Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Executive Order 14421 and the Bulk-Power System Supply Chain
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Executive Order 14421 and the Bulk-Power System Supply Chain

An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.

Read More
Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Your Environment, Your Risk: Building an OT Risk Management Program You Can Defend

There is no rulebook for securing an OT environment, and there never could be. Two utilities can make entirely different choices and both be defensible. Here is how to build an OT risk management program you can stand behind: map your environment, rank the consequences you will not tolerate, choose controls deliberately, and document why, so you can defend every decision an auditor asks about.

Read More
Cloud Comes to NERC CIP: The 100-Series and Project 2023-09
Deep Dive Patrick Miller Deep Dive Patrick Miller

Cloud Comes to NERC CIP: The 100-Series and Project 2023-09

NERC did not revise the CIP Standards for the cloud. It forked them. Project 2023-09 introduces a parallel 100-Series, an entity can elect into per system, built on a new foundation called BES Cyber Services and Systems (BCSS), with System Security Plans replacing asset lists and Cyber Security Zones replacing the Electronic Security Perimeter. Here is how the parallel track works, what the first drafts actually say, and the open problems worth commenting on before August 21.

Read More
Using the Work of Others in NERC CIP and O&P Compliance
Deep Dive Patrick Miller Deep Dive Patrick Miller

Using the Work of Others in NERC CIP and O&P Compliance

The work of others lets you lean on someone else's assessment as compliance evidence. It does not transfer accountability. This breakdown maps the ERO guidance stack, the two-part test auditors apply, worked examples for CIP-013 vendor assessments and BCSI in the cloud, the FERC FY2025 findings on delegation gone wrong, and the audit prep questions to answer first.

Read More
Protocol Converters: The 2023 SAR Just Got Validated (Again)
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Protocol Converters: The 2023 SAR Just Got Validated (Again)

The 2023 NERC SAR asked whether protocol converters belong inside CIP-002. A new disclosure of 22 CVEs in serial-to-Ethernet hardware, set against a decade of advisories across the category, settles the question. The categorization debate now has its empirical record, and asset owners have CIP-007 R2 and CIP-013 work to do that does not wait for the standard.

Read More
Funded, Not Secured: The April 20 DPA Determinations & the Bulk Electric System
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Funded, Not Secured: The April 20 DPA Determinations & the Bulk Electric System

Two April 20 Defense Production Act determinations expand domestic capacity for grid components and large-scale energy infrastructure. Neither addresses cybersecurity. For the electric sector, NERC CIP and Order 693 standards still apply. A practitioner's view of intersections with CIP-013, CIP-014, PRC, FAC, and TPL, and why domestic capacity is not domestic assurance.

Read More
National Cyber Strategy: What It Means for Critical Infrastructure
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

National Cyber Strategy: What It Means for Critical Infrastructure

The Trump administration released its long-awaited National Cyber Strategy. Six pages, six pillars, and a clear signal that federal cyber policy is shifting toward offensive posture and regulatory streamlining. For critical infrastructure operators, the document raises more questions than it answers. Here is what it says, what it doesn't, and what you should do about it.

Read More
Humans, Engineering Shifts, Required Investment, and Commitment for Operational Security
Deep Dive Patrick Miller Deep Dive Patrick Miller

Humans, Engineering Shifts, Required Investment, and Commitment for Operational Security

New secure connectivity guidance describes a greenfield target architecture, but most OT environments are brownfield reality. True resilience isn't achieved through technology alone. Human expertise, manual operating capability, physical engineering controls, and sustained investment are equally critical. Without these foundations, digital security layers risk becoming expensive new failure modes.

Read More
New NSA UEFI Guidance: Trust Starts Before the OS
Deep Dive Patrick Miller Deep Dive Patrick Miller

New NSA UEFI Guidance: Trust Starts Before the OS

UEFI Secure Boot is widely assumed to be enabled and enforcing, yet recent vulnerabilities show how easily trust at boot time can silently fail. NSA’s new guidance breaks down how Secure Boot actually works, where configurations commonly go wrong, and how organizations can validate and recover trust in the earliest stages of system startup.

