CIP-015-1 is approved and INSM tooling, sensor placement, and SIEM integration belong on your 2026 capex list — and Anthropic's April 7, 2026 Project Glasswing announcement, backed by $100,000,000 in cloud compute credits and $4,000,000 in direct funding for open-source security work, is the threat backdrop your patch cadence has to keep up with. Anthropic's 12-company coalition — AWS, Apple, Google, Microsoft, Cisco, CrowdStrike, Broadcom, Palo Alto Networks and others — reports its underlying model surfaced thousands of high-severity zero-day vulnerabilities, some dormant for 16–27 years, across major operating systems and browsers. Anthropic's vulnerability-discovery figures are vendor-reported and have not been independently validated.
Those software classes are not grid OT in themselves. They sit in adjacent IT environments — engineering workstations, jump hosts, vendor remote-access portals, and management consoles — that connect upstream of substation HMIs, generator controllers, and data center power stacks. That capability lands inside an active FERC/NERC rulemaking wave: FERC approved CIP-015-1 on internal network security monitoring, the Commission has acted on supply-chain cyber risk management gaps, and CIP-003-11 for low-impact assets is pending final FERC action. Your threat surface is widening while your compliance pathway is tightening.
Editor's note on verification. Anthropic's vulnerability counts, dormancy figures, the $500B cybercrime estimate, and Mythos Preview's capabilities are Anthropic's claims, not independently validated. CIP-003-11 is proposed, not in effect. The April 2026 CIP-003-9 deadline phrasing appears in vendor coverage (Shieldworkz); confirm against the NERC Reliability Standards page before relying on it for compliance planning. SecondWatt buyer-side recommendations in this article are procurement guidance, not legal compliance instructions.
Key Takeaways
- Glasswing is an announcement, not a remediation program. $100,000,000 in compute credits and $4,000,000 in direct funding help defenders; the coalition itself imposes no compliance obligation.
- CIP-015-1 (INSM) is approved. Treat it as a 2026 capex line.
- Proposed CIP-003-11 is a watchlist item, not a budget item.
- Supply-chain cyber risk is the procurement pressure point. Firmware provenance and SBOM artifacts are now diligence items.
- Patch cadence is the operational bottleneck, not tooling.
Project Glasswing in One Page: The Coalition, the Money, and the Model#
$100,000,000 in compute credits and $4,000,000 in direct funding define the seed envelope Anthropic announced on April 7, 2026. The 12-company coalition includes AWS, Apple, Google, Microsoft, Cisco, CrowdStrike, Broadcom, and Palo Alto Networks. No utility, ISO, or RTO is named.
The coalition's stated purpose is AI-assisted vulnerability discovery and disclosure across widely deployed software. Anthropic says it extended Mythos Preview access to 40+ organizations that maintain critical software, and reports findings of high-severity zero-day vulnerabilities — some undetected for 16 to 27 years — across major operating systems and browsers. These are Anthropic's claims; treat them as vendor-reported.
The $100,000,000 figure covers cloud compute credits earmarked for defensive scanning workloads. The $4,000,000 figure covers direct funding to open-source security projects. AWS additionally states it analyzes 400 trillion network flows per day using AI — a scale figure that signals coalition members' existing telemetry posture, not a Glasswing-specific output.
Anthropic frames the macro stakes against global cybercrime costs estimated around $500 billion per year, per the announcement. The narrower power-sector read: the OS, browser, and infrastructure software classes Anthropic describes are common in the IT and vendor-management layers that interact with OT. The same model class that finds dormant bugs in those layers will be applied — by defenders and adversaries — to environments connected to protective relays, RTUs, generator controllers, UPS controllers, and medium-voltage switchgear with remote management.
Verdict: Treat Glasswing as a signal that the AI-assisted vulnerability discovery cycle is now real, not as a remediation that has reached your fleet.
