Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management

FERC Order 912 marks a shift in supply chain cybersecurity for the Bulk-Power System. It directs NERC to strengthen supply chain protections by closing gaps in risk identification, reassessment, and response, and by extending coverage to Protected Cyber Assets. Vendor data validation is encouraged but not mandated, and NERC has 18 months to deliver new or revised standards.

Read More
FERC’s New Proposed Rule on Supply Chain Risk Management (SCRM)
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

FERC’s New Proposed Rule on Supply Chain Risk Management (SCRM)

The Federal Energy Regulatory Commission (FERC) has released a new Notice of Proposed Rulemaking (NOPR) under Docket No. RM24-4-000, focusing on supply chain risk management (SCRM) for the Bulk-Power System (BPS). This proposed directive aims to fill critical gaps in existing NERC Critical Infrastructure Protection (CIP) standards and bolster the defenses of our nation’s critical infrastructure.

Read More
Is SBOM the answer?
Deep Dive Patrick Miller Deep Dive Patrick Miller

Is SBOM the answer?

Government and industry experts have recently pointed to software bill of materials (SBOM) as a requirement for organizations, but what are you getting? David Foose spends some time exploring aspects of SBOM fever.

Read More