Ampyx Cyber Blog
The Intersection of Regulation & Resilience
Four Things in the EO 14421 Webinar That Aren't in the RFI
The Department of Energy (DOE) held its public webinar on the Executive Order (EO) 14421 request for information (RFI) on September 16. Most of the hour restated the notice, but four things came up that aren't in the RFI text at all. The one with the shortest fuse is that a phone call to DOE about this proceeding puts a memo in the public docket, and you're the one who has to write it.
Who Owns the Risk? The AI Reliability Boundary Assessment Questions
An AI decision-support platform fails at 2:07 on a weekday afternoon. At 2:22 the fifteen-minute reliability window closes and the vendor is still investigating. This is the full question set from the CYBR.SEC.CON talk, forty questions across four NERC CIP standards plus the ownership map behind them. You score your own answers, and nothing on this page collects anything.
CIP-014-4 Approved: The New Physical Security Risk Assessment and the 2028 Clock
FERC approved Reliability Standard CIP-014-4 on September 10, 2026 in Docket No. RD26-9-000, and the version number understates the change. CIP-014-3 had six requirements. CIP-014-4 has ten, three of them new. The risk assessment now needs a documented methodology, mandatory dynamic simulations, and a neighboring substation in the model. All of it has to be finished by October 1, 2028.
Question H-3: DOE Asks Whether Industry Should Execute the Bulk-Power Order
DOE's Request for Information on Executive Order 14421 includes one question, H-3, asking whether industry standards bodies and third-party labs can execute the order instead of the federal government. The electric sector ran something close to this before, under the Electric Reliability Organization. This post looks at what changes when the statute is IEEPA, not the Federal Power Act, and what a working precedent outside the sector suggests.
Nothing Is Grandfathered: The EO 14421 RFI on Existing Equipment
DOE has opened a 30-day request for information on how it will implement Executive Order 14421, the order restricting foreign-produced bulk-power system equipment. The most consequential questions concern equipment already installed, since the order does not grandfather it, and how DOE will define "foreign-produced" in the first place. Comments are due October 9, with a public webinar on September 16.
Top 10 Computational Load Accountability Mapping Questions for Leaders
NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.
Executive Order 14421 and the Bulk-Power System Supply Chain [Updated]
An executive order signed August 26, 2026 declares a national emergency over foreign-produced bulk-power system electric equipment. It reaches 69 kV and above, adds software, firmware, a list of OT/ICS gear, and vendor remote access to scope, and creates authority to condition or remove equipment already installed. Here is what changed since the 2020 order, where it meets CIP-003-9 and CIP-013-2, and what to do before December 24.
The Computational Load Entity Just Became Two
NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.
Interconnection Gets Teeth: Virginia Puts Cyber into the Rulebook
Virginia moves cyber into DER interconnection. State Corporation Commission (SCC) Staff proposes adopting IEEE 1547.3-2023 and the NARUC/DOE Baselines, requiring utilities to publish minimum cybersecurity standards, audit & report annually, and align Technical Interconnection (TIIR) settings for secure comms/ports. Bottom line: meeting utility cyber controls becomes a condition of interconnection.
Communication avalanche: What utilities need to think about before a nation-state cyberattack happens to them
Utilities are preparing for the technical side of a cyberattack generated by the Russia-Ukraine conflict. But there is another aspect to these attacks that can cause chaos if you’re not ready. We’ll explore that here.