Energy

Cyber security for oil and gas in the UAE

Upstream, midstream and downstream all run control systems where an unplanned stop has a cost measured in hours of production and, sometimes, in safety. We bring those environments into visibility passively and keep the corporate side from reaching them.

Cyber security services for the oil and gas industry in the UAE
Why energy is different

When the process is physical, a security action has physical consequences

In most estates the worst outcome of a wrong security decision is an outage. In energy it can be equipment damage or a safety event, because the systems being protected govern pressure, flow and temperature rather than records. That single fact rules out much of what is routine elsewhere.

The equipment is also long lived and deliberately conservative. Controllers specified twenty years ago are still in service because the process was qualified around them, and replacing one is an engineering project rather than an upgrade. They cannot take an agent, frequently cannot be patched, and in some cases will not tolerate being scanned.

Meanwhile the sites are spread out and the connections have multiplied. Remote facilities, historians feeding corporate reporting, contractors with maintenance access and engineering laptops that move between networks all create paths that were added one at a time for good operational reasons. Collectively they are the route by which corporate problems become production problems.

What works is structural and unglamorous: know precisely what is on the control network, define the zones and the conduits between them, control vendor access, and watch passively. Detection matters, but it is worth far less than a boundary that holds.

The threat picture

What actually reaches an energy control environment

Direct attacks on control systems make the news. The incidents that occur are usually more ordinary and arrive from the corporate side.

Ransomware crossing the boundary

Almost never aimed at the control system itself. It arrives in the corporate estate and travels through a connection that turned out to be more permissive than the diagram showed, and production stops as a consequence rather than as a target.

Contractor and vendor access

Maintenance access held by equipment suppliers and service contractors is frequently standing, broadly scoped and outside your monitoring. In a sector that runs on contractors, this is the most reliable route in.

Remote site connectivity

Links to unmanned and remote facilities were engineered for reliability. Many were built before security was a design consideration and have not been revisited since commissioning.

Long lived unsupported systems

Controllers and interfaces running software that stopped being supported years ago cannot be patched without requalifying a process, which makes them durable footholds that everyone knows about and nobody can close.

Process and commercial data theft

Production data, reservoir information and engineering designs carry real commercial value and are usually protected far less carefully than financial systems.

The operating reality

What an energy security programme has to work around

Four conditions that determine whether a control is usable on an operating asset.

Safety governs everything

Any action that could affect a process needs an operational and safety decision, not a security one. Response levels and authority are agreed before they are needed.

Nothing is installed on the control estate

No agents on controllers, no active scanning of fragile devices. Passive collection is the default and the boundary does the protective work.

Assets are remote and contractor operated

Sites without permanent staff and work performed by contractors mean access control and remote visibility carry more weight than on site controls.

Change windows are planned years out

Anything requiring a shutdown enters a turnaround plan. Work that can be done without one is worth disproportionately more, so it is sequenced first.

What we run

The services behind an energy security programme

Designed to add visibility and control without changing anything on an operating process.

Passive OT and SCADA visibility

Discovery and monitoring of the control estate by observing traffic, so you know what is present, what it communicates with, and when that behaviour changes.

Zones and conduits

The process divided by function and criticality with the permitted crossings defined and enforced, following the IEC 62443 model. This is where the measurable risk reduction is.

IT to OT boundary control

The real crossings between corporate and control identified in traffic rather than on the diagram, then tightened and monitored as the paths that matter.

Contractor and vendor access

Third party maintenance access inventoried, scoped to what it genuinely needs, made time bound where the contract permits, and brought into monitoring.

24x7 monitoring and response

Analysts on shift around the clock covering both estates, with separate rules, severities and permitted actions for corporate and for control.

Standards assessment

Zone modelling and gap assessment against IEC 62443 and the national requirements, with remediation sequenced into planned turnarounds.

Standards and regulation

What a UAE energy operator works to

Energy sits under both national critical infrastructure expectations and international control system standards.

IEC 62443

The reference standard for industrial automation and control system security. Zones, conduits and security levels give a defensible design and a measurable target for each part of the process.

UAE Information Assurance Standards

Applies across the corporate estate and, for operators treated as critical infrastructure, more widely. Logging, access control and incident response are examined first.

Critical infrastructure obligations

Operators of nationally significant assets carry additional expectations around resilience, incident notification and the security of connected suppliers. These are agreed at scoping because they affect retention and reporting.

ISO 27001

Frequently used as the management system wrapper, and often the certification partners and joint ventures ask to see before granting integration access.

How we start

How an engagement with an energy operator runs

iConnect OT security for UAE energy infrastructure

We establish which systems are safety instrumented, what may never be probed, who authorises anything that could affect a process, and how the turnaround calendar constrains the work.

  • Safety instrumented systems named and excluded from any active work
  • Passive only collection agreed for the control estate
  • Operational authority named for every response level

Passive discovery across control networks and remote sites, which consistently finds more devices and more crossings than the drawings record.

  • Control estate discovered without probing
  • Real IT to OT crossings found in traffic
  • Contractor and vendor access paths inventoried

The process is divided into zones with defined conduits between them. Work that needs no shutdown is staged immediately; the rest is sequenced into a planned turnaround.

  • Zones and conduits modelled against IEC 62443
  • Vendor access scoped and made time bound
  • Remaining work sequenced into turnaround planning

Monitoring covers corporate and control with separate rules and separate response authority, and reporting is written for the operations leadership as well as the security function.

  • Separate detection and response rules per estate
  • Baselines built from your own process traffic
  • Evidence assembled for national and partner requirements
FAQ

Oil and gas security questions

Because the consequence of getting it wrong is physical. A control system in this sector governs pressure, flow and temperature in processes where an unplanned change can damage equipment or create a safety condition. That makes availability and integrity the priorities, and it rules out a great deal of standard security practice. Nothing may be installed on a controller and nothing may be probed without understanding what the device will do when it is.

Yes. Collection is passive: traffic is watched at network level rather than agents being installed on controllers, historians or human machine interfaces. That produces an accurate picture of what is communicating and when the pattern changes, with no configuration altered and no vendor agreement affected.

It is the reference standard for industrial control system security and its zones and conduits model is the practical basis for design: divide the process into zones by function and criticality, define exactly what may pass between them, and set a security level per zone. Most measurable risk reduction on an energy estate comes from applying that rather than from adding detection.

Remote facilities are usually connected over links that were engineered for reliability rather than security, and are frequently reachable by vendors for maintenance. They are treated as their own zones with tightly defined conduits, and the remote access paths are brought into monitoring and made time bound where the contract allows.

We have to, because the vendor holds the operational knowledge and often the support obligation. The working arrangement is that we do not change anything on the control estate. We observe, we report, and any change is planned with the vendor and the operations team and executed in a proper window.

That depends on the boundary being right beforehand. If the zones and conduits are properly defined, containment is a matter of closing a conduit rather than stopping a process, and that can be immediate. Where segmentation is weak the only options are disruptive, which is why the boundary work comes first.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition

What happens next?

1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation