On 22 April 2023, The CyberDiplomat ran a Cybersecurity & Diplomacy Awareness Program for the Critical Infrastructure Sector – Oil & Gas Industry at Rajasthan Petroleum House, Kishangarh (Ajmer), Rajasthan. Saikat Roy and Harsh Baheti led the session for professionals from the oil and gas sector. It was run as a roundtable, so participants could discuss the risks with the facilitators rather than just listen to a lecture.
The session raised awareness of a sector where a cyber incident does not stop at data. It can halt fuel supply, put lives and the environment at risk, and turn into a matter of national security. Below, we look at why oil and gas is such an attractive target and what organisations in the sector can do about it.
Why oil and gas is a prime target
Oil and gas is critical infrastructure in every sense. Exploration and production, pipelines and storage, refining and retail all depend on each other, and the economy depends on all of them. That makes the sector attractive to three very different kinds of attacker: criminal groups who know that downtime is expensive and a ransom may be paid, hacktivists looking for visibility, and state-linked actors interested in disruption or leverage.
The technology makes the problem harder. Alongside ordinary corporate IT, the industry runs operational technology (OT), such as SCADA systems, distributed control systems, programmable logic controllers and safety instrumented systems, that physically controls pressure, flow and temperature. These systems were often designed decades ago for reliability, not security. They stay in service for many years, are spread across remote sites and are increasingly connected to corporate networks and to vendors who support them remotely.
In oil and gas, a cyber incident is not only an IT problem. It can become a safety, environmental and national-security problem within minutes.
Lessons from real incidents
- Shamoon (2012): destructive malware wiped data on tens of thousands of workstations at Saudi Aramco. It showed how an attack on business systems can cripple one of the world’s largest energy companies.
- Triton / Trisis (2017): attackers went after the safety instrumented system at a petrochemical facility in Saudi Arabia. Those are the controls that exist to prevent explosions and loss of life. It was a clear sign that some adversaries are willing to target physical safety.
- Colonial Pipeline (2021): a ransomware attack on the company’s IT systems led it to shut down one of the largest fuel pipelines in the United States as a precaution. Fuel shortages and panic buying followed along the East Coast, even though the pipeline’s control systems were not directly hit.
The common thread is that the weakest point is rarely the control room itself. It is the email inbox, a vendor’s remote connection, a flat network between IT and OT, or a staff member who has never been taught what an attack looks like.
Where diplomacy comes in
Energy is geopolitical. Supply chains, ownership and markets cross borders, and many of the most capable attackers are linked to states. Attributing an attack, responding to it and preventing the next one therefore involve governments and international cooperation as much as technical teams. States have acknowledged this at the United Nations: the voluntary norms of responsible state behaviour in cyberspace, set out in the UN Group of Governmental Experts’ 2015 report, include not conducting or knowingly supporting cyber activity that intentionally damages critical infrastructure. Understanding this landscape helps energy companies know who to engage, what to report and how their own security fits into national and international efforts.
What the sector should prioritise
- Know your assets: keep an up-to-date inventory of OT and IT systems, including legacy equipment and remote sites.
- Segment IT from OT: make sure an infection on the corporate network cannot move freely into control systems.
- Control remote and vendor access: use multi-factor authentication, time-bound access and monitoring for every third party that connects.
- Plan for the bad day: have incident response plans that cover OT, and manual fall-back procedures that let operations continue safely.
- Follow recognised standards: IEC 62443 for industrial automation and control systems, and ISO/IEC 27001 for the wider information security management system.
- Know your national obligations: in India, CERT-In’s 2022 directions require many types of cyber incident to be reported within six hours, and NCIIPC is the nodal agency for protecting critical information infrastructure.
- Train everyone: field engineers, control-room operators, contractors and senior leadership, not only the IT team.
Awareness is the first line of defence
Technology controls matter, but most incidents in this sector begin with a person: a clicked link, a reused password, an unverified vendor request. Sessions like this one give the people who run critical infrastructure a shared understanding of the threat and of their own role in stopping it. Our thanks to everyone at Rajasthan Petroleum House who took part.
Bring this session to your organisation
We deliver awareness lectures, workshops and certified training for universities, government bodies and industry.
Talk to us IEC 62443 OT security training


