Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

Beyond the Checklist: The Place of Internal Controls in NERC CIP Compliance Programs

NERC CIP compliance is no longer a checklist exercise. Internal controls are now how the ERO Enterprise measures whether an entity can sustain compliance over time. This post breaks down what internal controls are, the preventive, detective, and corrective types, how entities test and evidence them, and how WECC's ICDCT and the December 2025 ERO Guide put controls at the center of audit scoping.

Read More
How it started, where it's going: 20 years of NERC CIP
Policy Pulse Patrick Miller Policy Pulse Patrick Miller

How it started, where it's going: 20 years of NERC CIP

Two key people who helped start NERC CIP 20 years ago talk about how and why it came together, and where it could go next. Patrick C. Miller, one of the first NERC CIP auditors in the country, and Earl Shockley, a former leader at NERC, talk about this momentous regulation that changed the electric sector cybersecurity landscape forever.

Read More