Resilient. Secure. Compliant. NERC CIP and ICS/OT Security. We keep you ahead of your adversaries - and your auditors.

Webinar: Stop the Fire Drill

alarm-3410065_1920.jpg

Risk-Informed Remediation for NERC CIP

 
 

Webinar Abstract

Remediation under NERC CIP can feel like an endless cycle of urgent fixes, audit prep sprints, and reactive decisions. But what if there were a better way—one that helps you prioritize remediation efforts based on actual risk, not just compliance pressure?

Join Patrick C. Miller (Ampyx Cyber), Philip Huff (Bastazo), Scott Rosenberger (Vistra Energy), and Dave Revill (Georgia System Operations Corporation) as they as they tackle the toughest challenges in NERC CIP patch management and discuss smarter approaches to managing remediation within the NERC CIP framework. Based on Bastazo’s recent whitepaper, this session also explores how a risk-informed remediation management strategy can improve operational resilience, reduce compliance fatigue, and drive meaningful security outcomes.

We’ll cover

  • Trace the evolution of NERC CIP patch management and CIP-007 R2

  • Understand why patching is the industry’s most violated NERC requirement

  • How to use risk context to drive smarter remediation decisions

  • Practical tools and methods to implement risk-informed CIP remediation

  • Real-world scenarios and lessons learned

Whether you’re a CIP compliance lead, OT cybersecurity professional, or utility executive, this is your chance to rethink how your organization handles remediation—before the next audit or incident forces your hand.

 
 

Speaker Bios:

 

Moderator

Patrick Miller, President & CEO, ampyx cyber

Patrick Miller has dedicated his career to the protection and defense of critical infrastructures as a trusted independent security and regulatory advisor for more than 35 years. In addition to being the CEO of the industrial cybersecurity consulting firm AMPYX CYBER, he was one of the original architects and the first regulator of the NERC CIP Standards in North America and former Principal Investigator for the US Department of Energy’s National Electric Sector Cybersecurity Organization. Patrick is an internationally recognized public speaker, as well as an instructor for the Industrial Cybersecurity Center in Spain, Cyber Information Security Leader (CISL) program in Denmark, and formerly for the SANS Institute in the United States. Mr. Miller's diverse background spans the Energy, Water, Telecommunications, Financial, and Insurance Services verticals including key positions with regulatory agencies, private consulting firms, utility asset owners and commercial organizations.

 

Panelist

Philip Huff, Co-Founder & Chief Scientist, Bastazo

Philip is Co-Founder and Chief Scientist at Bastazo, an AI-driven cybersecurity company dedicated to defending the systems that power our world. At Bastazo, he leads research and development, applying artificial intelligence and advanced analytics to deliver innovative cybersecurity solutions that empower organizations to proactively defend their critical infrastructure.

With over 15 years of experience managing cybersecurity operations in the electric sector, his expertise spans threat intelligence, vulnerability management, incident response, and strategic cybersecurity planning. His career has focused extensively on enhancing operational resilience and security posture through technological innovation and workforce development initiatives.

In addition to his role at Bastazo, he serves as an Associate Professor of Cybersecurity at the University of Arkansas at Little Rock and Director of the Cyberspace Operations Research and Education (CORE) Center. Through this role, he works to bridge academia and industry, providing the next generation of students with highly relevant and cutting-edge degree programs and research opportunities.

 

Panelist

Scott Rosenberger PE CISSP,
Sr. Director, Generation Cyber Security, Vistra

Scott Rosenberger has a unique distinction—34 is the number that marks how long he has been married, lived in Texas, and worked for Vistra. He holds a Mechanical Engineering degree and is a licensed Professional Engineer in Texas.  He began his career in the electric sector as a design and systems engineer at the Comanche Peak Nuclear Station.

The first half of Scott’s career was rooted in engineering, with roles spanning nuclear, fossil, and corporate settings. With a strong technical acumen, he transitioned into Information Technology, where he has since held multiple roles across corporate, business, and operational technology (OT) environments. For more than a decade, Scott has focused exclusively on cybersecurity for Vistra’s generation fleet.

As a member of the CIP Version 5 Drafting Team, Scott contributed valuable insight by representing the generation sector during the development of industry standards.

Today, Scott serves as the Senior Director of Generation Cyber Security at Vistra, the largest competitive power generator in the United States with approximately 41,000 megawatts of capacity across nuclear, fossil, and renewable assets. He leads cybersecurity efforts to protect the company’s extensive generation portfolio and supports compliance, resilience, and operational integrity.