Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network
A second Polish combined heat and power plant was hit the same morning as the December 2025 attacks. CERT Polska's follow-up report describes something no one had seen in the wild, an attacker pivoting into an operational technology network across a shared private cellular network (a private APN). It explains how the chain worked, why the weak link sat on infrastructure the plant did not control, and what every operator relying on a private APN should check now.
New Joint Agency Guidance: Secure Connectivity Principles for OT
A Five Eyes plus European intelligence coalition has published a new doctrine for securing OT connectivity against nation-state threats. This Deep Dive examines what the NCSC principles mean for utilities and industrial operators, what breaks in legacy environments, and the safety, cost, and engineering realities of moving from compliance-driven security to true operational resilience.
Volt Typhoon and the Quiet Pre-Positioning of the U.S. Power Grid [Updated]
Volt Typhoon represents a quiet but strategic cyber threat to U.S. electric utilities, characterized by long-term access and persistence rather than immediate disruption. Rather than deploying malware, the actor relies on legitimate administrative tools to maintain durable access inside critical infrastructure networks. This blog examines what makes Volt Typhoon different and why early detection depends on behavioral context, not signatures.