The Regulatory Collision: FERC CIP-015-1, CIP-003-11, and Supply-Chain Action#
FERC approved CIP-015-1 on internal network security monitoring — a final standard sitting alongside two unresolved tracks: CIP-003-11 (proposed) for low-impact assets and FERC's directed standards development on supply-chain cyber risk. The procedural mix matters because vendor sales decks blur it. This section parallels SecondWatt's coverage of converging FERC tracks like large load interconnection.
CIP-015-1 — Internal Network Security Monitoring (Approved)#
Per FERC, INSM is designed to provide visibility inside the electronic security perimeter — the layer where AI-discovered exploits would actually move laterally if they reach a substation network. Applicability tiers, conditions, and effective dates are in the standard itself. Confirm coverage against CIP-015-1 on the NERC Reliability Standards page directly.
$100,000,000 — Anthropic's stated compute credit pool for defensive scanning, against a standard that requires utilities to see what is moving inside the perimeter.
Buyer consequence: If you operate in-scope BES cyber systems, scope INSM tooling, sensor placement, and SIEM/SOAR integration now. The standard rewards SEL-2740S-class protective relays, RTUs, and protection devices that expose clean telemetry and support modern syslog/NetFlow output.
CIP-003-11 — Low-Impact Assets (Proposed)#
CIP-003-11 is a proposed NERC reliability standard pending final FERC action. It has not displaced currently effective CIP-003 for low-impact BES cyber systems. The proposal addresses cyber expectations at low-impact bulk electric sites, reflecting FERC's noted concern that coordinated attacks on multiple low-impact assets could destabilize the grid. Confirm docket number, comment period, and procedural status against the FERC news release and the NERC standards record.
Buyer consequence: If approved as proposed, the framework would expand cyber expectations to a much larger population of substations and assets. Flag this as a pending pathway in 2026 capital plans — not a budget line.
Supply-Chain Cyber Risk Management (Directed)#
FERC directed NERC to develop modifications to the CIP supply-chain standards to close identified gaps, including extending scope to Protected Cyber Assets (PCAs). The categories most affected are network-connected devices — RTUs, networking gear, and similar equipment — that have not historically been subject to CIP supply-chain procurement controls.
Buyer consequence: Firmware provenance, vendor security attestations, and remediation-tracking documentation are procurement evidence now. Equipment with embedded communications — modern protective relays, transformer monitors, UPS controllers, generator paralleling controls — faces increased scrutiny as NERC develops standards under FERC's direction.
FERC/NERC Cyber Rulemaking Status Matrix#
| Rule / Action | Agency | Procedural Stage | Scope | Source |
|---|---|---|---|---|
| CIP-015-1 (INSM) | FERC / NERC | Approved by FERC | Applicable BES cyber systems per the standard | FERC |
| Supply-chain cyber risk action | FERC | Action issued; NERC directed to develop modified standards | BPS equipment vendors, registered entities; PCAs in scope direction | FERC |
| CIP-003-11 (low-impact) | FERC | Proposed; pending final FERC action | Low-impact BES cyber systems (if approved) | FERC |
| CIP-003 (current version) | NERC | Currently in effect | Low-impact BES cyber systems | NERC standards |
Verdict: One standard is in your capex plan (CIP-015-1). One is in your watchlist (CIP-003-11). One is in your supplier questionnaires (supply-chain direction). Do not conflate them.
Who Is Affected: Utilities, Grid Operators, Data Center Power Buyers, and Their Suppliers#
Four buyer groups sit inside the Glasswing-plus-CIP collision. SecondWatt's shadow grid tool tracks the asset visibility layer most exposed to these tracks.
Registered utilities, transmission owners, and generation owners with applicable BES Cyber Systems. These entities fall inside CIP scope where registered-entity status, BES asset classification, impact rating, and standard applicability align. Examples: protective relays, station HMIs, RTUs, and generator controllers when associated with in-scope BES Cyber Systems. Smaller utilities face a staffing capacity gap on AI-driven threats, per Power Magazine's coverage of the Glasswing announcement.
