Group Purchasing
Group Purchasing

Jason Christopher

Certified InstructorSenior Vice President of Cybersecurity and Digital Transformation for Research and Innovation at Energy Impact Partners (EIP)

Specialities

Industrial Control Systems Security

Jason Christopher

About Jason Christopher

Jason D. Christopher is a SANS Certified Instructor and the Senior Vice President of Cybersecurity and Digital Transformation (Research and Innovation) at Energy Impact Partners. He teaches SANS ICS456: Essentials for NERC Critical Infrastructure Protection and co-authors SANS ICS418: ICS Security Essentials for Leaders. Jason’s strength in the classroom comes from two decades bridging engineering, policy, and utility operations, turning regulatory complexity and real-world constraints into practical guidance.

Across his career, Jason served as the federal technical lead for the North American Electric Reliability Corporation Critical Infrastructure Protection standards (NERC CIP v5) at the Federal Energy Regulatory Commission, and he led the U.S. Department of Energy’s Cybersecurity Capability Maturity Model (C2M2) program before moving into executive roles advising utilities and energy innovators. That experience powers ICS456, where he demystifies NERC CIP by translating its requirements into labs, workflows, and audit-ready artifacts that improve reliability as well as compliance. In ICS418, he shifts to the leadership view, helping executives and plant leaders align industrial risk, investment, and governance with plant-floor reality using models like C2M2 and the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and shaping KPIs, tabletop exercises, and roadmaps the business can defend.

Jason holds the GIAC Global Industrial Cyber Security Professional (GICSP) and GIAC Critical Infrastructure Protection (GCIP) certifications. He helped shape widely adopted guidance, including DOE’s C2M2 and the Energy Sector Cybersecurity Framework Implementation Guidance. He serves as lead author for SANS’s annual State of ICS/OT Cybersecurity Report, providing fresh, data-driven guidance each year. Jason is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.

Students describe Jason’s teaching as lively, clear, and pragmatic: no “death by slides,” and lots of repeatable labs that respect safety and reliability. He’s known for bridging operator, engineer, and CISO perspectives, helping practitioners and leaders build programs that satisfy compliance and reduce real risk. Away from the classroom, he continues to advise across the energy ecosystem, advocate for measurable security, and champion ICS/OT defenders who keep critical services running.

Qualifications Summary
  • SANS Certified Instructor
  • Senior Vice President, Cybersecurity and Digital Transformation (Research and Innovation), Energy Impact Partners
  • Course instructor, ICS456: Essentials for NERC Critical Infrastructure Protection; co-author and instructor, ICS418: ICS Security Essentials for Leaders
  • Federal leadership: Federal technical lead for NERC CIP v5 at FERC; incident response and cyber risk lead for DOE; program lead for DOE’s Cybersecurity Capability Maturity Model (C2M2); energy sector lead for the NIST Cybersecurity Framework
  • Congressional engagement: Invited to brief U.S. Congressional committees on ICS/OT cybersecurity
  • Conference speaker: NERC GridSecCon; S4; RSA Conference; United States Energy Association; IIoT Day; SC Media eSummits; American Public Power Association; National Rural Electric Cooperative Association; Edison Electric Institute; American Petroleum Institute; American Gas Association; Hack the Capitol; Institute of Electrical and Electronics Engineers; SANS ICS Security Summit
  • GIAC Certifications: GICSP, GCIP
  • Guidance and publications: DOE C2M2; Energy Sector Cybersecurity Framework Implementation Guidance; EPRI security metrics work and failure scenarios; sector risk methodology publications
  • Executive and industry roles: Senior leader, Dragos (consulting and cyber risk); CTO, Axio; Senior Technical Leader, EPRI

Press & Media