top of page

Areas of Expertise

Critical Infrastructure Network Operations
Cybersecurity

Evaluting and measuring maturity of OT network operations, focusing on visibility, pre-event performance threshold identification and alerting, event response play-book development.

Applying proven standards-based frameworks and practical strategies to protect critical data communications systems, reduce risk, and strengthen cyber resilience and compliance posture.

IT/OT Network
Architecture
Resilience & Strategic
Planning

Engineering secure, scalable data communications network architectures that connect  Information Technologies (IT) and Operational Technology (OT) while supporting monitoring, performance, reliability, and control.

Developing practical data communications strategy roadmaps, processes, and response strategies that help organizations anticipate disruption, sustain operations, and evolve with confidence.

Mike_BV_portrait.png

Certifications & Achievements

Over his career Mike has been recognized through a variety of previously held professional technical certifications including Cisco Systems CCNP, Cisco Systems CCSP, Cisco Systems Grid Engineer, ISC2 CISSP, ISACA Certified Information Security Auditor, ISACA Certified Information Security Manager, and a Microsoft Certified Systems Engineer. Currently Mike has been recognized as a certified Idaho National Labs Consequence-driven Cyber-informed Engineering (CCE) Accelerate Methodology trainer.

CISSP
CCNP
ISACA CISA.jpg
CISA
ISACA CISM.jpg
CISM

ISC2 Certified Information Security Professional (CISSP) • Cisco Certified Network Professional (CCNP) • ISACA Certified Information Systems Auditor (CISA) • ISACA Certified Information Security Manager (CISM) • NERC CIP Standards Sub-committee Participant • Microsoft Certified Systems Engineer (MCSE) • Idaho National Labs Consquesnce-driven Cyber-informed Engineering (CCE) Accelerate Certified Training • NIST National Cybersecurity Center of Excellence (NCCoE) Network and Cybersecurity Frameworks Contributor •

Professional Background

Following his service in U.S. Army aviation, supporting VIP transport and experimental aircraft systems both domestically and abroad, Mike has built a career at the intersection of technology and critical infrastructure. He progressed into data communications, working on large‑scale, mission‑critical networks while representing leading technology providers including Cisco Systems, Farallon Computing, Netopia, Calence, Actuate, and others.

His roles spanned the full technology lifecycle — from product development and beta programs to remote and on‑site implementation and support. Building on this foundation, Mike moved into direct client consulting across North America, partnering with global enterprises and top‑tier consultancies to design, deploy, and optimize complex network environments.

 

Having served in pivotal solution and customer support roles for industry-leading OEMs and global engineering firms, Mike is frequently sought out for his ability to translate business requirements into technical network communication solution strategies supporting rapidly evolving OT environments.

Black & Veatch      Cisco Systems      Alexander Open Systems      Calence      Netopia      Actuate      Farallon Computing

Industry Endorsements

"Mike's experience in large MPLS networks was instrumental in helping us get more reliability and versatility out of our operations communications systems. He kept driving home what it meant to have a Build It Once And Use It Many network, and we've learned over time just how valuable that can be."

CTO, Global Energy Company

"A seasoned professional who understands the nuances of critical infrastructure communications. Mike delivered a resilient network architecture that has brought the benefits of his virtualization and modular approach."

Director of Infrastructure, MID-WEST Electric Cooperative

"The Telecm Master Plan Update Summary was shared with department leadership in preparation for Annual Reports and Trustee Meetings. I appreciate you and very proud of what we have accomplished together!"

OT Operations Network/Security Manager, Multi-State Generation & Transmission Utility

"The entire team put in long hours and extra efforts to ensure everything we do propels us forward...I have joyfully shared this major milestone accomplishment with our Director, COO, and CEO.  I look forward to maintaining the momentum of our partnership and teamwork."

OT Network Manager, Southeast Transmission& Distribution Utility

Publications

Cybersecurity: Secure Utilities Start with Secure Networks — BV

Repelling a Ransomware Attack — Medium

Ransomware: A Change Will Do Us Good — IEEE

Digitization at the Heart of Cybersecurity, Asset Management — BV

How to Build Your Game Plan to Win the Fight Against Utility Ransomware — BV

Low Impact Asset Assessment and Protections — Case Study — BV

Industry Contributions

01

Presenter

LinkedIn Live Event — Co-creator and presenter for live cybersecurity discussion, “Cybersecurity Resilience: Strategies for Water and Grid Infrastructure”. Discussion focused on steps to establishing long-term cyber posture enhancement through established frameworks and latest thinking regarding the importance of People and Process — COMPLETED 4th Qtr 2023

02

Interview

Authority Magazine, Medium.com, "Ransomware Attacks — 5 Things You Need To Do To Protect Yourself Or Your Business" — Published 1st Qtr 2022

03

Contributing Author

"Digitization at the Heart of Cybersecurity, Asset Management". Black & Veatch Insights Group Electric Report — Published 1st Qtr 2022

04

Author

IEEE Monthly Bulletin, "Ransomware: A Change Would Do Us Good". Short article promoting a change in approach to classic reliance on cybersecurity hygiene approaches to defense. The article suggests that network architecture, people and process aspects are equally important and should be emphasized in Cyber Attack For Ransom (CAFR) event response in utility OT environments — Published 4th Qtr 2022

05

Co-Author and Presenter

Distributech International, "Practical Protections to Combat Rising Ransomware". A joint industry customer/consultant presentation showing how concepts such as the Idaho National Laboratories (INL) Consequence-Driven Cyber-Informed Engineering (CCE) framework, combined with proper packet network architecture help define a more robust response to Cyber Attack for Ransom (CAFR) events — COMPLETED 1st Qtr 2023

06

Co-Author/
Co-Presenter

"Low Impact Asset Assessment and Protections — Case Study", refined case-study examination of a successful NERC CIP Low Impact inventory and qualification-assessment involving 80 locations across a state, and thousands of devices. Work included implementation of over 40 industrial firewalls at select field locations, national North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Committee meeting, Minneapolis, MN — September 2018

Author

"How to Build Your Gameplay in the Fight Against Utility Ransomware" — short article reviewing core principles or "pillars" for establishing an effective response plan to ransomware attacks. The intent is for utility operations leaders to focus efforts on essential categories of capabilities yielding the best chance of continued operation and service delivery within the context of a CAFR event — COMPLETED 2nd Qtr 2023

07

Certified Trainer Course

Idaho National Labs Consequence-Driven Cyber-Informed Engineering — Through in-person Accelerate Training, acquired knowledge to support investigating and assessing customer OT security postures utilizing newly released cybersecurity vulnerability assessment methodology for critical infrastructure. Evaluate possible efficacy, practicality of implementation of principles and any replication and/or enhancements of other established cyber assessment and protection approaches — September 2021

08

Contributing SME for Industry Standards Development

NERC CIP Critical Infrastructure Protection Committee (CIPC), participant for committee on Supply Chain Security. Formed to help North American Electric Reliability Corporation (NERC) advance the physical and cyber security of the critical electricity infrastructure of North America. The committee consists of both NERC-appointed regional representatives and technical subject matter experts — 2020/2021

09

Contributor/
Co-Presenter 

Utilities Technology Conference Speaker (UTC), Ransomware Planning Presentation — Joint presentation with customer to demonstrate methods and requirements used for establishing planned technical responses to a CAFR (Cyber Attack For Ransom) event, without paying ransom, Portland, OR, — August 2021

10

Contributing Author/Developer

Strategy Engine — Assist in creation of model for support of critical infrastructure Telecom Network Master Planning activities. Provides repeatable process for creation, tracking and evaluation of infrastructure and security project Key Performance Indicators (KPI's) and technical project Key Objectives (KO's). Co-developed with an electric utility customer and made compatible with existing best-practice network/security infrastructure assessment, and implementation execution processes, e.g., PAADIO — May, 2020

11

12

Requested Reviewer

"Energy Sector Asset Management for Electric Utilities, Oil and Gas Industry", National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) pre-publication release for public comment working draft — December 2017, Published 2018

13

Contributor Industry Standards

National Institute of Standards and Technology (NIST), National Cybersecurity Center of Excellence Partnership (NCEP), promoting mutual cooperation for collaboration to enhance trust in U.S. IT communications, data, and storage systems, lower risk for companies and individuals in the use of IT systems, and encourage development of innovative, job-creating cybersecurity products and services.

