what’s next for electric power industry security regulations. Patrick C. Miller, one of the first NERC CIP auditors in the country, and Carter Manucy, a utility IT/OT Security Director, talk about the regulation that changed the electric sector cybersecurity landscape forever.

Read More

Ask An Expert

GOT A TOUGH QUESTION?

Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no hassle and no commitment. We will not put you on a contact list and our sales team won’t harass you. We will always respect your privacy. We promise. Just real answers from real experts for real problems.