Sector-Specific

OT Security for Oil and Gas: Protecting Upstream, Midstream, and Downstream

July 2, 202612 min readBy Beacon Security Team

Three Segments, Three Security Problems

Few industries depend on operational technology as completely, or across as much physical distance, as oil and gas. The sector runs from remote wellheads and offshore platforms, through thousands of kilometers of pipeline, into densely instrumented refineries and petrochemical complexes. A single operator may run control systems that span all of it.

That span is why oil and gas is best understood not as one uniform environment but as three related ones. The threats, the operational constraints, and the consequences of a cyber incident differ meaningfully across the segments. Upstream is defined by distance and remote, distributed assets. Midstream is defined by the scale of pipeline SCADA stretched across vast geography. Downstream is defined by the concentration of hazard in a complex processing facility. This guide examines the threat landscape common to the whole sector, then works through the distinct challenges and controls for each segment.

The Threat Landscape Facing Oil and Gas

Threat intelligence tracks several groups with demonstrated interest in the energy and oil and gas sectors, and understanding them is the foundation of a threat-informed program.

XENOTIME holds a specific and serious distinction: it is associated with the 2017 TRITON attack, the first known malware built to target a safety instrumented system, the automated last line of defense designed to bring a hazardous process to a safe state. Following that event, XENOTIME was observed conducting reconnaissance against energy targets in multiple regions. Its demonstrated focus on safety systems makes it the highest-consequence threat to any operator running them.

HEXANE and MAGNALLIUM are groups with documented focus on energy and oil and gas, including operators and adjacent industrial and telecom targets, with particular activity in the Middle East. ELECTRUM, associated with attacks on power infrastructure, and financially motivated ransomware groups that have developed operational knowledge of industrial environments, round out a landscape in which oil and gas is a clear and recurring target.

The reasons are straightforward. Energy is strategically important, operations are highly valuable, and disruption creates significant pressure, a combination that attracts both nation-state and criminal actors.

Upstream: Securing Remote and Distributed Production

Upstream operations, covering exploration and production, are defined by distance and exposure. Wellheads, gathering systems, and offshore platforms are frequently located far from any staffed facility and connected to a central control room over cellular, licensed radio, or satellite links, often carrying protocols such as Modbus or DNP3 that provide little native security.

The defining challenges are:

  • Unmanned and remote sites, where physical access controls are naturally limited and an intruder reaching an RTU or network cabinet has a potential route toward the field.
  • Long, exposed communication links, which carry SCADA traffic over shared or public infrastructure and benefit from encryption and authentication to guard against interception and manipulation.
  • Long-lived field devices, such as RTUs and flow computers, chosen for durability and often running for years on original firmware and unauthenticated protocols.

The security emphasis upstream is on protecting distributed field assets and the links that reach them. This means securing site-to-center communications, hardening and monitoring RTUs and field controllers, applying physical and tamper protection at unmanned sites, and segmenting each remote location so that a compromise there cannot propagate into the central SCADA master. Segmentation upstream is not only between IT and OT, but between individual remote sites and the core.

Midstream: Securing the Pipeline

Midstream operations, covering transportation and storage, are dominated by the pipeline, and the defining security challenge is a geographically enormous SCADA system controlling flow, pressure, and leak detection across distances that can span jurisdictions.

The Colonial Pipeline incident of May 2021 shaped how the sector and its regulators approach this. Ransomware affected the operator's IT environment, and the intrusion did not need to reach the control systems. Because the separation between IT and OT was not fully certain, the operator made the prudent decision to pause a pipeline supplying a large share of a region's fuel while it confirmed the control systems were safe. The event highlighted that, in midstream, the IT to OT boundary and the plan for responding when it is threatened are themselves critical security controls.

The regulatory response is now a compliance reality. In the United States, the TSA issued Security Directives for critical pipelines, since revised into a performance-based model, requiring network segmentation between IT and OT, access control for critical cyber systems, continuous monitoring and detection, patch management, and a set of documented plans including a Cybersecurity Implementation Plan, an Incident Response Plan, and a Cybersecurity Assessment Program. These align with API Standard 1164 for pipeline SCADA security, the NIST Cybersecurity Framework, and IEC 62443.