Read More
Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Closing the Gaps: FERC Order 912 and the Future of Supply Chain Risk Management

FERC Order 912 marks a shift in supply chain cybersecurity for the Bulk-Power System. It directs NERC to strengthen supply chain protections by closing gaps in risk identification, reassessment, and response, and by extending coverage to Protected Cyber Assets. Vendor data validation is encouraged but not mandated, and NERC has 18 months to deliver new or revised standards.

Read More
Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Securing Tomorrow’s Grid: FERC Acts on Low Impact, Virtualization, and Supply Chains

FERC’s September 2025 actions reshaped grid reliability standards by tightening security requirements for low-impact assets, adding authentication, encryption, and monitoring; new requirements and new definitions to support secure adoption of virtualization technologies; and expanding supply chain protections to cover Protected Cyber Assets and other connected systems.

Read More
Canada’s Bill C‑8: A New Era for Cybersecurity Regulation
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Canada’s Bill C‑8: A New Era for Cybersecurity Regulation

Canada is proposing sweeping changes to strengthen its cyber resilience through Bill C‑8. This two-part legislation enhances federal powers over telecom infrastructure and establishes enforceable cybersecurity obligations for critical infrastructure operators. Read our full breakdown of what it means, who it impacts, and what’s next in Parliament.

Read More
Automation and AI Risks in Long Duration Energy Storage Systems (LDES): Risk Mitigation and Regulatory Responsibilities
Deep Dive Patrick Miller Deep Dive Patrick Miller

Automation and AI Risks in Long Duration Energy Storage Systems (LDES): Risk Mitigation and Regulatory Responsibilities

As Long Duration Energy Storage Systems (LDES) become essential to the future of grid resiliency and renewable integration, the infusion of automation and artificial intelligence (AI) into these technologies presents a range of strategic risks. These include cybersecurity vulnerabilities, operational uncertainties, automation-induced failures, and regulatory gaps. This white paper outlines the major categories of risk and identifies key government, regulatory, and standards bodies responsible for managing and mitigating these challenges.

Read More
Analysis of the June 6th, 2025 Executive Order on Cybersecurity
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Analysis of the June 6th, 2025 Executive Order on Cybersecurity

On June 6, 2025, President Donald J. Trump issued a new Executive Order (EO) titled “Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Orders 13694 and 14144.” This directive serves as a recalibration of federal cybersecurity strategy, signaling a shift away from prescriptive mandates toward more targeted, agency-specific authority and risk-informed investment in critical initiatives. It amends prior EOs while preserving core elements of federal cybersecurity policy.

Read More
Cyber Stress Testing: Strengthening Cyber Resilience in the EU Energy Sector
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Cyber Stress Testing: Strengthening Cyber Resilience in the EU Energy Sector

As cyber threats grow more complex, the EU energy sector is turning to stress testing to bolster its resilience. This post explores ENISA’s 2025 Cyber Stress Test Handbook and how it helps energy providers simulate real-world attacks, uncover vulnerabilities, and strengthen defenses in alignment with NIS2, CER, and the Cyber Solidarity Act.

Read More
Testimony Before the U.S.-China Economic and Security Review Commission: Protecting U.S. Energy Infrastructure from Strategic Risks
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Testimony Before the U.S.-China Economic and Security Review Commission: Protecting U.S. Energy Infrastructure from Strategic Risks

On April 24, 2025, Patrick Miller testified before the U.S.-China Economic and Security Review Commission on the growing cybersecurity and supply chain risks facing U.S. energy infrastructure. My testimony focused on how Chinese state-aligned actors are embedding themselves within critical systems and why securing our grid is essential to preserving America's economic leadership, technological advancement, and national security.

Read More