Keirsten Brager

Senior consultant

Keirsten Brager is a Senior Consultant with Ampyx Cyber, focusing on operational technology security, NERC CIP compliance, and the reliability questions now forming around AI and computational load. She is the founder and principal advisor of Brager Security, a boutique practice that guides utilities and critical infrastructure operators on OT cybersecurity strategy, AI governance, and regulatory compliance.

Her perspective comes from more than a decade inside electric utility security programs rather than from the outside looking in. As a named NERC CIP Senior Delegate she held full accountability for program execution, regulatory outcomes, and audit results across all registered entities and BES Cyber Systems, and served as the authoritative interpreter of NERC CIP across the Texas Reliability Entity, WECC, and NPCC. She carried direct ownership of CIP-002, -004, -007, -008, -010, -011, and -015, with shared accountability across the remaining standards, and delivered two consecutive successful NERC CIP audits by engineering evidence generation and control enforcement into everyday practice rather than a pre-audit sprint.

That last distinction is the through line of her work, treating compliance as a sustained discipline and a floor to build on rather than a box to clear. It also put her early on the problem her Ampyx writing now examines. She authored an OT AI program charter that brought governance and guardrails to AI tools already running in a safety-critical environment, closing a control gap before it became an incident, and her focus sits where reliability, compliance, and national security cannot be pulled apart.

What distinguishes the work is translation across audiences. She gives engineers precise technical direction and gives executives, boards, and regulators the same substance framed as business risk, without losing the accuracy that makes either version useful.

Before founding Brager Security she led OT security engineering and compliance teams inside the electric utility sector, where she automated CIP-007 and CIP-010 evidence production and cut manual compliance work by more than half. She is the author of Secure the Infosec Bag and the forthcoming Grid Grace, a contributing author to Tribe of Hackers, 97 Things Every Information Security Professional Should Know, and The Language of Cybersecurity, and served for nearly a decade as a subject matter expert for CompTIA's CySA+ certification. She speaks and leads workshops on OT security strategy, AI governance, NERC CIP audit readiness, and communicating cyber risk to boards.

Credentials

  • M.S. in Cybersecurity, University of Maryland Global Campus

  • CISSP, Certified Information Systems Security Professional

  • GICSP, Global Industrial Cyber Security Professional

  • Ongoing SANS Institute coursework in ICS/SCADA and generative AI security