ISOs and RTOs. Market operators do not own substation iron, but they coordinate with transmission owners whose CIP posture determines reliable telemetry. Glasswing's relevance is indirect: AI-disclosed vulnerabilities accelerating patch cycles at member TOs translates into schedule pressure on market operators.
Data center power buyers (behind-the-meter and co-located). Large data center operators procure medium-voltage switchgear, generator plants, paralleling controls, UPS systems, and BMS networks — most with embedded firmware and remote management. Where a site is not a registered BES asset, NERC CIP does not apply directly. Comparable diligence still comes from upstream utilities, interconnection counterparties, insurers, and enterprise risk teams. This is a market observation, not a regulatory requirement. The data center power bottleneck procurement roadmap covers the upstream constraints in detail.
Equipment suppliers, OEMs, and secondary-market resellers. This is where SecondWatt-tracked categories — used and refurbished generators (see generator pricing), transformers, switchgear, UPS, and ATS — meet the rulemaking direction. Equipment without clean firmware provenance, without SBOM-style artifacts, or without a credible patch channel encounters friction in due diligence as supply-chain expectations tighten under FERC's directed standards development.
Affected-Parties and Equipment Exposure Matrix#
| Buyer Type | Primary Equipment Exposed | Relevant Rule(s) | Glasswing Relevance |
|---|---|---|---|
| Registered utility / TO / GO | SEL-class protective relays, RTUs, station HMIs, SCADA front-ends, transformer monitors | CIP-015-1, CIP-003 (current and proposed), supply-chain direction | High — AI-disclosed bugs in adjacent stacks raise patch-cycle pressure |
| ISO / RTO | EMS interconnects with member TOs | CIP-015-1 (indirect) | Medium — schedule pressure flows downstream |
| Hyperscale / colo data center power team | 15kV MV switchgear, Cat 3516B/MTU 20V4000-class generator controllers, Vertiv/Eaton UPS controllers, ATS, BMS | Supply-chain direction applies to BES vendors; non-BES sites face parallel diligence | High — same equipment classes, same firmware stacks |
| OEMs and secondary-market resellers | Firmware-bearing power equipment | Supply-chain direction | High — provenance and SBOM artifacts become diligence items |
Verdict: If you procure firmware-bearing power equipment in any of these four roles, you are inside the procurement diligence ring — even where you sit outside formal NERC CIP jurisdiction.
Timeline and Compliance Pathway: What's Final, What's Proposed, What's Unsettled#
Approved. CIP-015-1 (INSM) — FERC approved it on June 26, 2025, per Industrial Defender's coverage. NERC implementation timelines flow from that approval; confirm against the NERC standards page.
Issued, with NERC standards-development to follow. FERC's supply-chain cyber risk action is issued. FERC directed NERC to develop new or revised reliability standards.
Proposed. CIP-003-11 is proposed and pending final FERC action; the currently effective CIP-003 continues to apply in the interim.
Unsettled. Open questions: final rule timing for supply-chain standards development; final disposition of CIP-003-11; implementation expectations by NERC Regional Entities and state PUCs; INSM scope for behind-the-meter data-center generation; and whether secondary-market equipment will face explicit firmware-attestation requirements. None of these are settled for 2026 procurement contracts.
Glasswing's April 7, 2026 announcement is concurrent with the active rulemaking. The coalition imposes no compliance deadline. FERC and NERC do.
Verdict: Treat CIP-015-1 as a 2026 capex line. Treat CIP-003-11 as a watchlist item, not a budget item. Treat the supply-chain direction as the live procurement pressure point right now.
What Buyers Should Do Now#
The questionnaire and diligence items below are SecondWatt procurement recommendations, derived from FERC's supply-chain direction. They are not legal compliance instructions.
1. Inventory firmware and software on every cyber-relevant asset. Include protective relays, RTUs, generator controllers and paralleling gear, UPS controllers, ATS controllers, BMS modules, and medium-voltage switchgear with embedded comms. With AI reportedly surfacing zero-days dormant for 16–27 years, firmware age is itself a risk signal.
