Preparing for CIP-015: Building Operational Resilience Through Visibility, Detection, and Segmentation 

July 21, 2026 | by Mark Koenig

Executive Summary 

Utility organizations preparing for CIP-015 should think beyond compliance. The organizations that will be best positioned are those investing in comprehensive network visibility, continuous operational intelligence, and segmentation to strengthen cyber resilience and operational continuity. This article explains what CIP-015 means, why it matters, and how Teneo helps utilities build a practical roadmap toward operational resilience. 

The electric utility industry is navigating a period of significant change. As organizations modernize critical infrastructure, expand operational technology (OT) environments, and defend against increasingly sophisticated cyber threats, they must also adapt to evolving regulatory requirements designed to strengthen the resilience of the power grid. 

One of the latest developments is CIP-015, a new North American Electric Reliability Corporation (NERC) standard that emerged from FERC Order No. 887. The standard introduces Internal Network Security Monitoring (INSM) requirements for applicable Bulk Electric System (BES) Cyber Systems, reflecting a growing recognition that perimeter defenses alone are no longer enough to protect critical infrastructure. 

From Compliance Requirement to Real-World Challenge 

Imagine a utility operator receives an alert indicating unexpected communications between two systems inside a critical substation. 

Is it planned maintenance? A configuration error? The early stages of a cyberattack? Or simply an operational anomaly? 

Without comprehensive visibility into network communications and the ability to investigate what actually occurred, answering those questions quickly can be extremely difficult. 

The longer it takes to understand what is happening, the greater the potential impact on operations, incident response, and regulatory reporting. 

This is exactly the type of operational challenge that CIP-015 is intended to help organizations address. The standard shifts the focus beyond protecting the network perimeter and toward continuously monitoring internal communications, detecting suspicious activity, investigating incidents, and limiting their impact before they disrupt critical operations. 

For utility organizations, the conversation should not simply be about compliance. 

It should be about building an operationally resilient network that enables teams to continuously observe communications, detect abnormal behavior, investigate incidents with confidence, and limit the impact of cyber threats before they disrupt operations. 

Organizations that take this broader approach will not only be better prepared for future compliance requirements, but will also improve network reliability, strengthen cyber resilience, and gain greater operational visibility across both IT and OT environments. 

Why CIP-015 Matters 

Historically, many cybersecurity programs have focused on preventing attackers from entering the network through firewalls, intrusion prevention systems, and other perimeter security controls. 

Recent attacks against critical infrastructure have demonstrated that this approach alone is no longer sufficient. 

Once an attacker gains access, the ability to move laterally across the environment can significantly increase the impact of a security incident. 

Recognizing this shift, the Federal Energy Regulatory Commission (FERC) issued Order No. 887, directing NERC to develop new standards requiring Internal Network Security Monitoring (INSM) for applicable BES Cyber Systems. 

Rather than concentrating solely on keeping threats out, CIP-015 emphasizes the ability to detect, investigate, and respond to suspicious activity occurring inside critical environments. 

At a high level, organizations should be able to: 

  • Continuously monitor communications within critical environments. 
  • Detect unauthorized or abnormal network activity. 
  • Investigate security events using objective network evidence. 
  • Retain and protect monitoring data. 
  • Demonstrate that appropriate monitoring processes and controls are in place. 

Although implementation deadlines are phased over the coming years, utilities should begin evaluating their readiness today. Building the visibility architecture, monitoring capabilities, and operational processes needed to support these objectives cannot happen overnight. 

Compliance Is Only Part of the Story 

While CIP-015 may be driving many organizations to evaluate their current capabilities, compliance is only one outcome. 

The broader objective is operational resilience. 

Utility organizations are also investing to: 

  • Improve grid reliability. 
  • Strengthen cybersecurity across IT and OT environments. 
  • Reduce operational risk. 
  • Shorten incident response times. 
  • Improve troubleshooting. 
  • Demonstrate objective evidence during investigations and audits. 

The same technologies that help organizations prepare for CIP-015 also help improve day-to-day operations. 

Rather than viewing compliance as a one-time project, leading utilities are using it as an opportunity to modernize how they monitor, protect, and operate their critical infrastructure. 

 

See Clearly: Visibility Is the Foundation of Operational Resilience

Every successful monitoring strategy begins with visibility. 

