Ampyx Cyber Blog

The Intersection of Regulation & Resilience

FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Issues Orders on Virtualization and Low Impact: What Changed and What You Need to Do

FERC unanimously approved Order Nos. 918 and 919 on March 19, 2026, finalizing CIP virtualization standards and new low-impact BES Cyber System controls, plus an updated "Control Center" definition. All CIP-registered entities are affected. Implementation windows are 24 and 36 months respectively. Compliance programs should begin gap assessments now.

Read More
Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber on Tap, Part Two: New York's Water Cybersecurity Regulation Is Now in Force

New York's Appendix 5-E cybersecurity regulation for public water systems took effect March 11, 2026, making it the first mandatory, enforceable water cybersecurity framework in the country. This post covers who is in scope, what is required, when it is due, and what resources are available to help. It also examines what New York's action means in the context of a federal policy environment that is actively stepping back from sector-specific cybersecurity regulation.

Read More