We understand the complexities and burden of NERC CIP-015-1 compliance for responsible entities. By streamlining monitoring, anomaly detection, reporting and evidence generation, our internal network security monitoring (INSM) solution enables teams to focus on business operations while assuring regulatory compliance and uptime.
Request DemoWith CIP-015-1, the Federal Energy Regulatory Commission (FERC) acknowledges that protecting the electronic security perimeter (ESP) is not enough. It directs high- and medium-impact Bulk Electric System (BES) Cyber Systems with external routable connectivity (ERC) to implement INSM by October 1, 2028. All other BES Cyber Systems with ERC have until October 1, 2030, to comply.
INSM provides continuous visibility into how networked devices within a trusted zone (ESP) are communicating with each other, allowing for early detection of lateral movement and malicious or anomalous activity within that zone.
Since CIP-015-1 was approved in July 2025, FERC has directed NERC to extend INSM further outside the perimeter. When selecting an INSM solution, responsible entities should also consider these future requirements.

Simplified INSM network architecture using the Nozomi Networks platform with SEL Blueframe®
NERC CIP-015-1 mandates that responsible entities use INSM to collect network data within an ESP, detect anomalous or unauthorized activity against established baselines, evaluate threats and anomalies, retain investigation records and protect INSM data integrity.
Nozomi Networks offers both the technology and expertise to help BES Cyber Systems operators meet the requirements.


Choose the OT/ICS cybersecurity platform that’s easy to deploy, with flexible architectures that conform to your ESP environment and NERC program requirements.

