WisePlant – A WiseGroup Company

OIL AND GAS

The oil and gas industry or also called the hydrocarbons sector chain corresponds to the set of economic activities related to exploration, production, transport, refining or processing and marketing of non-renewable natural resources known as hydrocarbons (organic material composed mainly of hydrogen and carbon), this set is also made up of the regulation and administration of these activities.

PROCESSES

The value chain typically consists of three major areas; (a) exploration and production – upstream, (b) Transport – midstream, and (c) Refining and Marketing – downstream.

Also known as exploration and production (E&P), this sector includes the search for potential crude oil and natural gas deposits, both underground and underwater, the drilling of exploratory wells, and subsequently the drilling and exploitation of wells that bring crude oil or natural gas to the surface.

It consists of transporting them from the wellhead to storage and processing sites, such as pumping stations, refineries and marketing centers (ports). Hydrocarbons are transported through oil (petroleum), gas pipelines (gas), tank cars (oil) and ships (oil).

It commonly refers to the tasks of refining crude oil and the processing and purification of natural gas, as well as the marketing and distribution of products derived from crude oil and natural gas. Refining consists of transforming oil by subjecting it to high temperatures, which reach 400 degrees Celsius, to obtain derived products. Process by which a wide variety of derived products are transformed, mainly fuels (ACPM and gasoline) and petrochemicals (petroleum jelly, brushes, tires, plastics).

In this link all those activities of a commercial nature are carried out, to make the products available to users. Typically, wholesale or retail distributors are used. Petroleum and gas derivatives are usually gasoline, lubricants, poison, kerosene, tires, paraffin, detergents, polyethylene, solvents, and others.

NEEDS

The hydrocarbon industry is generally highly regulated, often with price controls and is often the government of ownership and operation. Typically, many of the facilities involved in each of the industry’s processes can come to be considered critical infrastructure and therefore of national interest. This classification should be determined as a result of the criticality assessment using appropriate assessment methods, techniques and models. Suppliers of industrial automation, security, and service systems in conjunction with hydrocarbon operators must ensure compliance with security and cybersecurity standards, such as ISA/IEC-62443, NIST 800-53/82, IEC-61511, API, NPFA, and others. Keeping up with rules and regulations is a challenge.

SECURITY AND COMPLIANCE

Strategies and solutions based on information security technologies and perimeters are not enough to protect against all modern threats against electrical infrastructures. Industrial cybersecurity requires the protection of physical assets, i.e. the domain of physical security. Many programmable logic controllers (PLCs) and controllers for feed water pumps, feed water, valves, furnaces, boilers, turbines, generators, and capacitors are vulnerable due to the lack of built-in cryptographic controls, including: multi-factor authentication, secure boot, secure update, and encrypted secure communications.

OUR SOLUTION

In operational technology (OT) environments, risk is measured in terms of industrial safety and system availability. While data privacy is important, often human physical security, industrial process safety, environmental stewardship, and uptime drive the security needs of plants and large SCADA systems.

|

Most Common Security Risks to Oil & Gas Industries

Ransomware Attacks: Disrupt operations by encrypting critical systems. High-profile example: the Colonial Pipeline attack, which halted fuel distribution across the U.S. East Coast.

Phishing & Social Engineering: Entry point for most ransomware and credential theft. Exploits human error to bypass technical defenses.

Industrial IoT (IIoT) Vulnerabilities: Smart sensors and remote monitoring expand the attack surface. Many IIoT devices lack robust security controls.

Legacy Systems & Patch Gaps: Outdated SCADA and DCS platforms are common. Often incompatible with modern security tools, making patching difficult.

Supply Chain Attacks: Compromised third-party software or hardware introduces hidden threats. Attackers may exploit firmware updates or vendor access.

Insider Threats: Employees or contractors with privileged access may intentionally or accidentally cause harm. Often overlooked in risk assessments.

Distributed Denial-of-Service (DDoS): Overloads systems to disrupt operations or distract from deeper intrusions. AI-driven DDoS attacks are becoming more sophisticated.

Remote Access Exploits: VPNs and remote desktop tools are often misconfigured. Especially risky in offshore or unmanned facilities.

Some Strategic Mitigation Approaches

  • Adopt ISA/IEC-62443 for OT cybersecurity lifecycle management.
  • Segment IT and OT networks with strict access controls.
  • Implement continuous monitoring (SIEM, IDS/IPS).
  • Train personnel on phishing and incident response.
  • Vet third-party vendors and require SBOMs (Software Bill of Materials).
  • Develop and test incident response plans regularly.

|

OTConnect News. Articles and Publications.

Diesel protecting facility explosion

Explosion at diesel processing facility injures worker in mexico facility

An explosion at a diesel processing facility in Mexico injures a worker, prompting an urgent investigation and safety review ...
Chemical Plant Explotion

Chemical plant fire in Spain sends several towns into lockdown

Discover the aftermath of a chemical plant fire in Spain, as several towns go into lockdown. Emergency response efforts intensify ...
The Flixborough disaster realistic image covering the incident

The Flixborough disaster

Explore the profound impact of the Flixborough disaster on safety regulations, industry practices, and the enduring lessons learned ...
Fire on Petrobras offshore platform seriously injures 14

Fire on Petrobras offshore platform seriously injures 14

WisePlant explores the aftermath of a serious fire incident on a Petrobras offshore platform, delving into injuries, emergency response, investigation, ...
Svilosa Chemical plant fire injures three employees

Svilosa Chemical plant fire injures three employees

An explosion and subsequent fire left three employees injured at a Bulgarian chemical plant on 29 July. The incident happened ...
may 23 pemex refinery blaze injures four