2. Map assets to approved and proposed CIP scope. Separate what is required today (CIP-015-1, currently effective CIP-003) from what would be required if CIP-003-11 is adopted as proposed. Where assets sit at behind-the-meter data center power sites, document why they are or are not BES-classified.
3. Update supplier and OEM questionnaires for the supply-chain direction. Ask vendors for: firmware versioning and provenance, SBOM availability, vulnerability disclosure cadence, remote-access architecture, and patch-channel commitments. Per FERC's release, the framework expands supply-chain attention toward PCAs — questionnaires can reflect that direction now.
4. Budget for INSM tooling and patch-cycle staffing. Patch staffing is the operational constraint, not tooling. Axios reports AI is making vulnerability discovery easier than fixing, with 42% of vulnerabilities exploited last year reported as zero-days — broad cyber context, not power-sector-specific. Per Power Magazine, utilities should invest in AI-enhanced cybersecurity tools now and grid operators should begin budgeting and deploying monitoring systems ahead of upcoming compliance deadlines.
5. Apply secondary-market diligence. Before closing on a used SEL relay, RTU, or CAT-class generator controller, request firmware provenance and patch-channel evidence — last-known firmware, OEM patch availability, and whether the asset retains a credible update channel. SecondWatt's generator pricing coverage flags how firmware provenance affects secondary-market pricing on controllers and paralleling gear.
6. Track open dockets. Don't assume. Watch FERC's CIP and supply-chain rulemaking activity and confirm current standards status against the NERC Reliability Standards page. Current postures are a pending regulatory pathway, not settled law.
Procurement Diligence Checklist#
- Firmware inventory complete for all cyber-relevant power assets
- CIP-015-1 INSM scope mapped; INSM tooling RFP issued or budgeted
- Vendor questionnaires updated against FERC supply-chain direction
- Used/refurbished equipment provenance documented before close
- CIP-003-11 exposure flagged as a pending pathway in 2026 capital plans
- Patch-cycle staffing reviewed against AI-accelerated disclosure cadence
Verdict: Six items. The first two are this quarter. The next three are this year. The last is permanent.
Next step for SecondWatt buyers: Pull current pricing and provenance data on the equipment classes named above through SecondWatt's generator pricing and asset visibility tools before closing on any firmware-bearing transaction in 2026.
FAQs and Editor's Note on What Is Not Yet Verified#
Which companies are involved in Project Glasswing? Per Anthropic's announcement, the coalition includes Anthropic plus 11 named partners — AWS, Apple, Google, Microsoft, Cisco, CrowdStrike, Broadcom, and Palo Alto Networks among them. No utility, ISO, or RTO is named.
What is the Glasswing summary? A 12-company AI cybersecurity coalition announced April 7, 2026, seeded with $100,000,000 in compute credits and $4,000,000 in direct funding, aimed at AI-assisted discovery and disclosure of software vulnerabilities. Mythos Preview's capabilities are Anthropic-reported and not independently validated.
How are AI companies turning into cyber-defense companies for energy? They are not, formally. Glasswing partners are technology firms, not utilities. The energy relevance: AI-class vulnerability discovery surfaces bugs in the operating systems, browsers, and management software adjacent to OT — increasing patch-cycle pressure on operators governed by FERC CIP.
What does Project Glasswing mean for FERC/NERC CIP compliance? Nothing directly. Glasswing imposes no compliance obligation. The compliance obligations come from CIP-015-1 (approved) and the pending FERC tracks above.
Excluded from this article as unverified or out of scope: Macro grid-investment figures ($600B/yr, $700B U.S. transmission, $88B China), single-substation outage cost figures, and any claim that CIP-003-11 is in effect. The April 2026 CIP-003-9 deadline phrasing appears only in vendor-tier coverage; confirm against NERC before relying on it.