
OT and ICS Security for Oil and Gas: Keeping Production Safe
Safety instrumented systems, remote sites with satellite links, and vendor tunnels installed at commissioning. Where the real exposure sits.
GuardsArm Team
Security Experts

Oil and gas operations run on control systems designed for reliability and safety over decades, in environments where an unplanned shutdown is measured in serious money and an unsafe condition in something worse.
Security in that context cannot borrow directly from IT practice. Patching on a monthly cycle, aggressive scanning and automated isolation are all inappropriate or actively dangerous against equipment that holds a process in a safe state.
What makes this estate different
| IT assumption | Reality in the field |
|---|---|
| Patch monthly | Patching requires a maintenance window, and vendor approval |
| Scan the network | Active scanning can crash older controllers |
| Isolate a compromised host | Isolation may remove control of a live process |
| Replace end-of-life systems | Equipment has a twenty-year service life |
| Everything is inventoried | Equipment predates every register you have |
| Reliable connectivity | Remote sites on satellite or cellular, intermittently |
The correct response is not to force IT practice onto OT. It is to build compensating architecture around equipment that cannot be hardened directly.
Segmentation is the primary control
The Purdue-style separation between enterprise and control networks, with a controlled intermediate zone, is the reference model. What matters in practice:
- No direct path from a corporate workstation to a controller
- An intermediate zone where data historians and jump hosts live, with enforced inspection on both boundaries
- Egress control from OT, not just ingress. Control systems should not be reaching the internet.
- Segmentation between sites, so a compromise at one facility does not traverse to others
See microsegmentation — the staged approach transfers directly to industrial estates.
Safety instrumented systems are a category apart
SIS exists to bring a process to a safe state independently of the control system. It should be independent in security terms too: separately segmented, with change control that reflects its function, and no shared credentials or engineering workstations with the basic process control system.
Where an operator has allowed the SIS and the control system to share a network, an engineering workstation or an account, that is the finding that matters most in any assessment.
Vendor remote access
The recurring finding across every industrial assessment. Control system suppliers hold persistent access into plant equipment, installed at commissioning, shared among support engineers, frequently unlogged and sometimes unknown to the operator's IT function.
The defensible model is brokered access: the vendor connects to a controlled jump point, authenticates individually with MFA, the session is time-boxed and approved, and it is recorded. See third-party remote access.
Monitoring without touching the process
Passive monitoring — a network tap feeding an OT-aware sensor — gives you asset discovery and anomaly detection without sending a single packet toward a controller. For most operators it is the highest-value first investment, because it simultaneously produces the asset inventory that every other requirement depends on.
Active scanning has a place, in maintenance windows, with vendor agreement, and never as a default.
The regulatory layer
Alberta operators face Regulation 84/2024, requiring a documented programme aligned to CSA Z246.1 with AER enforcement powers. Pipeline operators may additionally fall under the federal Critical Cyber Systems Protection Act.
Build one programme against CSA Z246.1, IEC 62443 and NIST SP 800-82, then map it to each obligation rather than running parallel documentation.
Remote sites change the problem
Wellheads, compressor stations and metering points sit far from anywhere, on satellite or cellular links, visited occasionally. That produces its own set of constraints:
- Bandwidth is limited, so shipping full packet capture or verbose logs centrally is not viable. Collect locally, summarise, forward.
- Links drop, so anything depending on constant connectivity to a central service will fail routinely and train operators to ignore alarms.
- Physical security is minimal, so an attacker with site access has an easier path than one on the network. Cabinet locks, tamper indication and port control matter more than they would in a data centre.
- Updates are carried in, frequently on removable media, which makes controlled media handling a real control rather than a policy line.
Design monitoring on the assumption that a site will be offline sometimes and that the person visiting it is not a security specialist.
Getting a programme started
For an operator beginning from nothing, the order that works:
- Passive asset discovery at one representative site
- Network architecture review — establish what can actually reach what
- Vendor access inventory, asked of the vendors directly
- Segmentation design, prioritising safety systems
- OT-specific incident response, written with operations rather than for them
- Roll out to remaining sites using the first as the template
Step five is worth emphasising. An incident plan written by IT that instructs responders to isolate systems will not survive contact with a control room, and an unusable plan is the same as no plan.
Where to start
Deploy passive monitoring on one site and see what it finds. It is non-intrusive, it produces the asset inventory every other requirement depends on, and in most first deployments it identifies equipment and connections nobody knew were there.
GuardsArm assesses industrial control environments and designs segmentation. See OT and ICS security and oil and gas solutions, or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “OT and ICS Security for Oil and Gas: Keeping Production Safe”
Talk to the GuardsArm team about how these services apply to your environment.