Quite simply, you cannot monitor what you cannot see. 

Many utility environments consist of multiple substations, operational technology networks, enterprise networks, remote locations, cloud services, and third-party connections. As these environments grow more complex, blind spots become increasingly common. 

Without comprehensive access to network traffic, monitoring platforms, cybersecurity tools, and operational teams may all be working from incomplete information. 

This is where Teneo’s Network Visibility solutions, powered by Gigamon and Niagara Networks, provide the foundation for effective monitoring. 

Rather than acting as monitoring tools themselves, these solutions create a pervasive visibility architecture by collecting, aggregating, filtering, and intelligently distributing network traffic to the platforms responsible for monitoring, security, analytics, and compliance. 

By eliminating network blind spots across enterprise and operational technology environments, these solutions provide the trusted data foundation that monitoring, security, and compliance platforms depend on. 

This approach delivers several important benefits: 

  • Eliminate network blind spots across IT and OT environments. 
  • Maximize the effectiveness of existing monitoring and security investments. 
  • Deliver the right data to the right tools. 
  • Reduce unnecessary traffic sent to downstream platforms. 
  • Support scalable monitoring as environments continue to evolve. 

For organizations preparing for CIP-015, visibility is not simply another technology investment. It is the foundation that enables continuous monitoring, incident investigation, and operational awareness. 

Without comprehensive visibility, even the most advanced security platforms may miss critical events. 

Understand What's Happening: Turning Visibility into Operational Intelligence 

Visibility provides the foundation, but visibility alone is not enough. 

Organizations must also be able to understand what network activity means, detect issues as they occur, and investigate events with confidence before they become operational or security incidents. 

Historically, many packet capture solutions have been viewed primarily as forensic tools. They record network traffic so investigators can look back after an incident has occurred. 

Today’s utility environments require something more. 

Operational teams need continuous network intelligence, not simply historical evidence. 

This is where Teneo Network Performance Monitoring & Diagnostics (NPMD), powered by Allegro Packets, provides a unique advantage. 

Unlike traditional packet capture solutions that primarily store traffic for later analysis, Teneo NPMD continuously analyzes live network communications while simultaneously preserving complete packet evidence for historical investigation. 

This combination enables organizations to move beyond reactive troubleshooting toward continuous operational intelligence, helping teams identify issues before they impact critical services. 

For utilities, that means there is no need to choose between real-time detection and forensic investigation. Both capabilities work together within a single passive platform. 

Continuous Monitoring Across IT and OT Networks 

One of the goals of Internal Network Security Monitoring is the ability to observe activity continuously across critical environments. 

Teneo NPMD supports this objective through configurable Layer 2 through Layer 7 analytics that continuously inspect network traffic as it traverses the network. 

Technical teams can configure alarms to identify: 

  • Unauthorized communications 
  • Protocol anomalies 
  • Security events 
  • Network performance degradation 
  • Application behavior issues 
  • Operational anomalies 
  • Policy violations 
  • Custom signatures and thresholds 
  • Regular expression matches within packet payloads 

Rather than waiting for a user to report a problem or relying solely on log files after an event has occurred, operators receive immediate notification when network behavior falls outside expected parameters. 

For organizations responsible for maintaining critical infrastructure, earlier detection can significantly reduce operational risk while improving incident response. 

Evidence That Supports Faster Investigations 

When a security or operational event occurs, one of the biggest challenges is to determine exactly what happened. 

Logs, alerts, and NetFlow records often provide useful context, but they rarely tell the complete story. 

Teneo NPMD preserves the actual packet conversations that occurred across the network, allowing analysts to investigate using objective network evidence rather than assumptions. 

Technical teams can quickly determine: 

  • Who communicated 
  • Which systems were involved 
  • What protocols were used 
  • What data moved across the network 
  • When communications occurred 
  • Whether operational technology assets were affected 

This ability to move seamlessly from real-time detection to detailed forensic investigation helps reduce mean time to investigate while providing the evidence needed to support operational reviews, incident response activities, and compliance audits. 

Beyond Network Performance 

Although the solution includes powerful Network Performance Monitoring & Diagnostics capabilities, its value extends well beyond troubleshooting slow applications or network issues. 

