Back to Blog
Industry Specific
5 min read

OT and ICS Security for Oil and Gas: Keeping Production Safe

Safety instrumented systems, remote sites with satellite links, and vendor tunnels installed at commissioning. Where the real exposure sits.

GuardsArm Team

Security Experts

September 25, 2026

OT and ICS security for oil and gas operators

Oil and gas operations run on control systems designed for reliability and safety over decades, in environments where an unplanned shutdown is measured in serious money and an unsafe condition in something worse.

Security in that context cannot borrow directly from IT practice. Patching on a monthly cycle, aggressive scanning and automated isolation are all inappropriate or actively dangerous against equipment that holds a process in a safe state.

IT practice can be unsafe here
Scanning and isolation have physical consequences
Vendor tunnels are the finding
Installed at commissioning, rarely logged
Passive monitoring first
Asset inventory without touching the process

What makes this estate different

IT assumptionReality in the field
Patch monthlyPatching requires a maintenance window, and vendor approval
Scan the networkActive scanning can crash older controllers
Isolate a compromised hostIsolation may remove control of a live process
Replace end-of-life systemsEquipment has a twenty-year service life
Everything is inventoriedEquipment predates every register you have
Reliable connectivityRemote sites on satellite or cellular, intermittently

The correct response is not to force IT practice onto OT. It is to build compensating architecture around equipment that cannot be hardened directly.


Segmentation is the primary control

Segmentation layers in an industrial estateEnterprise network, an inspected intermediate zone, supervisory control, basic process control, and safety instrumented systems kept separate from all of it.Enterprise networkCorporate IT — no direct path onwardIntermediate zoneHistorians and jump hosts, inspected both waysSupervisory controlHMIs and engineering workstationsBasic process controlControllers and field devicesSafety instrumented systemsSeparate again — no shared accounts or workstations
The bottom layer sharing anything with the one above it is the finding that matters most.

The Purdue-style separation between enterprise and control networks, with a controlled intermediate zone, is the reference model. What matters in practice:

  • No direct path from a corporate workstation to a controller
  • An intermediate zone where data historians and jump hosts live, with enforced inspection on both boundaries
  • Egress control from OT, not just ingress. Control systems should not be reaching the internet.
  • Segmentation between sites, so a compromise at one facility does not traverse to others

See microsegmentation — the staged approach transfers directly to industrial estates.


Safety instrumented systems are a category apart

SIS exists to bring a process to a safe state independently of the control system. It should be independent in security terms too: separately segmented, with change control that reflects its function, and no shared credentials or engineering workstations with the basic process control system.

Where an operator has allowed the SIS and the control system to share a network, an engineering workstation or an account, that is the finding that matters most in any assessment.


Vendor remote access

The recurring finding across every industrial assessment. Control system suppliers hold persistent access into plant equipment, installed at commissioning, shared among support engineers, frequently unlogged and sometimes unknown to the operator's IT function.

The tunnel nobody remembers is the way in
Assessments find vendor remote access by looking at installed software on engineering workstations rather than at firewall rules, because the connection is frequently outbound and invisible to the perimeter. Ask each control system supplier directly what access they hold, and verify the answer.

The defensible model is brokered access: the vendor connects to a controlled jump point, authenticates individually with MFA, the session is time-boxed and approved, and it is recorded. See third-party remote access.


Monitoring without touching the process

Passive monitoring — a network tap feeding an OT-aware sensor — gives you asset discovery and anomaly detection without sending a single packet toward a controller. For most operators it is the highest-value first investment, because it simultaneously produces the asset inventory that every other requirement depends on.

Active scanning has a place, in maintenance windows, with vendor agreement, and never as a default.


The regulatory layer

Alberta operators face Regulation 84/2024, requiring a documented programme aligned to CSA Z246.1 with AER enforcement powers. Pipeline operators may additionally fall under the federal Critical Cyber Systems Protection Act.

Build one programme against CSA Z246.1, IEC 62443 and NIST SP 800-82, then map it to each obligation rather than running parallel documentation.


Remote sites change the problem

Wellheads, compressor stations and metering points sit far from anywhere, on satellite or cellular links, visited occasionally. That produces its own set of constraints:

  • Bandwidth is limited, so shipping full packet capture or verbose logs centrally is not viable. Collect locally, summarise, forward.
  • Links drop, so anything depending on constant connectivity to a central service will fail routinely and train operators to ignore alarms.
  • Physical security is minimal, so an attacker with site access has an easier path than one on the network. Cabinet locks, tamper indication and port control matter more than they would in a data centre.
  • Updates are carried in, frequently on removable media, which makes controlled media handling a real control rather than a policy line.

Design monitoring on the assumption that a site will be offline sometimes and that the person visiting it is not a security specialist.


Getting a programme started

For an operator beginning from nothing, the order that works:

  1. Passive asset discovery at one representative site
  2. Network architecture review — establish what can actually reach what
  3. Vendor access inventory, asked of the vendors directly
  4. Segmentation design, prioritising safety systems
  5. OT-specific incident response, written with operations rather than for them
  6. Roll out to remaining sites using the first as the template

Step five is worth emphasising. An incident plan written by IT that instructs responders to isolate systems will not survive contact with a control room, and an unusable plan is the same as no plan.


Where to start

Deploy passive monitoring on one site and see what it finds. It is non-intrusive, it produces the asset inventory every other requirement depends on, and in most first deployments it identifies equipment and connections nobody knew were there.

GuardsArm assesses industrial control environments and designs segmentation. See OT and ICS security and oil and gas solutions, or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “OT and ICS Security for Oil and Gas: Keeping Production Safe”

Talk to the GuardsArm team about how these services apply to your environment.