Anchor: Register-now1

Webinar Series: NERC CIP-015 INSM in Practice

Field lessons, architecture considerations, and deployment strategies for Internal Network Security Monitoring.

The final episode: Ask Our Experts Anything.


The finale isn't until Sept 30. We want time to collect every good question you've got, so send them in early and often. This is the last episode in the CIP-015 INSM series, and it runs entirely on your questions. Whatever you submit, our experts will answer live. No slides, no set agenda; the session is built from what you send in.
Anchor: on-demand

Watch the NERC CIP-015 INSM in Practice Series On Demand

Catch up on practical guidance from Nozomi Networks, SEL, and Emerson experts on INSM strategy, implementation, sensor placement, and network data feeds for electric utilities.

Read the Newest Blogs

Explore Nozomi Networks' latest insights on INSM strategy, deployment, network visibility, and CIP-015 readiness.
Anchor: Register-now

Learn more about what's left of the NERC CIP-015 in Practice Series

Episode 1: What Utilities Are Actually Running Into — and How They’re Solving It (recording and blog are available) Wed, March 18, 2026 at 8 AM - 9 AM PT

After a quick overview of the INSM standard, this session will explore how security and compliance teams are approaching INSM in practice — where they’re running into challenges...

Episode 2:  INSM Current State of Implementations (recording and blog are available) Wed, April 8, 2026, at 8 AM - 8:30 AM PT

Are you running behind, on track or ahead of schedule with your CIP-015 INSM implementation? Do you know? In this session, we’ll look at ...

Episode 3: Sensor Placement and Network Data Feeds with SEL and Emerson (recording and blog are available) Wed, April 29, 2026, at 8 AM -8:30 AM PT

Join Will Edwards, Head of Cyber Services at Schweitzer Engineering Laboratories (SEL), Nicholas Janouskovec, Global Cybersecurity at Emerson, and Markus Mueller as they break down how to effe...

Episode 4: INSM Systems Classification (recording and blog are available) Wed, May 20, 2026, at 8 AM -8:30 AM PT

How are you going to classify your INSM system? As an EACMS, PCA or BCSI storage location? The classification can significantly affect the effort required to stay...

Episode 5: INSM Anomaly Detection Strategies (recording and blog are available) Wed, June 10, 2026 at 8 AM -8:30 AM PT

To detect network anomalies for CIP-015 compliance, you must first baseline normal behavior. But without careful tuning, anomaly detection can introduce a lot of noise. Thi...

Episode 6: Evidence Generation and Collection (recording and blog are available)  Wed, July 1, 2026 at 8 AM -8:30 AM PT

Evidence collection and retention are key requirements for proving compliance with CIP-015 during an audit. This session will cover all things ...

Watch the on demand

Episode 7: Anomaly Investigation and Response with Skyhelm (recording and blog are available) Wed, July 22, 2026 at 8 AM - 9 AM PT

CIP-015-1 & 2 require that entities evaluate the anomalous network activity. How these processes are developed, implemented, and maintained can significantly impact the long-term sustainab...

Watch the ondemand

Episode 8: INSM Audit Readiness (Running A Mock Audit) with Archer (recording) Wed, August 19, 2026 at 8 AM - 9 AM PT

Making it through an audit without any findings or areas of concern takes preparation and forethought.
This session will provide guidance on preparing for an audit, i...

Episode 9: Writing Your NERC CIP-015 INSM Program Wed, Sept 9, 2026 at 8 AM - 9 AM PT

The basis for a successful NERC CIP program is often the written policies and processes that define how an entity will meet the requirements. CIP-015 INSM is no different, and this session pro...

Episode 10: Finale Ask Our Experts Anything Session Wed, Sept 30, 2026 at 8 AM - 9 AM PT

Ask the Nozomi Networks team anything. In this interactive session, our Subject Matter Experts will address questions from the audience and the field, diving deeper into the topics covered thr...

Meet our Speakers

The professionals who will teach you

Markus Mueller

Field CISO

Markus has over 20 years of experience in OT, working across a wide range of industries, with a particular emphasis on utilities, energy and manufacturing. In his previous roles, he led OT tea...

Steve Parker

Managing Partner & Principal Consultant
Archer

At Archer, Steven serves as Managing Partner and Principal Consultant, leading NERC CIP compliance engagements, audit readiness efforts, regulatory strategy development, security control matur...

Leonard Chamberlin | CISSP, CISA, PSP, C3P, NIST CSF 2.0

Managing Partner & Principal Consultant

At Archer, Leonard serves as Managing Partner and Principal Consultant, leading NERC CIP compliance programs, audit-readiness engagements, cybersecurity architecture design reviews (including ...

Marc Berner

Product Managmenet Nozomi Networks

Marc is a technology leader with over a decade of experience orchestrating high-performing teams to deliver cutting-edge, scalable solutions that drive business transformation.

Michael Dutko

Sales Engineer Nozomi Networks

Mike is an experienced ICS/OT Senior Security Consultant with a demonstrated track record across multiple industrial verticals. Focus on assessments and helping clients build and develop their...

Sandeep Lota

Global Field CTO

Sandeep Lota is a seasoned professional in the fields of cybersecurity and technology, currently serving as Global Field CTO at Nozomi Networks, his responsibilities include overseeing technic...

Chris Grove

Director Cybersecurity Strategy

Chris brings over 25 years of cybersecurity experience across IT, OT, and IoT environments, leading complex security initiatives for mission-critical infrastructure worldwide. He has supported...

Will Edwards

Head of Cyber Services Schweitzer Engineering Laboratories (SEL)

Will is presently the head of SEL Cyber Services team within Secure Solutions. Prior to joining SEL, William worked for Concurrent Computer Corporation, where he ensured quality...

Nicholas Janouskovec

Global Cybersecurity at Emerson

Nicholas is the Business Development Manager for Emerson’s Guardian™ digital platform and cybersecurity solutions and services for the power and water industries.

Jeff Foley

Chief Technology Evangelist for Cybersecurity Siemens

Jeff Foley, with Siemens since 1998 and now Chief Technology Evangelist for Cybersecurity, leads global ICS cybersecurity development. With nearly 30 years at Siemens, he works across manufact...

Jeremy Dreyer

CEO, SkyHelm

Jeremy Dreyer is the founder and CEO of SkyHelm, a cybersecurity firm focused on protecting America's critical infrastructure. He has spent more than 20 years in OT and network security, desig...

Logan Sarrington

Leads deployments, SkyHelm

Logan Sarrington leads deployments for SkyHelm’s OT monitoring practice. He works with electric utilities across the country, scoping and deploying OT monitoring sensors, building asset invent...

Tim Pierce

Sr. Technical Sales Engineer Nozomi Networks

Tim Pierce is a professional at Nozomi Networks with a strong background in cybersecurity and industrial network protection. He brings experience working with organizations to secure critical ...

Get Ready: NERC CIP-015-2 Will Expand INSM Beyond the Electronic Security Perimeter

NERC CIP-015-2 is poised to significantly expand Internal Network Security Monitoring (INSM) requirements beyond the traditional Electronic Security Perimeter (ESP), introducing new considerations for Electronic Access Control and Monitoring Systems (EACMS) and Physical Access Control Systems (PACS). For utilities, this evolution will likely drive important architectural, operational, and compliance changes that impact how internal OT networks are monitored, secured, and managed. Understanding what these changes mean for your environment — and how to prepare your INSM strategy accordingly — will be critical for reducing regulatory risk and maintaining compliance readiness.

Learn more about what’s changing and how utilities can prepare for the next phase of NERC CIP-015 requirements.

NERC CIP‑015 in Practice: Early Challenges and Common Pitfalls for Utilities

Utilities preparing for NERC CIP-015 are quickly discovering that compliance is more than deploying sensors — it requires operational alignment, architecture planning, and a clear understanding of Internal Network Security Monitoring (INSM) expectations. From visibility gaps and network segmentation challenges to data collection, alert tuning, and audit readiness, early adopters are already encountering common pitfalls that can slow progress and increase risk.
Learn about the real-world challenges utilities face as they implement INSM programs, and share practical guidance to help organizations avoid costly mistakes and accelerate compliance readiness.

Why Nozomi Networks for NERC CIP-015-1?

Compliance Assurance


  • Audit-ready evidence generation mapped directly to CIP-015-1 INSM requirements

  • Nozomi NERC CIP SMEs who support our customers...

Seamless Program 
Integration


  • Easy incorporation into your existing NERC CIP program
  • An extensive set of native integrations to co...

Flexible & Scalable 
Approach


  • Scalable from a single sensor to a multi-tier enterprise architecture
  • On-prem, Hybrid, and SaaS ...

Collaboration

We foster teamwork and open communication, believing that the best ideas come from collaboration.

Innovation

We foster teamwork and open communication, believing that the best ideas come from collaboration.

Discover More