Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order
DOE's Request for Information on Executive Order 14421 includes one question, H-3, asking whether industry standards bodies and third-party labs can execute the order instead of the federal government. The electric sector ran something close to this before, under the Electric Reliability Organization. This post looks at what changes when the statute is IEEPA, not the Federal Power Act, and what a working precedent outside the sector suggests.
Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment
DOE has opened a 30-day request for information on how it will implement Executive Order 14421, the order restricting foreign-produced bulk-power system equipment. The most consequential questions concern equipment already installed, since the order does not grandfather it, and how DOE will define "foreign-produced" in the first place. Comments are due October 9, with a public webinar on September 16.
Top 10 Computational Load Accountability Mapping Questions for Leaders
NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.
Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
The Computational Load Entity Just Became Two
NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.
CIP-015-2 Approved: The FERC Order and the Real Compliance Timeline
FERC approved Reliability Standard CIP-015-2 on August 10, 2026 in a delegated letter order, uncontested and about as short as FERC orders get. The order says the approval is effective as of the date of the order, and that line has caused more confusion than anything else in it. It sets the effective date of the Commission's action, not of anyone's compliance obligation. The internal network security monitoring clock lives in the implementation plan, and it was fixed by CIP-015-1's schedule long before FERC signed. This post walks the two prongs of the effective date calculation, lays out all four compliance dates from October 1, 2028 through October 1, 2031, and explains why the second phase is a carried-forward obligation rather than the one-year extension some entities have read it as.
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.
Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend
There is no rulebook for securing an OT environment, and there never could be. Two utilities can make entirely different choices and both be defensible. Here is how to build an OT risk management program you can stand behind: map your environment, rank the consequences you will not tolerate, choose controls deliberately, and document why, so you can defend every decision an auditor asks about.
Poland's Energy Sector Attack, Part Two: When the Path Into OT Is a Private Cellular Network
A second Polish combined heat and power plant was hit the same morning as the December 2025 attacks. CERT Polska's follow-up report describes something no one had seen in the wild, an attacker pivoting into an operational technology network across a shared private cellular network (a private APN). It explains how the chain worked, why the weak link sat on infrastructure the plant did not control, and what every operator relying on a private APN should check now.
Ampyx Cyber Joins the E-ISAC Vendor Affiliate Program
Ampyx Cyber has joined the Electricity Information Sharing and Analysis Center (E-ISAC) Vendor Affiliate Program. For a services firm that sits across a wide cross-section of the electric sector, membership formalizes something we already believed: grid threat intelligence is only as good as its willingness to move in both directions.