Defensive implication: Midstream security depends on a clearly enforced separation between enterprise IT and pipeline control, strong monitoring of the SCADA network, well-governed remote access for the operators and vendors who support far-flung assets, and an incident response plan that has rehearsed the most consequential decision of all: when to shut the line.

Downstream: Securing the Refinery

Downstream operations, covering refining and petrochemicals, present the opposite profile to upstream. Rather than sparse assets across distance, the challenge is density and consequence concentrated in a single hazardous facility. A refinery is a tightly coupled system of distributed control systems, safety instrumented systems, historians, and thousands of instruments coordinating processes involving heat, pressure, and hazardous materials.

Two systems define the downstream security challenge. The distributed control system (DCS), from vendors such as Honeywell, Yokogawa, Emerson, and ABB, runs the process day to day and must be protected from unauthorized change. The safety instrumented system (SIS), from vendors such as Triconex and HIMA, sits behind it as an independent protection layer and must remain both available and trustworthy. The SIS is the layer that TRITON targeted, and IEC 61511 now carries explicit cybersecurity expectations for it. Alongside these, the significant vendor and remote access footprint that these complex platforms require must be carefully governed.

Defensive implication: In downstream operations, cybersecurity and process safety are inseparable. A cyber incident affecting the DCS or SIS is potentially a safety incident, so protecting the control and safety layers, and verifying rather than assuming their isolation, is the highest security priority in the facility.

Threats Common to the Whole Chain

While the segments differ, several threats apply across all of them and justify a consistent baseline:

  • Ransomware, which has affected oil and gas operations and, as Colonial illustrated, can influence operations even without directly reaching OT.
  • Nation-state activity, given the strategic importance of energy, including quiet pre-positioning in systems that matter during a crisis.
  • Supply chain and vendor risk, arising from the sector's heavy reliance on equipment vendors and integrators.
  • IT and OT convergence, which delivers real operational value while connecting once-isolated control systems to enterprise networks.

Building a Program Across the Value Chain

An operator with assets across all three segments benefits from a program that is consistent in principle and adapted in application.

  1. Establish visibility everywhere. Enumerate every asset, from a remote wellhead RTU to a refinery safety controller. Distributed and hard-to-reach assets are the ones most likely to be undocumented, and visibility is the foundation for protecting them.
  2. Segment by consequence using IEC 62443 zones and conduits. Separate IT from OT, remote sites from central control, and safety systems from general process systems, giving the SIS its own zone at the highest target Security Level.
  3. Govern remote and vendor access carefully. Across all three segments, this is both operationally essential and a leading area of risk, and it benefits from strong authentication, least privilege, and session recording.
  4. Protect safety systems as a distinct priority, especially downstream, by verifying SIS isolation and integrity against IEC 61511 and IEC 62443.
  5. Rehearse incident response, including the shutdown decision, so that difficult operational choices are made against a practiced plan.
  6. Align to a recognized framework. IEC 62443 provides the structure to make security consistent across a multi-segment enterprise and to satisfy the regulatory expectations converging on the sector, from pipeline directives to the NCA OTCC in the Gulf.

The Bottom Line

Oil and gas presents three distinct security problems along a single value chain: distance at the wellhead, scale across the pipeline, and consequence inside the refinery. Operators who respect those differences while binding them under one coherent, framework-aligned program are far better positioned than those who treat the whole enterprise as uniform.

In Beacon Security's experience across energy and oil and gas environments, the areas that most often benefit from attention are practical ones: fuller documentation of remote assets, a clearer boundary between IT and OT, and well-governed vendor access. Each is addressable, and strengthening them meaningfully improves resilience across the entire value chain.


Beacon Security delivers OT cybersecurity assessments, architecture, and compliance support across upstream, midstream, and downstream oil and gas operations, aligned with IEC 62443 and IEC 61511. Contact us to discuss securing your operations across the value chain.

Industrial infrastructure
OT Cybersecurity Experts

Your OT Environment Deserves
Expert Protection

IT security tools were not built for Modbus, OPC, or safety-rated controllers. Get a dedicated OT cybersecurity team that understands industrial protocols, control system architecture, and the operational constraints of your environment.

IEC/ISA 62443 Aligned
NIST 800-82 Compliant
OTCC Ready
ECC Aligned
Zero Operational Disruption