Skip to content

Cybersecurity

OT cybersecurity in oil & gas: refineries, pipelines and terminals under pressure

In oil & gas, cybersecurity is intertwined with process safety: a cyber incident can become a physical one. Risks, safety systems and strategies for refineries, pipelines and terminals.

3 min read
Oil & gas facility with connected process control and safety systems

When cyber and safety coincide

Oil & gas is the sector where OT cybersecurity shows its most serious face. In a factory, an attack halts production. In a refinery or a petrochemical plant, the worst-case scenario is not the loss of output: it is the physical incident. Fires, explosions, toxic releases. Cybersecurity does not protect just any process, it contributes to the safety of people and the environment.

This changes the priorities. The classic cybersecurity triad (confidentiality, integrity, availability) is turned upside down: in oil & gas, the integrity and availability of control systems, and above all the protection of safety systems, come before everything else.

The systems at risk along the value chain

The value chain is divided into three segments, each with its own profile.

Upstream (extraction): wells, platforms, control systems often distributed across remote and hostile locations, with satellite or radio communications. The surface is dispersed and hard to oversee.

Midstream (transport): pipelines and terminals. Here SCADA distributed over long distances dominates. Pumping stations and remote valves communicate with control centers through networks that, if not segmented and encrypted, are exposed. An attack on management systems, even without touching the process, can force a precautionary shutdown of the entire line, as demonstrated by recent incidents that halted fuel distribution for days.

Downstream (refining): refineries and petrochemical plants, the environments most densely packed with process control. DCS, PLCs and, above all, safety systems.

The heart of the problem: safety systems

Every major-hazard facility is equipped with a Safety Instrumented System (SIS): the independent network of sensors and actuators that brings the process into a safe condition when parameters move outside their limits. It is the last line of defense against the physical incident.

The Triton/TRISIS attack hit exactly this layer in a petrochemical plant, with the goal of manipulating the SIS. It is the scenario that keeps safety engineers awake at night: an attacker disabling the protection network while, at the same time, pushing the process toward going out of control.

The practical consequence is a clear rule: safety systems must be kept rigorously separate from process control systems, with minimal, monitored and ideally one-way communications. Any access to the SIS must be an exceptional event, logged and alarmed.

The regulatory framework

The energy sector is among the essential sectors under NIS2, with full obligations for risk management, notification and supply chain security. Layered on top of this is a long tradition of process safety regulations (the Seveso Directive at European level for major-hazard establishments), which cybersecurity must integrate with without creating conflicts.

The organizational challenge is precisely this convergence: process safety teams and cybersecurity teams have different cultures, languages and life cycles. Getting them to work together on the same plant is half the job.

A practical defensive approach

The principles are the well-established OT ones, applied with safety priority at the front:

  1. Inventory and visibility of the entire control estate, with explicit mapping of where safety systems live.
  2. Isolation of the SIS as the first and non-negotiable line of defense, separated from the DCS and from the rest of the network.
  3. Segmentation into zones and conduits according to IEC 62443, naturally suited to plants with distinct process functions.
  4. Passive monitoring that includes dedicated surveillance of traffic toward safety systems: any anomalous activity there is a top-priority alert.
  5. Security of distributed communications for pipelines and remote sites: channel encryption, station authentication, remote access control.
  6. Safety-security convergence: incident response plans that involve both teams and account for process constraints.

In oil & gas, the margin for error is the thinnest of all OT sectors. It is also why this is the sector where a well-run security program is worth the most.

The MON5 angle

The rule stated above is clear: any access to the SIS must be an exceptional event, logged and alarmed. This is exactly the kind of surveillance MON5 implements with passive, out-of-band NDR: traffic toward safety systems is observed without interacting with the process, and every anomalous communication generates a top-priority alert.

For pipelines and remote sites, the platform's multi-site architecture aggregates telemetry from distributed stations into a centralized view, with continuous asset inventory and segmentation into IEC 62443 zones and conduits. The path starts with an OT assessment that maps where safety systems live, without stopping the plant.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

Related articles

Power grid control panel in the dark during a blackout

Cybersecurity

The Iberian Blackout: Lessons for Critical Energy Infrastructure

The blackout that brought Spain and Portugal to a standstill shows how fragile energy grids are and why visibility into OT assets is decisive.

2 min read
Water treatment plant with SCADA systems and field IoT sensors

Cybersecurity

Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure

Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

3 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna