Ampyx Cyber Blog

The Intersection of Regulation & Resilience

Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)
Deep Dive Patrick Miller Deep Dive Patrick Miller

Four Years In: What NERC’s Cyber Security Incident Reporting Data Tells Us (and What It Doesn’t)

In the world of Bulk Electric System (BES) cybersecurity, signals of risk don’t always arrive with alarms blaring or malware lighting up dashboards. Sometimes, the signs are quieter—brute force login failures, odd port scans, or a sudden spike in account lockouts. The annual CIP-008-6 report, filed March 21, 2025 by NERC, shines a small but telling light on just such signals.

Read More
Proactively Enhancing Safety in Long Duration Energy Storage: Lessons, Challenges, and Future Strategies
Deep Dive Patrick Miller Deep Dive Patrick Miller

Proactively Enhancing Safety in Long Duration Energy Storage: Lessons, Challenges, and Future Strategies

As Long Duration Energy Storage (LDES) technologies gain prominence in modern energy infrastructure, ensuring the safety of workers and surrounding communities is critical. By examining past incidents involving lithium-ion Battery Energy Storage Systems (BESS) and other storage solutions, we can extract crucial lessons to mitigate risks in LDES deployment.

Read More
FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know
Deep Dive Patrick Miller Deep Dive Patrick Miller

FERC Staff Report Offers Lessons Learned from 2024 CIP Audits: What You Need to Know

In its 2024 CIP audit report, the Federal Energy Regulatory Commission (FERC) shared critical lessons learned from the latest round of reliability audits, revealing key areas where NERC-registered entities can strengthen their security posture. While many organizations successfully met compliance requirements, the report highlighted specific gaps in asset categorization, control center segmentation, and data protection that could pose significant operational risks.

Read More
Is SBOM the answer?
Deep Dive Patrick Miller Deep Dive Patrick Miller

Is SBOM the answer?

Government and industry experts have recently pointed to software bill of materials (SBOM) as a requirement for organizations, but what are you getting? David Foose spends some time exploring aspects of SBOM fever.

Read More