Cybersecurity for Oil and Gas and Pipeline Operators
Oil and gas operations run some of the most widely distributed and highest-consequence control systems anywhere. A single company may operate hundreds of remote sites, many unstaffed, all reporting back to a central control room over radio, cellular or satellite links. Securing that environment calls for a practical approach that respects how the industry actually works.
A wide range of assets

The industry is often described in three segments, and each brings its own control system profile.
Upstream covers exploration and production: wellsites, pads, batteries, gathering systems and, in places like Canada's oil sands, large integrated mining and in-situ facilities. Many sites are remote, small and automated, with controllers and RTUs reporting to SCADA.
Midstream covers gas processing, compression, pipelines, storage and terminals. Pipeline SCADA spans enormous distances, with pump and compressor stations, block valves and metering sites along the route.
Downstream covers refining, petrochemicals and distribution. Refineries run large distributed control systems (DCS) and safety instrumented systems (SIS) in dense, complex plants.
What ties them together is long asset life, a mix of vendors and generations of technology, and processes where a loss of control can affect safety, the environment and the communities around the facility.
Remote sites and distributed SCADA
The defining challenge for upstream and midstream operators is geography. Remote sites are often reached by licensed or unlicensed radio, cellular modems, satellite links or third-party networks. RTUs and small PLCs at those sites may have been installed years ago, with limited security features and default settings that were never changed.
Common issues across the sector include:
Cellular modems and gateways reachable from the internet, sometimes with default credentials.
Flat networks where a compromise at one remote site could reach the central SCADA host.
Unencrypted, unauthenticated protocols such as Modbus or older DNP3 implementations running over shared links.
Physical security gaps at unstaffed sites, where an outsider with a laptop and some time could connect directly.
Vendor and contractor remote access paths that are poorly documented and loosely controlled.
High-consequence systems: leak detection and safety
Two systems deserve particular attention.
Leak detection on pipelines often relies on computational methods that use SCADA data, such as flow, pressure and temperature, to identify possible releases. If that data is unavailable or untrustworthy, controllers may lose an important safety tool and have to fall back on more conservative operating decisions or a shutdown.
Safety instrumented systems are the last automated line of defence in processing plants and refineries. They should be independent from the basic process control system, with tightly controlled access and changes managed through functional safety processes. Connections between the SIS and other networks deserve careful review.
What real incidents teach us
Two well-known incidents shape how the industry thinks about this risk.
In May 2021, Colonial Pipeline, which operates a major fuel pipeline system in the eastern United States, was hit by ransomware that the FBI attributed to the DarkSide group. The attack affected business IT systems, and the company shut down pipeline operations as a precaution for several days, contributing to fuel shortages and panic buying in parts of the region. The lesson was that IT-side ransomware can halt physical operations, especially when business systems such as billing and scheduling are tightly coupled to the ability to operate.
In 2017, malware later named TRITON (also called TRISIS) targeted the safety instrumented system at a petrochemical facility in Saudi Arabia. The attack was discovered after it triggered a safe shutdown. In 2020, the US government sanctioned a Russian government-backed research institute in connection with it. TRITON was a sobering reminder that attackers were willing to target the systems specifically intended to prevent loss of life.
Standards and regulatory expectations
Several frameworks apply to oil and gas operators.
IEC 62443 is the international series for industrial automation and control system security. Its zones and conduits model and security levels are widely used across the sector, and many vendors certify products and processes against it.
API Standard 1164, Pipeline Control Systems Cybersecurity, provides pipeline-specific guidance. Its third edition, published in August 2021, draws on the NIST Cybersecurity Framework and broadens the scope from SCADA alone to all pipeline control systems.
TSA security directives have applied since 2021 to US hazardous liquid and natural gas pipelines and LNG facilities that TSA has identified as critical, following the Colonial incident. They require incident reporting, a cybersecurity coordinator and, under later revisions, performance-based measures such as segmentation, access control, continuous monitoring and an incident response plan.
In Canada, pipelines regulated by the Canada Energy Regulator (CER) must have a security management program, and the CER points companies to CSA Z246.1, Security management for petroleum and natural gas industry systems, which covers both physical and cyber security.
Provincial regulators may also set requirements for pipelines and facilities under their jurisdiction, so it is worth confirming which rules apply to each asset.
Priority actions
For most operators, the following steps deliver the most value early:
Build an accurate inventory of SCADA hosts, remote sites, RTUs, PLCs, communication links and modems. Passive monitoring at key aggregation points can fill gaps safely.
Lock down remote access, including vendor connections, with multi-factor authentication, individual accounts, session logging and an approval process.
Find and close internet exposure, particularly cellular modems and gateways at remote sites.
Segment the control network from business IT, and limit what each remote site can reach. Reduce dependencies that would force a shutdown if business systems are lost.
Protect the SIS with strict separation, access controls and change management.
Prepare for incidents with an OT-specific response plan, offline backups of controller and SCADA configurations, and manual operating procedures that have been practised.
Align with a recognized framework such as IEC 62443 or API 1164 so progress can be measured and communicated to regulators and leadership.
How QBits Networks can help
Our team works with oil and gas, pipeline, gas processing and oil sands operators on passive-first OT security assessments, secure remote access reviews and IEC 62443 gap assessments that take the realities of remote, distributed operations into account. Tell us what you need through our contact page and we'll scope it with you.