<description>&lt;p dir="ltr"&gt;Patrick Miller has OT cybersecurity experience as an asset owner, PacificCorp. As a regulator and one of the first NERC CIP auditors with WECC. As a community organizer creating and leading EnergySec and the BeerISAC. And as an entrepreneur creating and leading a number of consulting practices. He is currently the Founder of Ampyx Cyber.&lt;/p&gt; &lt;p&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p dir="ltr"&gt;In this episode Patrick and Dale discuss:&lt;/p&gt; &lt;ul&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Why Patrick changed the company name and selected Talinn as the location for the new European office.&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;The major differences in approaches to OT cybersecurity and risk management between Europe and the US. (more than just regulatory differences)&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;What has the EU learned or improved on regulation from NERC CIP.&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;What is the current state of NERC CIP regulatory risk? Are the regulated entities understanding and meeting the standards’ requirements?&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;The challenge of slow NERC CIP modifications, eg virtualization and cloud.&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Bad standard &amp; good regulator v. good standard &amp; bad regulator.&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Should water follow the NERC CIP model as recommended by AWWA?&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;How Patrick is dealing with AI.&lt;/p&gt; &lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt; &lt;p dir="ltr"&gt;Links&lt;/p&gt; &lt;ul&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Ampyx Cyber: &lt;a href= "https://ampyxcyber.com"&gt;https://ampyxcyber.com&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Patrick’s Critical Assets Podcast: &lt;a href= "https://amperesec.com/podcast"&gt;https://amperesec.com/podcast&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Subscribe to Dale’s ICS Security Friday News &amp; Notes: &lt;a href= "https://friday.dale-peterson.com/signup"&gt;https://friday.dale-peterson.com/signup&lt;/a&gt;&lt;/p&gt; &lt;/li&gt; &lt;li dir="ltr" aria-level="1"&gt; &lt;p dir="ltr" role="presentation"&gt;Advertise on Unsolicited Response: &lt;a href= "https://dale-peterson.com/advertising/"&gt;https://dale-peterson.com/advertising/&lt;/a&gt; &lt;/p&gt; &lt;/li&gt; &lt;/ul&gt; &lt;p&gt; &lt;/p&gt;</description>

Unsolicited Response

Dale Peterson: ICS Security Catalyst and S4 Conference Chair

State Of NERC CIP, European Update and OT Security Community

APR 24, 202446 MIN
Unsolicited Response

State Of NERC CIP, European Update and OT Security Community

APR 24, 202446 MIN

Description

Patrick Miller has OT cybersecurity experience as an asset owner, PacificCorp. As a regulator and one of the first NERC CIP auditors with WECC. As a community organizer creating and leading EnergySec and the BeerISAC. And as an entrepreneur creating and leading a number of consulting practices. He is currently the Founder of Ampyx Cyber.

 

In this episode Patrick and Dale discuss:

  • Why Patrick changed the company name and selected Talinn as the location for the new European office.

  • The major differences in approaches to OT cybersecurity and risk management between Europe and the US. (more than just regulatory differences)

  • What has the EU learned or improved on regulation from NERC CIP.

  • What is the current state of NERC CIP regulatory risk? Are the regulated entities understanding and meeting the standards’ requirements?

  • The challenge of slow NERC CIP modifications, eg virtualization and cloud.

  • Bad standard & good regulator v. good standard & bad regulator.

  • Should water follow the NERC CIP model as recommended by AWWA?

  • How Patrick is dealing with AI.

 

Links