A new reliability standard has been introduced for major U.S. and Canadian electric grid operators, requiring comprehensive monitoring and logging of all network traffic on operational technology (OT) and industrial control systems. The regulation aims to enhance the ability of power companies to detect, prevent, and respond to unauthorized intrusions, particularly in light of recent attacks on the Ukrainian grid by Russian hackers and the discovery of Chinese threat actors within U.S. power company networks.
OT security experts highlight that the mandate is far-reaching, covering not only 'North-South' traffic entering OT networks but also 'East-West' traffic within them, including communications between operator stations, human interface workstations, controllers, and field devices. The sector faces significant challenges in implementing these requirements due to the complexity and scale of the systems involved, making compliance a substantial undertaking for the electricity industry.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Medium-impact and other covered systems have up to two additional years after the first deadline to comply with CIP-15-1, extending the rollout to 2030 for some environments. The phased schedule reflects the complexity and cost of implementing comprehensive OT monitoring across diverse utility networks.
Under the phased rollout of CIP-15-1, operators of critical high-impact sites must meet the new OT monitoring and logging requirements by October 1, 2028. This includes baselining normal behavior, detecting anomalies, and triaging alerts.
NERC introduced reliability standard CIP-15-1 for U.S. and Canadian electric grid operators, requiring monitoring and logging of both perimeter and internal OT network traffic. The rule shifts utilities toward a detect-and-respond, zero trust-style model for high- and medium-impact systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.