Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order
DOE's Request for Information on Executive Order 14421 includes one question, H-3, asking whether industry standards bodies and third-party labs can execute the order instead of the federal government. The electric sector ran something close to this before, under the Electric Reliability Organization. This post looks at what changes when the statute is IEEPA, not the Federal Power Act, and what a working precedent outside the sector suggests.
Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment
DOE has opened a 30-day request for information on how it will implement Executive Order 14421, the order restricting foreign-produced bulk-power system equipment. The most consequential questions concern equipment already installed, since the order does not grandfather it, and how DOE will define "foreign-produced" in the first place. Comments are due October 9, with a public webinar on September 16.
Top 10 Computational Load Accountability Mapping Questions for Leaders
NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.
Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
The Computational Load Entity Just Became Two
NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.
Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook
Virginia moves cyber into DER interconnection. State Corporation Commission (SCC) Staff proposes adopting IEEE 1547.3-2023 and the NARUC/DOE Baselines, requiring utilities to publish minimum cybersecurity standards, audit & report annually, and align Technical Interconnection (TIIR) settings for secure comms/ports. Bottom line: meeting utility cyber controls becomes a condition of interconnection.
Communication avalanche: What utilities need to think about before a nation-state cyberattack happens to them
Utilities are preparing for the technical side of a cyberattack generated by the Russia-Ukraine conflict. But there is another aspect to these attacks that can cause chaos if you’re not ready. We’ll explore that here.