The Prioritized Industrial Cyber Defense in Oil and Gas white paper, published by SANS Institute in March 2025, applies the SANS Five ICS Cybersecurity Critical Controls to industrial cybersecurity in the oil and gas sector. Developed exclusively for ONE-ISAC members, the paper addresses upstream, midstream, and downstream environments, covering defensible architecture, incident response, network monitoring, remote access, and vulnerability management for ICS/OT operations.
Key findings:
- The paper centers on the SANS Five ICS Cybersecurity Critical Controls: ICS-specific incident response, defensible control system network architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management
- Oil and gas facilities break into three operational segments with distinct cyber risk profiles: upstream (exploration and extraction), midstream (transportation and storage), and downstream (refining and distribution)
- Halliburton confirmed a cyberattack in August 2024 that led to unauthorized data exfiltration and disrupted some business applications
- The 2021 Colonial Pipeline ransomware attack targeted IT systems but forced a full shutdown of ICS/OT pipeline operations across the US East Coast
- In 2017, the Triton/TRISIS malware attacked a Saudi Arabian petrochemical plant by targeting safety instrumented systems, risking physical asset destruction and loss of life
- PIPEDREAM, discovered in 2022, is a modular malware framework capable of interacting with native industrial protocols across multiple critical infrastructure sectors, including oil and gas
- The paper names OilRig, HEXANE, Temp.Veles/XENOTIME, and APT33 as adversary groups known to target the oil and gas sector
- ICS/OT environments depend on proprietary protocols such as Modbus TCP, DNP3, OPC, and PROFINET, in addition to traditional IT protocols like HTTP and SSH
- The paper recommends that IT security teams support and collaborate with ICS/OT engineering staff rather than direct security strategy, since misapplied IT tools like EDR or active vulnerability scanners can destabilize control system processes
- Defensible architecture needs vary by segment: upstream relies on satellite links and possible air gaps, midstream uses segmentation around compressor stations and telemetry, and downstream applies micro-segmentation against IT and internet-facing risk
The paper's throughline is that a one-size-fits-all cybersecurity model does not work for oil and gas ICS/OT environments. Upstream, midstream, and downstream operations each carry different architecture, access, and incident response needs, so the same five critical controls must be adapted rather than applied uniformly. It also reinforces that engineering teams, not IT security alone, should lead control system security decisions given the safety and physical-process stakes involved.
This white paper was developed for ONE-ISAC members and cybersecurity professionals working across upstream, midstream, and downstream oil and gas operations, with a focus on ICS/OT engineering and IT security collaboration.