By Dr. Jerome Farquharson, Managing Director, Energy, Oil & Gas Sector Lead
The electric utility industry faces unprecedented cybersecurity challenges with NERC CIP-015-1 (NERC CIP compliance), the new Internal Network Security Monitoring (INSM monitoring) standard. Following the approval of FERC Order No. 907 on June 26, 2025, utilities must implement comprehensive monitoring within trusted zones by October 1, 2028, for Control Centers, and by October 1, 2030, for other applicable systems. This paradigm shift from perimeter-based to internal network monitoring (internal network visibility) creates opportunities for utilities to leverage AI-enhanced SIEM/SOAR (SIEM/SOAR for utilities) technologies—but success requires a carefully orchestrated balance between machine intelligence and human expertise through Human-in-the-Loop (HITL) approaches.
While AI agents can analyze millions of events and identify patterns beyond human capacity, they require human supervision to ensure accuracy, learn from mistakes, and adapt to evolving threats. Modern security operations should adopt a hybrid model, where AI handles volume and velocity, while humans provide context, judgment, and strategic decision-making. This approach transforms AI from a potential liability into a force multiplier for security teams.
CIP-015-1 mandates three core requirements:
- Implementing network data feeds to monitor activity within Electronic Security Perimeters (ESPs)
- Detecting anomalous network activity
- Evaluating detected anomalies to determine appropriate actions.
The standard technology-agnostic approach allows utilities to implement AI-powered solutions (AI in critical infrastructure), but regulatory compliance demands demonstrable human oversight and accountability. Critical security operations should always involve a human in the loop, with AI agents recognizing their own boundaries of capability and escalating complex decisions to human analysts.
Establishing Human-AI Collaboration Frameworks
Building effective human-AI collaboration frameworks begins with establishing clear boundaries and escalation paths. AI agents must operate within defined boundaries that clearly distinguish autonomous actions from those that require human intervention. Best practices include implementing tiered response levels where AI can autonomously handle low-risk, high-confidence scenarios while escalating ambiguous or high-impact decisions to human analysts. For CIP-015-1 compliance, this means AI can collect and correlate network data feeds, but requires human validation before blocking critical operational technology communications (OT cybersecurity).
The effectiveness of AI systems depends on continuous learning from human corrections and feedback. When analysts override AI decisions or identify missed threats, these corrections must feed back into the system to improve future performance. Studies show that AI systems with robust human feedback mechanisms can reduce false positive rates by 75–95% within the first six months of deployment. This iterative improvement process ensures AI systems become more accurate and trustworthy over time. Human oversight extends beyond individual alert validation to systematic quality control processes.
Security teams should implement regular audits of AI decisions, comparing automated responses against human analyst assessments. This validation process serves dual purposes: ensuring AI accuracy for compliance documentation and identifying areas where additional training or rule adjustments are needed. For NERC CIP facilities (NERC CIP compliance), maintaining these audit trails demonstrates due diligence in monitoring internal networks (internal network visibility) and ensuring compliance with regulatory requirements.
Phased Implementation Strategy
Practical implementation of supervised AI for CIP-015-1 follows a phased approach. During initial deployment, AI systems operate in “shadow mode,” analyzing network traffic and generating recommendations without taking any action. Human analysts review all AI findings, validating accurate detections and correcting errors. This phase typically lasts 3–6 months and establishes behavioral baselines while training the AI on environment-specific patterns. For OT networks, this careful approach prevents AI from misinterpreting legitimate industrial control system communications (OT cybersecurity) as threats.
As confidence in AI accuracy grows, systems can take autonomous action on high-confidence, low-impact scenarios while continuing to escalate complex situations. Human analysts focus on validating edge cases, investigating sophisticated threats (AI threat detection), and refining AI decision-making processes to ensure accuracy and reliability. This graduated approach maintains security effectiveness while building organizational trust in AI capabilities. In mature deployments, AI handles routine analysis and initial response while humans focus on strategic threat hunting, process improvement, and handling novel attack patterns. Regular “red team” exercises test both AI detection capabilities (AI threat detection) and human oversight processes, ensuring the combined system remains effective against evolving threats.
Measuring Human-AI Collaboration Success
Measuring success in human-AI collaboration requires metrics that assess both the automated performance and the quality of human oversight. Key performance indicators include investigation accuracy rate (percentage of AI findings validated by human review), escalation appropriateness (ratio of justified escalations to total escalations), learning velocity (rate of false positive reduction through human feedback), coverage completeness (percentage of network segments effectively monitored with human validation), and mean time to human review (average time between AI detection and human validation). For CIP-015-1 compliance, these metrics demonstrate not just technical capability but also the effectiveness of human oversight processes.
Industry’s best practices for sustainable human-AI operations address several critical challenges. Preventing analyst burnout through intelligent workload distribution is essential, as poorly implemented systems can create new forms of analyst fatigue through constant validation requirements. Best practices include:
- Implementing intelligent sampling where humans review a statistical sample of low-risk AI decisions rather than every action and
- Creating rotation schedules that balance AI supervision with strategic analysis tasks.
- Building AI literacy across security teams, as successful human-AI collaboration requires security professionals who understand both the capabilities and limitations of AI.
Utilities should invest in training programs that enable analysts to effectively supervise AI systems, interpret AI reasoning, and identify situations that require human intervention. This education allows teams to maximize the benefits of AI while maintaining appropriate skepticism.
Clear governance structures must define roles and responsibilities in human-AI security operations to ensure effective collaboration. This includes designating AI oversight roles, establishing review boards for significant AI deployments, and creating transparent chains of accountability for AI-assisted decisions. For NERC CIP compliance, documented governance demonstrates regulatory due diligence and ensures that human judgment remains at the center of critical infrastructure protection (AI in critical infrastructure).
A Balanced Path Forward
AI-powered SIEM/SOAR (SIEM/SOAR for utilities) platforms offer transformative potential for achieving NERC CIP-015-1 compliance (NERC CIP compliance), but only when implemented with robust human oversight and continuous learning mechanisms in place. The future of critical infrastructure security (AI in critical infrastructure) lies not in replacing human analysts but in creating synergistic human-AI teams where each component strengthens the other. Organizations that embrace this balanced approach will not only meet regulatory requirements but build resilient security operations capable of defending against tomorrow’s threats while maintaining the human judgment essential for protecting critical infrastructure (AI in critical infrastructure).
The path forward requires commitment to both technological innovation and human expertise, recognizing that the most effective security operations leverage the unique strengths of both artificial and human intelligence working in concert. Ready to explore how AI-powered SIEM/SOAR (SIEM/SOAR for utilities) can support your CIP-015-1 compliance strategy (NERC CIP compliance)? Contact our team to start building your human-AI security framework today.
Sources
- Industrial Defender – CIP-015-01 Approved: NERC CIP Requirements for Internal Network Security Monitoring
- Darktrace – NERC CIP-015 INSM Requirements Explained
- Dragos – NERC CIP-015 Is Approved: Next Steps for Asset Owners
- Nozomi Networks – Preparing for NERC CIP-015-1
- NERC CIP-015-1 Standard Document – Cyber Security – Internal Network Security Monitoring
- Federal Register – Critical Infrastructure Protection Reliability Standard CIP-015-1
- NERC – 2025 ERO Reliability Risk Priorities Report
- Industrial Cyber – NERC 2025 RISC Report
