Behind the Grid: What You Need to Know About NERC CIP-015-1

Published July 30, 2025

Critical infrastructure cybersecurity may be facing a turning point given funding cuts proposed by the government. For instance, Cybersecurity Dive reports that cuts to CISA’s budget would impact “funding for vulnerability assessments, training sessions and shared services like security operations centers.” Furthermore, the Environmental Protection Agency, the Department of Health and Human Services, the Department of Energy, and the Transportation Security Administration stand to be impacted, each of which have invested in support for critical infrastructure cybersecurity.

Despite these concerns, action on cybersecurity has occurred elsewhere. Most notably, the Federal Energy Regulatory Commission (FERC) recently approved the North American Electric Reliability Corporation (NERC) CIP-015-1.

What is NERC CIP-015-1?

As written by Anna Ribeiro at Industrial Cyber, “The new standard signals a significant shift for the North American electric sector.” So, what does NERC CIP-015-1 outline? Essentially, it provides a mandated guide for internal network security monitoring of industrial control systems. It is concerned with collection, detection, and analysis processes and is poised to encompass electronic access control and physical access control systems.

The approval of NERC CIP-015-1 follows FERC’s issuing of Order No. 887, which occurred in January 2023. Authors at Inside Privacy explained that No. 887 directed “NERC to develop new INSM requirements for CIP networked environments.”

Why Internal Monitoring Matters on the Grid

The mandate has an operational reason behind it. Johns Hopkins, the University of California, Berkeley, and the New York University Center for Urban Science and Progress studied “compound cyber-attacks and extreme weather events” on electric power networks. The researchers found that an attack carried out in the wake of a weather event increased the potential impact three times more than a standalone cyberattack. Local economies could also experience a 37% drop in economic activity under such a compound threat.

Federal attention has moved in the same direction. In January the Department of Energy allocated $70 million to research into technologies that reduce energy infrastructure exposure to hazards, including cyber threats, natural disasters and climate effects. The department’s cybersecurity office also released best practices for clean energy supply chains, built on insight from energy, automation and industrial control system professionals. The guidance addresses suppliers and end users alike, and its practices include the following.

  • Upholding vulnerability management processes.
  • Offering access to security patches.
  • Ensuring mutual understanding of cybersecurity tools and resources.

Utilities can start by checking where their own view of the network stops, a question at the center of industrial computing built for the energy sector. Seeing the traffic, though, is not the same as being able to steer it once an event is underway.

Addressing NERC CIP-015-1

In the wake of the approval of NERC CIP-015-1, several cybersecurity vendors have promoted their ability to help meet the mandate. While these tools fulfill the monitoring requirement, one key piece is still missing. True control means observing and managing live packet flows directly from the network’s control plane, SNMP, or other management interfaces without relying solely on mirrored traffic. Most solutions require the network to be configured to send a copy of relevant traffic to their sensors, which limits visibility and can compromise an operator’s full control over the network.

Sources

  • “Dwindling federal cyber support for critical infrastructure raises alarms” – Eric Geller, Cybersecurity Dive

https://www.cybersecuritydive.com/news/critical-infrastructure-cybersecurity-federal-support-risk/753686/

  • “FERC approves NERC CIP-015-1 internal network security standard to strengthen ICS defenses” – Anna Ribeiro, Industrial Cyber

https://industrialcyber.co/nerc-cip/ferc-approves-nerc-cip-015-1-internal-network-security-standard-to-strengthen-ics-defenses/

  • “FERC Finalizes New Internal Network Security Monitoring Requirements for Bulk Electric Systems” – Ashden Fein, Caleb Skeath, John Webster Leslie, Shayan Karbassi & Krissy Chapman, Inside Privacy

https://www.insideprivacy.com/critical-infrastructure/ferc-finalizes-new-internal-network-security-monitoring-requirements-for-bulk-electric-systems/

  • “Double Trouble: When Weather Emergencies Meet Malicious Hackers” – Danielle McKenna, Johns Hopkins Whiting School of Engineering

https://engineering.jhu.edu/news/double-trouble-when-weather-emergencies-meet-malicious-hackers/

  • “US DOE to fund resilience tech for energy infrastructure” – Smart Energy International

https://www.smart-energy.com/finance-investment/us-doe-to-fund-resilience-tech-for-energy-infrastructure/

  • “Manufacturing cybersecurity at heart of new White House guidance” – Kate Magill, Manufacturing Dive

https://www.manufacturingdive.com/news/energy-department-cybersecurity-manufacturing-supply-chain-best-practices/719479/

Author: <a href="https://dynics.com/author/dynics-team/" target="_self">Dynics Team</a>

Author: Dynics Team

The Dynics engineering group designs and builds industrial computing hardware and OT cybersecurity systems for the plant floor. Its engineers hold more than 75 years of combined experience, and its plant-floor deployments go back more than 30 years. More than 75% of staff work in product development, design, assembly, and service. Dynics designs, fabricates, and assembles its panel PCs, monitors, rackmount chassis, and security appliances at a 37,500 square foot facility in Ann Arbor, Michigan.

Related Posts

You Might Also Like...