CIP-015 and BOD 26-02 Are the Same Requirement Wearing Two Different Names
Two federal directives landed in 2026 that look like they have nothing to do with each other.
NERC’s CIP-015-1 tells electric utilities to start watching traffic inside their own electronic security perimeter, not just at the edge. CISA’s BOD 26-02 tells federal agencies to find every edge device that stopped receiving security updates and get rid of it. Put them side by side and they are asking the same question: what is actually running inside the network you already trust, and can you prove it?
That question stopped being theoretical in December 2025, when attackers forced a small Polish combined heat and power plant into a two-hour shutdown without ever touching its own perimeter. This post walks through how that attack worked, why it maps directly onto what CIP-015 and BOD 26-02 both require, and what to do about it whether or not a regulator has your network in scope yet.
Two regulators, one blind spot
CIP-015-1 applies to high and medium impact Bulk Electric System Cyber Systems with external routable connectivity. It requires three things: collect internal network data and detect anomalous activity, retain that data long enough to investigate an incident, and protect it from being altered or deleted.
The reasoning is direct. Perimeter defenses stop working the moment something gets past the perimeter, and most utilities have no way to see what happens next.
BOD 26-02 comes from a different direction. It orders federal agencies to inventory every edge device, router, firewall, gateway, access point, that has reached end of support, and replace it on a fixed schedule. The directive’s own language is blunt: unsupported devices stop receiving patches, which makes them permanent entry points.
Two different agencies, two different sectors, arriving at the same diagnosis: a device or a data path inside the boundary you already secured, and nobody is watching it.
To be clear about scope: most distribution-only private LTE, AMI meters, distribution automation, field workforce radios, still sits outside the Bulk Electric System and outside CIP-015. This is not every private cellular network suddenly becoming regulated.
NERC’s own CIP-002-8 rewrite narrowed the communications exemption. It did not delete it. But the direction both directives point in does not stop at the edge of who is technically in scope, it describes the operational bar every private cellular network is heading toward, regulated or not.
What the Polish plant attack actually proved
The attackers never breached the power plant’s own perimeter. They breached an unrelated wind farm through a VPN concentrator with no multi-factor authentication, then rode a cellular router across a private APN the wind farm and the power plant happened to share.
Client isolation on that APN was assumed. Nobody had verified it. From there, a default-credentialed controller opened a path straight to the plant’s SCADA layer.
Eleven days passed between the first reconnaissance and the moment three PLCs were forced into STOP mode. Every step after the initial VPN breach moved device to device, across a path a standard firewall was never positioned to see, because a firewall watches north-south traffic at the edge.
This was east-west, inside a shared APN both organizations treated as just communications. We broke down the full attack chain in detail elsewhere. The part worth sitting with here: none of it required a zero-day. It required an assumption that turned out to be wrong, held for eleven days, unmonitored.
It also was not unique. Roughly thirty other renewable energy sites were hit the same day, and the pattern was public well before this disclosure.
Volt Typhoon had already shown adversaries pre-positioning inside energy, water, and communications networks for years at a time. Salt Typhoon showed the same pattern inside carrier cores. A CISA advisory on router hygiene, issued months before the Polish disclosure, warned specifically about the edge devices that terminate networks like this one.
The bar both directives are setting
Getting to real internal visibility is a maturity path, not a single purchase. First, know what is connected. Then observe what it does. Only then does enforcing policy on it mean anything.
Mapped against what CIP-015 asks for:
- Collect and detect anomalous internal activity. Start by knowing every device behind every router, not just the SIMs listed in a carrier portal. Then watch device-to-device traffic on the same APN or LTE network, the exact layer a north-south firewall never reaches.
- Retain monitoring data for investigation. In the Polish incident, the attackers factory-reset the router and firewall specifically to erase logs. One router’s older firmware kept a local event database through the reset anyway, and that is the only reason investigators could rebuild what happened.
- Protect that data from tampering. The same principle applies before an incident. If a record of what is on the network can be edited or deleted by whoever is already inside it, it will not hold up in an investigation or an audit.
BOD 26-02’s edge-device mandate maps just as directly: find every end-of-support device before a regulator, or an attacker, finds it first. On one live utility network alone, this kind of inventory has turned up over 260 end-of-life cellular devices still passing traffic, the exact device class BOD 26-02 now orders federal agencies to replace.
What to do before the deadline forces it
None of this depends on waiting for an enforcement date:
- Verify client isolation on every private APN and cellular network you operate, rather than assuming a carrier or vendor already enforces it. In the Polish incident, isolation was assumed and never tested, and that gap is exactly what let attackers cross from an unrelated wind farm into the plant’s network.
- Document your own scope determination in writing now, while the standard is still new, rather than relying on a communications exemption as a permanent shield. NERC already narrowed that exemption once in the CIP-002-8 rewrite, and a written determination is what protects you if it narrows again.
- Extend monitoring to device-to-device traffic on the APN or LTE layer itself, not just north-south traffic at the firewall. A pivot that never crosses the network edge never shows up in firewall logs, which is exactly how the Polish attack moved for eleven days without being seen.
- Inventory every cellular and edge device on the network, including the end-of-life hardware nobody remembers deploying, rather than trusting what a carrier portal lists. That forgotten hardware is precisely the device class BOD 26-02 now orders agencies to find and replace.
- Build evidence retention into daily operations now, before an incident forces the question, rather than treating logging as something to fix after the fact. Data collected only after an attacker has erased the logs cannot tell you what happened.
CIP-015 and BOD 26-02 did not create the requirement to watch what happens inside your own network. They just made it official.
Getting there starts with knowing every device on the network, watching what moves between them, and keeping a record that survives someone trying to erase it. Platforms such as OneLayer work alongside the teams already running that network, extending visibility down to the device and the APN itself, the layer a firewall was never built to see. See how OneLayer Bridge builds that layer.
VP Alliances & Marketing, OneLayer


