Ampyx Cyber Blog

The Intersection of Regulation & Resilience

INSM Just Got Clearer: Key Takeaways from the NATF Guidance
Deep Dive Patrick Miller Deep Dive Patrick Miller

INSM Just Got Clearer: Key Takeaways from the NATF Guidance

NATF has released new CIP-015 INSM guidance that confirms a risk-based approach for collection points, clarifies scope around ESP boundaries, contains numerous useful reference models, and reinforces practical retention strategies. It aligns closely with our INSM playbook, especially on passive visibility, multicast deduplication, and EACMS/BCSI determinations for INSM platforms.

Read More
CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015 Clarified: Mixed-use PACS/EACMS and What’s Actually In Scope

FERC Order 907-A clarifies CIP-015 on shared networks. INSM must monitor only east-west traffic used for access monitoring of EACMS and PACS. Non-CIP assets and data flows are out of scope, even in mixed-use or commingled PACS/EACMS environments. Learn practical patterns to filter collection, segment analytics, and produce audit-ready evidence.

Read More
Foundations for OT Cybersecurity: From Inventory to Impact
Deep Dive Patrick Miller Deep Dive Patrick Miller

Foundations for OT Cybersecurity: From Inventory to Impact

CISA’s new OT asset-inventory guidance puts structure behind “know your system.” This post translates it into action: a practical, prioritized field set and taxonomy you can implement now. We added a lightweight BIA overlay that links asset criticality to mission impact. We also show where to emphasize configuration baselines, change control, and logging to improve monitoring and decision quality.

Read More
CIP-015-1 INSM: A Practical Playbook
Deep Dive Patrick Miller Deep Dive Patrick Miller

CIP-015-1 INSM: A Practical Playbook

NERC CIP-015 makes east-west visibility inside the ESP mandatory. This playbook shows how to stand up INSM the right way through risk-based data feeds, ICS-aware anomaly detection, evaluation tied to incident response, and defensible evidence on a timeline to 10/1/2028 and beyond. Avoid common pitfalls and design now for the likely CIP-015-2 expansion.

Read More
FERC Proposes New Standards for INSM: Internal Network Security Monitoring (CIP-015-1)
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC Proposes New Standards for INSM: Internal Network Security Monitoring (CIP-015-1)

The Federal Energy Regulatory Commission (FERC) has issued a new Notice of Proposed Rulemaking (NOPR) under Docket No. RM24-7-000. This proposed rule seeks to approve NERC’s proposed Critical Infrastructure Protection (CIP) Reliability Standard CIP-015-1. The new standard focuses on Internal Network Security Monitoring (INSM) to detect and address cyber threats within the electronic security perimeter of the Bulk Electric System (BES).

Read More
CIP-015: The Crucial Role of INSM in Strengthening Grid Security
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

CIP-015: The Crucial Role of INSM in Strengthening Grid Security

introduction of CIP-015, a new regulation aimed at enhancing grid security by mandating Internal Network Security Monitoring (INSM) for high and medium impact Bulk Electric System (BES) Cyber Systems. This development, initiated by FERC Order No. 887, responds to the need for robust monitoring within trusted network zones to detect and mitigate potential cyber threats. CIP-015 emerges as a standalone standard after industry feedback suggested that INSM requirements did not align well with existing frameworks, shifting towards an objective-based rather than prescriptive approach.

Read More