Cyber security for oil and gas in the UAE
Upstream, midstream and downstream all run control systems where an unplanned stop has a cost measured in hours of production and, sometimes, in safety. We bring those environments into visibility passively and keep the corporate side from reaching them.

When the process is physical, a security action has physical consequences
In most estates the worst outcome of a wrong security decision is an outage. In energy it can be equipment damage or a safety event, because the systems being protected govern pressure, flow and temperature rather than records. That single fact rules out much of what is routine elsewhere.
The equipment is also long lived and deliberately conservative. Controllers specified twenty years ago are still in service because the process was qualified around them, and replacing one is an engineering project rather than an upgrade. They cannot take an agent, frequently cannot be patched, and in some cases will not tolerate being scanned.
Meanwhile the sites are spread out and the connections have multiplied. Remote facilities, historians feeding corporate reporting, contractors with maintenance access and engineering laptops that move between networks all create paths that were added one at a time for good operational reasons. Collectively they are the route by which corporate problems become production problems.
What works is structural and unglamorous: know precisely what is on the control network, define the zones and the conduits between them, control vendor access, and watch passively. Detection matters, but it is worth far less than a boundary that holds.
What actually reaches an energy control environment
Direct attacks on control systems make the news. The incidents that occur are usually more ordinary and arrive from the corporate side.
What an energy security programme has to work around
Four conditions that determine whether a control is usable on an operating asset.
The services behind an energy security programme
Designed to add visibility and control without changing anything on an operating process.
What a UAE energy operator works to
Energy sits under both national critical infrastructure expectations and international control system standards.
IEC 62443
The reference standard for industrial automation and control system security. Zones, conduits and security levels give a defensible design and a measurable target for each part of the process.
UAE Information Assurance Standards
Applies across the corporate estate and, for operators treated as critical infrastructure, more widely. Logging, access control and incident response are examined first.
Critical infrastructure obligations
Operators of nationally significant assets carry additional expectations around resilience, incident notification and the security of connected suppliers. These are agreed at scoping because they affect retention and reporting.
ISO 27001
Frequently used as the management system wrapper, and often the certification partners and joint ventures ask to see before granting integration access.
How an engagement with an energy operator runs
We establish which systems are safety instrumented, what may never be probed, who authorises anything that could affect a process, and how the turnaround calendar constrains the work.
- Safety instrumented systems named and excluded from any active work
- Passive only collection agreed for the control estate
- Operational authority named for every response level
Passive discovery across control networks and remote sites, which consistently finds more devices and more crossings than the drawings record.
- Control estate discovered without probing
- Real IT to OT crossings found in traffic
- Contractor and vendor access paths inventoried
The process is divided into zones with defined conduits between them. Work that needs no shutdown is staged immediately; the rest is sequenced into a planned turnaround.
- Zones and conduits modelled against IEC 62443
- Vendor access scoped and made time bound
- Remaining work sequenced into turnaround planning
Monitoring covers corporate and control with separate rules and separate response authority, and reporting is written for the operations leadership as well as the security function.
- Separate detection and response rules per estate
- Baselines built from your own process traffic
- Evidence assembled for national and partner requirements
Oil and gas security questions
Because the consequence of getting it wrong is physical. A control system in this sector governs pressure, flow and temperature in processes where an unplanned change can damage equipment or create a safety condition. That makes availability and integrity the priorities, and it rules out a great deal of standard security practice. Nothing may be installed on a controller and nothing may be probed without understanding what the device will do when it is.
Yes. Collection is passive: traffic is watched at network level rather than agents being installed on controllers, historians or human machine interfaces. That produces an accurate picture of what is communicating and when the pattern changes, with no configuration altered and no vendor agreement affected.
It is the reference standard for industrial control system security and its zones and conduits model is the practical basis for design: divide the process into zones by function and criticality, define exactly what may pass between them, and set a security level per zone. Most measurable risk reduction on an energy estate comes from applying that rather than from adding detection.
Remote facilities are usually connected over links that were engineered for reliability rather than security, and are frequently reachable by vendors for maintenance. They are treated as their own zones with tightly defined conduits, and the remote access paths are brought into monitoring and made time bound where the contract allows.
We have to, because the vendor holds the operational knowledge and often the support obligation. The working arrangement is that we do not change anything on the control estate. We observe, we report, and any change is planned with the vendor and the operations team and executed in a proper window.
That depends on the boundary being right beforehand. If the zones and conduits are properly defined, containment is a matter of closing a conduit rather than stopping a process, and that can be immediate. Where segmentation is weak the only options are disruptive, which is why the boundary work comes first.