The agent representing “CIP”, whose full name is Critical Infrastructure Protection, released a statement this morning that nobody saw coming:
“After nearly twenty years working exclusively with NERC, CIP is now available to all fifteen of the other critical infrastructure sectors, effective immediately.”
Most people outside the field have never had much reason to look closely at what CIP actually does. CIP is a Protection player, which is more versatile than a purely Defense player.
Being a Protection player means system categorization, security management controls, personnel & training, electronic security perimeters, physical security, system security management, incident reporting & response planning, recovery planning, change management & vulnerability assessments, information protection, supply chain risk management, comms between control centers and internal network security.
Consequence management is what drives CIP, not just “Security.”
CIP works to keep high-hazard industrial processes observable, controllable, and operable when the systems around it begin to fail.
In practice, CIPs work entails processes and procedures, change and consequence management, risk decisions, continuity plans and numerous other aspects along with the often slow and arduous cross-functional coordination required to carry them out under pressure across IT, OT, engineering, operations, safety, legal, and the executives who answer for the consequences.
If not for NERC’s mandatory enforcement, CIP’s value tends to surface as the incidents that never escalate into anything worse.
NERC benefited exclusively from CIP’s work for two decades with very few outside the electric sector ever getting to see it, because CIP has spent an entire career inside a single market.
“OT Security” arrived later and made a very different impression, with prevention, detection, and response highlight reels and lights-on products like asset discovery, network monitoring, threat detection, vulnerability management, and secure remote access.
Fans and buyers could watch these tools working, and the money followed quickly. Analysts now estimate OT security’s cap at above twenty billion dollars last year, with the largest investment rounds of the past two years going toward detection and monitoring.
Part of the why comes down to measurement:
OT Security’s produced stat lines like alerts triaged, vulnerabilities closed, and the time it took to detect an intrusion.
CIP’s work doesn’t always fit into that kind of pretty pew-pew dashboard with neat and tidy numbers, sometimes for numbers’ sake.
The practical effect is that an operator who needs a change-control process for field devices, a routine for handling new indicators of compromise, and a defensible decision about running in a degraded state has very little help. Apart from contractors and consultants, they figure it out and do it themselves.
Meanwhile, owners and operators in the water sector often cannot.
The recent joint advisory from the FBI, CISA, NSA, EPA, the Department of Energy, and US Cyber Command brought a lot of this into focus for CIP.
It described Iranian-affiliated actors who had been disrupting programmable logic controllers across government services, water and wastewater, and energy since at least that March, altering the controllers’ project files and presenting operators with a false picture on their HMI and SCADA displays.
The Key Actions guidance is reasonable on its own terms. Operators were told to:
locate exposed devices
change default credentials
place those devices behind secure remote access
collect the published indicators
monitor their networks.
But the gap between the guidance and enactment is where discipline comes into play.
Changing a controller’s exposure without interrupting the process it governs has to be done carefully, often one manufacturer and one site at a time, with an approval chain and a written record of the risk being accepted.
Deciding whether to move a function into a test mode or run it by hand while a continuity plan absorbs the load is a judgment that needs to be signed by the people who own the business consequences rather than the network.
This is the work CIP was meant to do, and almost none of it gets picked up by OT Security.
NERC deserves none of the blame here. The organization valued CIP, built a serious program around it, and renewed the relationship year after year. The exclusivity grew out of a successful partnership that never had reason to look elsewhere.
The consequence was that the other fifteen sectors were left running critical processes without CIP’s comparable play for the discipline.
The other sectors are interested now, and the water sector has perhaps the most frustrating recent history of any of them. After a chain of political and legal events in 2023, the American Water Works Association asked for a collaborative model resembling the one the electric sector already had.
Then, a few weeks after the April advisory, CISA published CI Fortify and instructed operators to assume they’re already compromised and to prepare to run essential services while isolated, degraded, and unable to reach a vendor for weeks or months.
That instruction describes the work CIP does almost exactly, even though it never uses the name.
A quasi-reasonable objection is that Protection as a discipline, CIP’s main game, doesn’t change what the work already is, and that calling something a discipline does not make it one.
But Defense, OT Security’s main game, suggests otherwise.
Defense became fundable, then prominence at conferences, and eventually the subject of regulation only after it had acquired a name and a set of categories that buyers could compare and purchase.
Once fans and buyers can name what they’re acquiring, they can write a budget line for it, weigh competing vendors, and justify the expense to a board. Investment tends to follow that kind of clarity, conferences tend to follow the investment, and regulators usually arrive last, formalizing the practices a market has already settled.
Case in point, NERC’s CIP-015-1.
None of that machinery ever formed around CIP, because OT Security’s flashier game took over and Discipline got lost amongst the tools.
Defense remains genuinely important and will continue to be. The mistake was in treating it as the entire field instead of one capable part of a larger discipline.
In Free Agency, CIP is now available to all fifteen other sectors, and it brings with it a concern for resilience and consequence management alongside prevention and detection.
For the operator who needs a workable runbook more than another sensor, that is welcome news.
When the next advisory arrives, the familiar tools will offer the familiar answers, and the more useful question is whether an owner or operator will finally have somewhere else to turn for enactment.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.