Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap: NY's Water Utilities Face New Cyber Rulebook

New York has proposed the first mandatory cybersecurity regulation for water and wastewater systems, targeting utilities serving over 3,300 people. With requirements for vulnerability assessments, incident reporting, and executive oversight, this rule signals a shift toward enforceable cyber resilience and other states may soon follow.

Read More
Broad Scope, Big Impact: NY Mandates Cyber Rules for Public Sector
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Broad Scope, Big Impact: NY Mandates Cyber Rules for Public Sector

New York's new cybersecurity law, Chapter 177 of 2025 (S.7672A / A.6769A), introduces mandatory incident reporting, ransom payment disclosures, annual training, and data protection requirements for public-sector entities. Its broad definitions suggest applicability to both IT and OT systems, signaling a significant expansion in cybersecurity oversight for municipalities and public authorities.

Read More
Canada’s Bill C‑8: A New Era for Cybersecurity Regulation
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Canada’s Bill C‑8: A New Era for Cybersecurity Regulation

Canada is proposing sweeping changes to strengthen its cyber resilience through Bill C‑8. This two-part legislation enhances federal powers over telecom infrastructure and establishes enforceable cybersecurity obligations for critical infrastructure operators. Read our full breakdown of what it means, who it impacts, and what’s next in Parliament.

Read More
Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)
Deep Dive Patrick Miller Deep Dive Patrick Miller

Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)

In the world of Bulk Electric System (BES) cybersecurity, signals of risk don’t always arrive with alarms blaring or malware lighting up dashboards. Sometimes, the signs are quieter—brute force login failures, odd port scans, or a sudden spike in account lockouts. The annual CIP-008-6 report, filed March 21, 2025 by NERC, shines a small but telling light on just such signals.

Read More
Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking
Patrick Miller Patrick Miller

Reporting Cyber Incidents under DHS CIRCIA’s Proposed Rulemaking

The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) on April 4, 2024 published its proposed rules requiring critical infrastructure entities to report significant cyber incidents and ransom payments to CISA. The proposed regulations are intended to consolidate, fortify, and strengthen the United States’ cyber defenses in critical infrastructure (CI) sectors.

Read More
The European Union's Upgraded NIS2 Cybersecurity Framework
NIS2 Patrick Miller NIS2 Patrick Miller

The European Union's Upgraded NIS2 Cybersecurity Framework

The European Union, with its commitment to digital governance and cyber protection, has recently updated its foundational cybersecurity framework, repealing the previous Network and Information Systems Directive (“NIS”) with the NIS2 Directive. Take a dive into the notable changes, implications, and suggested actions for businesses that fall under its scope.

Read More

Ask An Expert

GOT A TOUGH QUESTION?

Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no hassle and no commitment. We will not put you on a contact list and our sales team won’t harass you. We will always respect your privacy. We promise. Just real answers from real experts for real problems.