Oil & Gas

Pipeline SCADA, wells, refineries.

"Oil and gas organisations must address the cyber challenges of sprawling global infrastructure, major safety hazards, the threat of nation-state cyber attacks and growing regulatory compliance and scrutiny."

The Challenge

Cybersecurity Challenges

Safety, Integrity and Availability are clear priority risk considerations associated with the Oil and Gas sector. The safety of people, the environment and operational assets is typically ensured by a combination of mechanical and computerised (OT/ICS) controls. Together they deliver process control, safeguarding, reliable real-time data integrity and near-continuous availability to support business operations. However, increased digitalisation, convergence and connectivity with mainstream technologies have exposed these critical considerations to a wider range of cyber threats.

Moreover, heightened regulatory compliance scrutiny means that a structured OT cyber security risk management strategy is now more important than ever to effectively manage these risks.

The unique physical-cyber convergence in Oil & Gas makes…

The unique physical-cyber convergence in Oil & Gas makes organisations vulnerable to exploitation, attackers can commandeer OT systems to disrupt operations or even physically…

Regulatory requirements such as the IMO Maritime Cyber Risk…

Regulatory requirements such as the IMO Maritime Cyber Risk Management Guidelines and IACS Unified E26/E27 have raised the bar on demonstrating effective cyber risk management.…

Situational Awareness

What's Happening & Why It Matters

Perception

What's Happening?

Complex, high-impact cyber attacks targeting operational industries like Oil & Gas are on the rise, from malware on control and safety systems to ransomware that locks down core IT and halts operations. On top of increasing attacks, factors like system obsolescence, greater…

Comprehension

Why Does It Matter?

The unique physical-cyber convergence in Oil & Gas makes organisations vulnerable to exploitation, attackers can commandeer OT systems to disrupt operations or even physically damage assets. Regulatory requirements such as the IMO Maritime Cyber Risk Management Guidelines and…

Solution

Industry Risk Management

For organisations with no or limited OT cyber security risk management, we recommend a holistic, two-phase programme:

Phase 1

Risk Discovery & Prioritization

Identify the most critical OT functions (e.g. upstream wells, pipelines, refineries) and assess the potential impact of a cyber attack against them. Leverage system custodians and engineers to map realistic attack paths, including technical architecture details, user access, third-party scope, supply chain factors and physical security. Real-world industrial scenarios ensure a comprehensive risk picture.

Phase 2

OT Cybersecurity Framework (OT-CSF)

Establish a formal OT-CSF with policies, procedures and playbooks aligned to: Typical elements: Formal governance model (RACI roles), End-to-end operating model, Regulatory compliance mapping, Asset inventory, Network architecture documentation, Incident response plan.

ISA/IEC 62443 NIST CSF NERC-CIP ISO/IEC 27001/27002/27019
Related OT Services

Relevant OT Services

These services are best suited to address the OT risks in this industry.

Need an Industry-Specific
OT Audit?

Our experts with oil & gas OT experience are ready to assess your environment's risks, with standards-aligned methodology.