










Ransomware targeting SCADA, DCS, and production management systems halts operations and extorts payment under extreme commercial and safety pressure. Double-extortion threatens to leak sensitive operational, environmental, and commercial data. Attacks on Safety Instrumented Systems and Emergency Shutdown Systems directly threaten human safety. Recovery in OT environments requires full system revalidation before production restart, extending downtime significantly.
NCSC has identified Russia, Iran, and China as actively targeting UK energy infrastructure. Attacks range from stealing exploration, reservoir, and seismic data to pre-positioning within control systems for potential future disruption. North Sea operations and UK gas distribution networks are strategic national assets. Energy trading data and commercial intelligence are also targeted for economic advantage.
USB-based malware remains a primary vector for compromising air-gapped and semi-air-gapped OT environments across offshore and onshore sites. Remote access infrastructure connecting platforms and field stations is exploited through stolen credentials and VPN vulnerabilities. GPS spoofing and communications interference affect marine and offshore operations. Legacy OT systems on unsupported operating systems are directly exploitable without vendor patch availability.
Oil field services providers, equipment vendors, and OEMs represent supply chain entry vectors into operational environments. Compromised firmware and software updates for control system components introduce malware without direct network access. Third-party remote access for vendor maintenance of SCADA and DCS creates persistent backdoor risk. Concentration risk means a single service provider compromise can cascade across multiple operators.
Phishing targets engineers, control room operators, and offshore personnel who may have limited security awareness training. Business email compromise targets commercial and procurement teams handling high-value contracts. Insider threats from contractors, temporary offshore workers, and departing staff with access to operational systems are difficult to detect. Social engineering exploits the safety culture where urgent requests are acted upon quickly.
Manipulation of environmental monitoring and emissions reporting data carries severe regulatory and reputational consequences under OPRED and DESNZ. Metering and custody transfer data integrity attacks directly affect commercial settlements. Production data manipulation affects operational decisions and reporting accuracy. Exploration, reservoir, and seismic data exfiltration provides competitors and nation-state actors with strategic intelligence.
Mandatory cyber obligations for Operators of Essential Services in oil and gas
Required alignment demonstrating proportionate security controls for NIS compliance
Control of Major Accident Hazards with cyber risk as contributing factor to major accident scenarios
Department for Energy Security and Net Zero sector-specific cyber obligations
Offshore Petroleum Regulator for Environment and Decommissioning requirements
New cyber obligations for the UK energy sector
Industrial automation and control systems security standard for OT environments
Body-certified baseline security for supply chain and partnership requirements
Information security management for enterprise and partner requirements
Personnel data, contractor data, and environmental reporting obligations
SCADA, DCS, and Safety Instrumented System assessments across upstream, midstream, and downstream environments. Pipeline control system reviews, historian server security, and IT/OT segmentation validation. RTU and PLC security assessments for distributed control networks.
Offshore platform and FPSO security assessments covering satellite communications, remote access, marine systems, and physical/OT integration. Unmanned and normally unattended installation reviews. Field station and remote terminal security.
Internal infrastructure penetration testing including password cracking, patching assessments, device hardening, audit logging, and Active Directory security across corporate, control room, and field environments. Network segmentation validation between IT and OT zones.
Web application testing for production management portals, energy trading platforms, and contractor access portals. Cloud security posture reviews for operational analytics, digital twins, and ERP systems using CREST accredited methodologies.
Vendor security assessments for oil field services providers, equipment OEMs, managed service providers, and logistics partners. USB and removable media control reviews for air-gapped OT environments. Third-party remote access security for vendor maintenance channels.
NCSC CAF alignment assessments, NIS Regulations compliance support, and Cyber Essentials Plus certification. Security awareness programmes for engineers, operators, and offshore personnel. Incident response planning for safety-critical OT environments covering production shutdown and environmental incident scenarios.
Simulate attacks on your corporate networks and offshore platforms to identify lateral movement paths to critical SCADA, DCS, and Safety Instrumented Systems (SIS).
View serviceTest your production management portals, energy trading platforms, and remote contractor access gateways for OWASP Top 10 vulnerabilities and data integrity flaws.
View serviceAssess your AWS, Azure, or hybrid cloud environments for misconfigurations that could expose sensitive reservoir models, seismic data, and operational digital twins.
View serviceAudit the security posture, configurations, and access controls of your third-party ERPs, supply chain portals, and environmental monitoring systems.
View serviceAlign your IT and OT security controls with strict energy sector mandates including the NIS Regulations, NCSC CAF, COMAH, and IEC 62443 standards.
View serviceAchieve Cyber Essentials Plus certification, a vital baseline requirement for securing oil field services contracts and reducing energy sector cyber insurance premiums.
View serviceEmpower control room operators and offshore personnel with targeted phishing simulations and continuous dark web monitoring for leaked VPN and remote access credentials.
View serviceIdentify critical vulnerabilities in your iOS and Android field inspection applications, remote diagnostic tools, and mobile pipeline monitoring platforms.
View serviceHarden your corporate M365 environment against Business Email Compromise (BEC) and invoice fraud targeting your procurement, commercial, and energy trading teams.
View service
Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.