For utilities, packet-level intelligence can help improve: 

  • Continuous operational monitoring 
  • Cybersecurity visibility 
  • Root cause analysis 
  • Operational troubleshooting 
  • Incident investigation 
  • Audit evidence collection 
  • Change validation 
  • Visibility across substations, control centers, and enterprise networks 

This broader perspective is changing how organizations think about packet-based technologies. 

Rather than acting as passive packet recorders, modern platforms provide continuous operational intelligence that enables IT, OT, cybersecurity, engineering, and compliance teams to work from the same objective network evidence. 

For utilities preparing for CIP-015, that means strengthening operational resilience while simultaneously supporting compliance objectives. 

Compliance becomes an important outcome, but the real value lies in building a network that can detect, understand, and respond to issues before they impact critical operations. 

One Platform. Multiple Teams. 

One of the challenges facing utility organizations is that network operations, cybersecurity, compliance, and engineering teams often rely on different tools and different datasets when investigating the same event. 

This can slow investigations, create conflicting conclusions, and make it more difficult to establish a common understanding of what actually occurred. 

Teneo NPMD, powered by Allegro Packets, provides a shared source of packet-level intelligence that supports multiple operational teams from a single passive deployment. 

Whether the priority is maintaining grid reliability, investigating suspicious communications, validating configuration changes, or preparing an audit, every team works from the same objective network evidence. 

This shared visibility helps improve collaboration while reducing the time required to investigate operational and security events. 

Protect Critical Systems: Limiting Risk Through Segmentation 

Detecting suspicious activity is only part of the response. 

Organizations must also be able to contain threats before they spread throughout critical environments. 

Once an attacker gains access to a network, lateral movement becomes one of the greatest risks to operational technology environments. A compromise that begins on a single endpoint or application can quickly spread to systems supporting substations, control centers, or other critical infrastructure if appropriate controls are not in place. 

This is why segmentation has become an increasingly important component of modern cybersecurity strategies. 

Teneo’s Segmentation solution, powered by Akamai Guardicore, helps organizations establish granular security boundaries throughout their environments. Rather than relying solely on perimeter defenses, segmentation controls how systems communicate with one another, ensuring that only approved traffic is permitted between workloads, applications, and critical assets. 

For utility organizations, this provides several important advantages. 

  • Reduce opportunities for lateral movement. 
  • Strengthen internal access controls. 
  • Improve visibility into communication between systems. 
  • Better protect operational technology assets. 
  • Support a Zero Trust approach to network security. 

While visibility and continuous monitoring help identify potential threats, segmentation helps contain them before they can impact critical operations. 

Together, these capabilities create a more resilient security architecture that supports both operational objectives and evolving regulatory expectations. 

Build an Operational Resilience Strategy 

Preparing for CIP-015 is not about purchasing another technology platform. It is about designing an architecture that enables continuous visibility, detection, investigation, and protection across critical environments. 

It begins with understanding your current architecture, identifying visibility gaps, evaluating how effectively your organization monitors internal communications, and determining whether your teams can investigate and contain threats before they impact operations. 

Every utility environment is different. 

Some organizations already have strong monitoring capabilities but lack comprehensive network visibility. Others have visibility but need better operational intelligence. Some have both but need stronger segmentation to reduce the impact of a potential compromise. 

There is rarely a single technology that addresses every requirement. 

Instead, organizations should think about building an architecture that combines visibility, continuous monitoring, detection, investigation, and segmentation into a cohesive operational strategy. 

When these capabilities work together, compliance becomes a natural outcome of a well-designed security and operational framework rather than the primary objective. 

Why Operational Resilience Matters 

Although CIP-015 is an important milestone for the utilities industry, it also reflects a broader shift taking place across critical infrastructure. 

Utility organizations are balancing increasing cyber threats, aging operational technology, digital transformation initiatives, and growing expectations around reliability and service availability. 

Success is no longer measured solely by preventing attacks. 

It is measured by how quickly organizations can detect issues, understand their impact, respond effectively, and continue delivering reliable services. 

The organizations investing in visibility, operational intelligence, and security today are not simply preparing for compliance. They are building the resilience needed to support the future of critical infrastructure. 