Pemex refinery blaze injures four

"May 23: A Day of Tragedy as Pemex Refinery Blaze Injures Four" ...
A factory fire in Hull, UK, involved 300 tonnes of plastic

A factory fire in Hull, UK, involved 300 tonnes of plastic

A major incident was reported in Hull, north-west England, on 24 November after a fire broke out in a factory ...
Fire injures “a number of people” at Kuwait’s largest oil refinery

Fire injures “a number of people” at Kuwait’s largest oil refinery

A fire broke out at Kuwait’s largest oil refinery on October 18 and injured several people. The incident occurred at ...
UK gas processing terminal shut down after methane leak

UK gas processing terminal shut down after methane leak

The Easington Gas Terminal in East Yorkshire, UK was shut down on October 19 after a methanol leak was discovered ...
First interim report into July chemical explosion that killed seven in Leverkusen reveals likely cause

First interim report into July chemical explosion that killed seven in Leverkusen reveals likely cause

The first interim report on the investigation into the July 27 explosion at a chemical waste incineration plant in Leverkusen, ...
US CSB releases safety video on fatal 2019 hydrogen sulphide release

US CSB releases safety video on fatal 2019 hydrogen sulphide release

The US Chemical Safety Board (CSB) has released a safety video into the October 26, 2019, hydrogen sulfide release at ...
US refinery reaches $1 million settlement, admits no wrongdoing in 2018 explosion that injured 36

US refinery reaches $1 million settlement, admits no wrongdoing in 2018 explosion that injured 36

The Superior Refining Company has reached a settlement of around $1 million in relation to the 2018 explosion at its ...
Russian chemical plant fire kills seven

Russian chemical plant fire kills seven

A fire at a chemical plant in southern Russia killed seven people on July 29. The seven people were initially ...
US chemical plant leak kills two, injures 30

US chemical plant leak kills two, injures 30

A chemical leak at a plant in La Porte, Texas left two people dead and another 30 injured on July ...
2 dead, 30 hospitalized after 'mass casualties' incident at LyondellBasell chemical plant near La Porte

2 dead, 30 hospitalized after ‘mass casualties’ incident at LyondellBasell chemical plant near La Porte

The incident comes just days after a leak at a Dow Chemical plant in La Porte and another LyondellBasell leak ...
Chemical park explosion kills two person in Germany, five people still missing and 31 injured

Chemical park explosion kills two person in Germany, five people still missing and 31 injured

An explosion at an industrial park in Leverkusen, Germany killed two people and injured 31 others on July 27. The ...
Pipeline Pumping Station Explosion Kills Three in Iran

Pipeline Pumping Station Explosion Kills Three in Iran

An explosion at an oil pipeline pumping station in southern Iran killed three workers and injured four others on July ...
Chemical factory explosion kills one and leaves 39 injured in Thailand

Chemical factory explosion kills one and leaves 39 injured in Thailand

A fire and explosion at a plastics factory in Bangkok initially injured 21 people on July 5. Despite firefighters' efforts ...
'Eye of Fire' in Gulf of Mexico Caused by Thunderstorm, Says PEMEX

‘Eye of Fire’ in Gulf of Mexico Caused by Thunderstorm, Says PEMEX

Petroleos Mexicanos (PEMEX) has said the cause of the 'eye of fire' that occurred in the Gulf of Mexico on ...
The explosion of a chemical plant causes major fires and mass evacuations in the US.

The explosion of a chemical plant causes major fires and mass evacuations in the US.

An explosion at a chemical plant in northern Illinois, USA, On June 14, it sparked a large fire and resulted ...
Oil company fined £400,000 for North Sea platform gas leak

Oil company fined £400,000 for North Sea platform gas leak

Offshore Apache oil company was fined £400,000 after it failed to provide written safety procedures for the depressurisation of an ...
Massive fire at chemical plant in Rockton, Illinois, could burn for days

Massive fire at chemical plant in Rockton, Illinois, could burn for days

Authorities are allowing a massive fire from a chemical plant in Rockton, Illinois, to burn, which could take several days, ...
Deadly explosion reported at Romania's largest oil refinery

Deadly explosion reported at Romania’s largest oil refinery

Thick black smoke from the fire was reported to be moving away from the Romanian coast towards the Black Sea ...
Cyberattack forces closure of major U.S. pipeline

Cyberattack forces closure of major U.S. pipeline

A cyberattack forced the temporary closure of one of the largest pipelines in the United States on Friday, underscoring already ...
Manage, evaluate, and deploy ISA/IEC-62443 like an expert

Manage, evaluate, and deploy ISA/IEC-62443 like an expert

The new training courses 2150, 2160, 2161, and 2162 are dedicated exclusively and primarily to implementation and compliance, with the ...
ARPEL and WisePlant sign cooperation agreement to promote the strengthening of cybersecurity in the energy sector in Latin America and the Caribbean

ARPEL and WisePlant sign cooperation agreement to promote the strengthening of cybersecurity in the energy sector in Latin America and the Caribbean

ARPEL (Regional Association of Companies in the Oil, Gas and Bio-fuels Sector in Latin America and the Caribbean) recently signed ...
We were at the Industrial Cybersecurity Seminar ARPEL 2018

We were at the Industrial Cybersecurity Seminar ARPEL 2018

Once again we were present at the Seminar on Industrial Cybersecurity and Critical Infrastructures ARPEL 2018 organized by ARPEL, OAS, ...

By corporate policy we do not publish, nor do we provide information about our customers or their applications. In case of needing technical and / or commercial references, these must be requested formally, and will be answered only with the prior authorization of our customers.