14

Project Execution Process Co-Developer and Custodian

 I.T. and O.T. project planning, design and implementation process, "PAADIO"  Methodology builds upon ISO, PMI, Carnegie Mellon and other world-class contributors for promoting value-engineering project planning and execution, including CMMI principles and CAPEX / OPEX predictor inputs.

15

Network Coursework Co-Developer and Custodian

Customer-facing IP modernization education workshops, providing information and training on proven network and cybersecurity project and technology practices with practical fit, function and organizational impact perspectives. Assists business operations teams in developing their strategic telecommunications plans, execution and sustainment efforts.

16

Invited Panelist

Utilities Technology Council National Meeting, Security Summit, "Mission Critical Security — Getting it Secure, Keeping it Secure", Charlotte, North Carolina — May 2017

17

Invited Panelist

North American Electric Reliability Corporation ("NERC") GridSecCon, NIST National Cybersecurity Center of Excellence (NCCoE), Cybersecurity Portfolio and Framework panel member, w/Utilities Technologies Council, Quebec City, CAN — October 2016

18

Organizer/
Moderator

Joint review and comment forum for Special Publication 1800-2 Identity Access Management for Electric Utilities: Utilities Technologies Council (UTC), Customer Representation, Black & Veatch with IEEE contributor, MITRE representing NIST National Cybersecurity Center of Excellence Overland Park, KS — March 2016

19

Invited Panelist

North American Reliability Corporation, Critical Infrastructure Protection, NERC CIP, "Practical Implementations and Beyond", Utilities Telecom Council, US National Conference, Denver, Colorado — May 2016

20

Official Reviewer

National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) SP 1800-2 — Identity and Access Management Practice Guide for Electric Utilities,  WERB Draft — February 2016

21

Contributor/
Co-Presenter

"NERC Critical Infrastructure Protection (CIP) v5/6 Transitions", UTC Region 6 Meeting, Overland Park, KS — April 2016

22

Participant

NIST National Cyber Security Center of Excellence — Energy Provider Community, Situational Awareness Case Studies Review and Prioritization — 2015

23

Contributor/
Co-Presenter 

"Building a Practical Cyber Security Practice", Utility Telecom Council, Region 6, Overland Park, KS — March 2015

24

Participant

NIST National Cyber Security Center of Excellence — Energy Provider Community, Identity Access Management Case Studies — 2015

25

Author & Presenter 

"Practical IT/OT Convergence for Utility Networks", UTC Canada National Conference, Calgary — September 2014

26

Invited Panelist/
Presenter

"Smart Grid Convergence Using Multi-protocol Label Switching (MPLS)", UTC National Conference, Orlando, Florida — May 2012

27

Author & Presenter 

"Foundations for MPLS VPN’s", UTC Region 4, Indianapolis, IN — October 2012

28

Invited Panelist/
Presenter

"Network Infrastructure, Kansas Legislative Systems Strategic Plan (e-Democracy Strategies)", United States House of Representatives Executive Staff briefing, Topeka KS — December 2008

Project Experience

Solution Leader — Network/Cyber OEM Product Evaluation Brief — Develop and document a short-form OEM product evaluation deliverable for Operations Technology utilizing Open Flow Software Defined Network technologies within industrial Operations Technology (OT) environments. Demonstrates solution effectiveness in product space evaluating multiple criteria for purposes of solution purchase decision-making by customers. — COMPLETED 2nd Qtr 2025



Team Member — Nuclear Power Innovation Project Pursuit — Contribute to providing secure communications systems and risk identification and mitigation for SMR nuclear generation innovation project off-shore, near-shore. — COMPLETED, 2nd Qtr 2025



Cybersecurity Architect — Water Infrastructure Risk Mitigation Project — Assist large U.S. metropolitan water utility with analyzing comprehensive  SCADA cybersecurity Assessment, identifying optimum control additions and procedure fit for established policies. Controls involved Active Director IDAM, additional Password security controls and Remote Access policy, process and procedures creation. — COMPLETED 3rd Qtr 2025

 


Extensive experience working directly for OEM software and hardware producers  now assisting organizations to design and deploy secure, reliable, and operationally efficient critical infrastructure communications solutions. 