How Teneo Helps Utilities Prepare 

For more than 20 years, Teneo has helped organizations design, optimize, secure, and operate complex IT and operational technology environments. 

Our approach begins with understanding your business, your existing architecture, and the challenges unique to your environment. 

Rather than leading with products, we work alongside your team to determine where gaps exist, evaluate your current capabilities, and recommend practical solutions that align with your operational objectives and regulatory requirements. 

Whether your priority is improving visibility, strengthening internal monitoring, reducing lateral movement, or building a broader operational resilience strategy, Teneo can help you identify the right path forward. 

For some organizations, the answer may be a single solution. For others, it may involve multiple technologies working together as part of a long-term roadmap. 

Our goal is not simply to help you prepare for CIP-015. It is to help you build a more secure, resilient, and observable network that supports your business long after compliance deadlines have passed. 

Frequently Asked Questions 

What is CIP-015? 

CIP-015 is a NERC cybersecurity standard developed in response to FERC Order No. 887. It introduces Internal Network Security Monitoring (INSM) requirements for applicable Bulk Electric System (BES) Cyber Systems to improve the detection and investigation of cyber threats within critical environments. 

Who does CIP-015 apply to? 

The standard applies to applicable electric utilities operating Bulk Electric System (BES) Cyber Systems subject to NERC Critical Infrastructure Protection (CIP) standards. Organizations should review the published NERC guidance to determine how the requirements apply to their specific environments. 

Why is internal network security monitoring important? 

Traditional perimeter security helps prevent unauthorized access, but it cannot always detect threats that have already entered the network. Internal Network Security Monitoring improves an organization’s ability to identifysuspicious communications, investigate incidents, and respond before operational systems are impacted. 

How can utilities prepare for CIP-015? 

Preparation typically begins with assessing current visibility, monitoring, detection, and segmentation capabilities. Understanding where gaps exist allows organizations to develop a roadmap that strengthens operational resilience while supporting compliance objectives. 

When does CIP-015 take effect? 

FERC approved the development of CIP-015 following Order No. 887. Utilities should review the implementation timeline published by NERC to understand when requirements apply to their organization. Because preparing the necessary visibility, monitoring, and operational processes can take significant time, organizations should begin planning well before compliance deadlines. 

Start the Conversation Today 

Preparing for CIP-015 is more than meeting a regulatory requirement. It is an opportunity to strengthen visibility across your environment, improve operational intelligence, and build a more resilient security architecture for the future. 

If you’re beginning to assess your organization’s readiness, Teneo’s technical experts can help you evaluate your current environment, identify potential gaps, and determine the most effective strategy and whether any of Teneo’s solutions can help support your operational resilience and compliance objectives. 

Whether the outcome is a single technology recommendation or a broader strategic roadmap, our focus is on helping you build the right solution for your environment. 

Contact Teneo today to schedule a complimentary CIP-015 Readiness Discussion with one of our technical experts. 

 

Author:  

Mark Koenig, Field Technology Consultant, Teneo  

Cookie Policy
Teneo Logo

This website uses cookies so we can provide you with the best user experience possible.

Cookies are small files containing information that enables a website to recognise you. They’re downloaded to the device you use when you visit a website and sent back to that website each time you re-visit, or sent to another website that recognises the same cookie.

Our cookie policy tells you how and why we use cookies, and how this allows us to improve your online experience. You can read our full Cookie Policy here.

Strictly Necessary Cookies

Strictly necessary cookies include session cookies and persistent cookies. Session cookies keep track of your current visit and how you navigate the site. They only last for the duration of your visit and are deleted from your device when you close your Internet browser. Persistent cookies last after you’ve closed your Internet browser and enable our website to recognise you as a repeat visitor and remember your actions and preferences when you return.

Third Party Cookies

Third party cookies include performance cookies and targeting cookies. Performance cookies collect information about how you use a website, e.g. which pages you go to most often, and if you get error messages from web pages. These cookies don’t collect information that identifies you personally as a visitor, although they might collect the IP address of the device you use to access the site. Targeting cookies collect information about your browsing habits. They are usually placed by advertising networks such as Google. The cookies remember that you have visited a website and this information is shared with other organisations such as media publishers.

Keeping these cookies enabled helps us to improve our website and display content that is more relevant to you and your interests across the Google content network.