News
September 19, 2026

Burns & McDonnell Outlines CIP-015 Compliance Approach for Utility Network Monitoring

Construction Owners Editorial Team

Highlights

  • Burns & McDonnell addresses the implementation requirements associated with NERC CIP-015-1.
  • The standard expands cybersecurity monitoring beyond traditional electronic security perimeter controls.
  • Applicable utilities must establish internal network security monitoring across protected operational technology environments.
  • Network data collection, anomaly detection, documentation and audit evidence are key implementation considerations.
  • Large substation networks, legacy OT equipment and limited communications capacity can complicate deployment.

Lead

Electric utilities preparing for expanded cybersecurity requirements face new operational and infrastructure considerations as internal network activity becomes part of compliance monitoring. Burns & McDonnell has outlined an approach to help utilities address NERC CIP-015-1, including network visibility, monitoring processes and documentation requirements.

Internal Network Monitoring Requirements

NERC CIP-015-1 adds internal network security monitoring (INSM) requirements to cybersecurity controls already used to protect critical operational technology environments. Existing NERC CIP-005 controls address electronic access protections such as network segmentation, firewalls, remote access and logging.

Under the newer standard, applicable utilities must establish processes for monitoring activity within protected environments rather than concentrating only on the external security boundary.

Implementation requires utilities to determine what network information should be collected, how activity will be evaluated and how monitoring decisions will be documented. Utilities also need to maintain sufficient evidence to demonstrate compliance during audits.

Deployment Challenges Across Utility Networks

The scale and condition of utility infrastructure can affect how internal monitoring systems are implemented. Utilities operating numerous substations may need to account for differences in equipment, network configurations and communications capabilities across facilities.

Legacy operational technology can create additional integration requirements, particularly where existing systems were not designed around modern cybersecurity monitoring practices. Limited communications bandwidth can also affect the amount and type of network data that can be transmitted for analysis.

Burns & McDonnell's telecommunications engineers Beaux Gonzales, Adam Holl and Andrew Shimamoto addressed these considerations in the company's published guidance on CIP-015-1 compliance.

Why It Matters

For utility owners and infrastructure stakeholders, CIP-015-1 introduces cybersecurity requirements that extend into internal operational networks. Planning for data collection, monitoring, documentation and audit evidence can affect telecommunications infrastructure, OT systems and project implementation decisions.

Utilities with extensive substation portfolios or older OT infrastructure may need to evaluate existing network capabilities before implementing the required monitoring processes. Early planning can help identify infrastructure and documentation requirements before compliance activities become time-sensitive.

Available next action: Create a downloadable PDF file here in this chat containing the findings and recommendations above

Source: Burns & McDonnell.

Get the inside scoop on the latest trending construction industry news and insights directly in your inbox.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.