Presenter — Joint Kansas University and FBI Cybersecurity Conference — FBI Director Christopher Wray, keynote speaker, presenting compare and contrast, IT verses OT communications security. — 1st Qtr 2024



Team Member — NERC CIP 013 Supply Chain Risk Management Update Team (Gap Review) — Continue contribution working within the NERC CIP standards committees to assist in resolving identified gaps in existing 013 standard. — 2nd Qtr 2024



Team Leader — NERC CIP 013 Supply Chain Risk Management Team (Incident Response Guide Update) — Supply Chain Risk Management — Vendor Incident Response Guide version 2 revisions. Effort to keep up to date existing guidance documentation for use by energy sector operating entities supporting the U.S. Bulk Electric System (BES). — 1st Qtr 2024



Investigator — Contract Compliance — Cybersecurity subject matter expert for team investigating supply chain project execution performance for critical infrastructure. Purpose is to validate cybersecurity designated aspects of information handling and assist to improve overall project data security. — 1st Qtr 2024

 


Contributor — Cybersecurity Services Group Launch Team — Assist with the development and launch of new cybersecurity services organization delivering Engineering Procurement and Construction services. Activities include organization design: human resource identification and qualifying through interviews; service offerings identification; revenue vs. strategy refinement of initiatives; cross markets cyber services delivery integration and communications development; assist with development of sales, marketing and media collateral. — December, 2023



Contributor — Security Product Development — Participation in early development process for multiple products; exploring possible product creation including customer input mechanisms such as focus group surveys and product information videos, contribution to (ERD) including security feature/function and Marketing Requirements (MRD) Engineering Requirements sets. — October, 2023



Team Member — Critical Infrastructure Cybersecurity Assessment/Audit — Utilize automated CISA CSET tool to assess, audit and validate network and cybersecurity posture for large southwest metropolitan utility. Analyze results, measure risk and recommend controls enhancements to close identified gaps. Issue C-level report on findings and review mitigation project(s) cost. — August, 2023



Principal Consultant — Cyber Attack for Ransomware (CAFR) Reaction Plan — Assist medium size U.S. Energy sector customer, investigate and assess requirements, methods and activities required for responding to a ransomware attack. Include critical systems priorities, playbook, existing IR and DR plan impacts, area and access isolation techniques, data flows and processes while negating ransom payment; utilize existing frameworks and tools wherever possible, (e.g. CISA Ransomware preparation information, INL CCE®, MITRE ATT&CK® framework, etc.). — April, 2022



Co-Presenter — "Developing a Cyber Attack for Ransomware (CAFR) Response Playbook" — Presentation to an electric utility Reliability Organization (RO) relating methods and techniques for establishing planned organization, systems and network response to a CAFR (Cyber Attack For Ransom) event while negating ransom payment — March, 2022



Principle Consultant — Cyber Attack for Ransomware (CAFR) Reaction Plan — In cooperation with mid-size Energy sector customer, investigate and assess requirements, methods and activities for responding to a ransomware attack. Produce Playbook that recognizes critical systems priorities, existing IR plan impacts, isolation techniques accounting for essential operational application flows and processes, while negating ransom payment. — July, 2021



Technical Coordinator — Private Wireless Device MPLS Implementation — Develop very large-scale energy sector customer field demonstration criteria for implementation and validation for 17 site MPLS VPN SCADA/AMI OT data network with data flow filtering protections that include wired, private radio spectrum and microwave wireless infrastructure. Examined interaction requirements of IP network team and RF team seeking to optimize overlapping responsibilities and tasks for provisioning, validation testing and turn up. — March, 2021



Co-Creator — OT Services Supply Chain Cybersecurity Risk Management Survey Response Template — Develop new process to assist pre-sales organization response to various customer surveys resulting from NERC CIP 013 Supply Chain Risk Management requirement. Customer submitted survey may be of any form, depth or breadth. Response process considered assurance of risk reduction and project information protections. — April 2021



Principal Consultant — Cybersecurity Process Documentation — North American Reliability Corporation — Critical Infrastructure Protection (NERC CIP) procedures documentation standardization project for very large scale Energy sector client. Provide review, validation and verification for series of practical process/procedures guide documents aligned with NERC CIP rule set. — August, 2020



Principal Consultant — VLS Network and Cybersecurity Design — North American Reliability Corporation — Critical Infrastructure Protection (NERC CIP), BCA Low Impact Electronic Access Point (LEAP) Assessment. for a very large-scale OT network. Developed Statement of Work (SoW), led Design and Deployment — pursuant to rapidly evolving DoE directives for Critical Infrastructure Protection compliance requirements, active project to assess vulnerability in approximately 100 electric grid field sites through inventory and logical assessment, detecting and analyzing all NERC CIP LEAP's and cyber assets. — February, 2019



Human Resourcing Consultant — OT Network Infrastructure Talent Search — Requested by private energy generation, transmission and distribution utilities to assist in identification and qualification of Smart Grid technical resources for very large-scale O.T. network modernization projects. Interview and rated  candidates with urgent timeline requirements. — November, 2019



Technical Team Leader — Very Large Scale Network and Cybersecurity Design, MPLS — Very Large-scale OT network design Proof-of-Concept Lab Electric sector — led creation and execution of OEM switch/route/firewall proof-of concept test to evaluate best design solution employing MPLS network virtualization, data path encryption and traffic flow filtering. Tasks included test plan case development and documentation, lab provisioning, inventory controls, test monitoring, results evaluation and outcomes memorandum. — July, 2018



Principal Consultant — Network Operations Center CMMI — Assist with development of RFP response, win and then execute assessment of Network Operations capabilities for large multi-state SouthEast U.S. utility. Duties included current state analysis, gap analysis, CMMI maturity modeling of energy network monitoring operation (NMS) to track progress toward future state goals. Areas of analysis include application requirements and data flow, network health baseline and deviation, alert monitoring, tools, staffing and cybersecurity integration. — April, 2018



Lead Product Evaluator — Cybersecurity IDS Product — Develop new service, related collateral, sell then execute as leader for product field evaluation team. Analyze and record Human Factors observation through user interviews and use-case functional testing of  industrial networks purpose-built intrusion detection appliance supporting DNP3 and related protocol(s) signature detection. Developed Statement of Work (SoW) for service. Product was examined during Proof-of-Concept deployment within operational production network. — June, 2017



Co-Developer — Cybersecurity Live-fire Exercise — Developed statement of work (SOW), assisted with design and execution of organization-wide cybersecurity intrusion(s) exercise including Identification, Incident Response and Mitigation for generation/transmission multi-state electric cooperative; included master security event list (MSEL) development and exercise injects for human engineering site access, EMS SCADA-Master packet payload modification, law enforcement scenario, and natural disaster event, assessing response capabilities and business continuity impacts. — January, 2017

Senior Consulting Engineer — Network Design and Cybersecurity, MPLS — Multi-year critical account assignment, on-site supporting named account to help ensure customer success with product line in large-scale multi-year MPLS deployment.



Contributor Technical Coordinator/Architect — Very Large Scale Network Engineering, MPLS —  Multi-year engagement advising state government I.T. organizations. Hands-on network architect, infrastructure engineer and team leader for federated state government, all-agency $5,000,000+ network transition project: Migration from legacy network to full MPLS virtualized, tiered and modularized design: 1000+ router nodes; 37,000+ ports, 100+ user groups; future-proofing designs, flexible growth trajectories and investment preservation.



Architect — Network and Cybersecurity Architecture — Very large-scale energy distribution co-op Operations Control Center network architecture redesign including multi-tiered multi-vendor Firewall architecture with NERC CIP regulatory compliance factors addressed: Logging; DMZ; Access Controls; Interactive Remote Access; Change Control Reporting.



Project Team Principal Consultant — Network and Cybersecurity Controls — Assist with development of RFP response for win and then execute, Energy Markets network, large-scale firewall rule set refresh (1000+ ACL's) for multi-tiered and virtualized security architecture. Work was performed during production hours for the Market necessitating extreme care for rule validation and change activities.



Principal Architect — Network Cybersecurity Strategy — Assist with development of RFP response, win and then execute Telecom Master Plan for very large scale Generation, Transmission and Distribution, I.T. infrastructure, South East U.S. energy co-op; defining new highly secure and reliable Smart Grid data transport infrastructure supporting AMI, HMI, RTU, DNP3 SCADA-monitored and managed field network flows. Work produced Current State, Futures State, Solutions Analysis and Roadmap.

bottom of page