The oil and gas industry is spending billions on cybersecurity — and much of it is pointed in the wrong direction. Network monitoring tools, vulnerability scanners, and vendor questionnaires are the pillars of most operators’ OT security programs. They’re necessary. They’re also insufficient. Because none of them answer the one question that matters most—what is actually running inside the firmware of the controllers, RTUs, and SCADA systems keeping your pipelines flowing and your refineries processing? That question, paired with the industry’s collective failure to answer it, is the most dangerous blind spot in critical infrastructure security today. The Numbers Are Moving the Wrong Way The threat landscape isn’t abstract. In 2024, Halliburton suffered a ransomware attack that cost $35 million. CISA reported a 145% surge in OT-targeted cyberattacks that same year. Dragos documented an 87% increase in ransomware groups targeting industrial organizations. The average cost of a single OT security incident in oil and gas has reached $4.4 million. These aren’t outliers. They’re a pattern. And the pattern that stems from decades where operational technology lived in isolation, running proprietary protocols on air-gapped networks. IT/OT convergence changed that. Remote monitoring, predictive maintenance, and real-time optimization connected those systems to networks that threat actors have been probing for years. Over this time, however, the underlying equipment stayed the same. I’m referring to fifteen-year-old controllers, firmware that was never designed to face the internet and protocols that predate modern encryption. The attack surface expanded. The software inside the devices didn’t change. And almost nobody has looked inside it. What’s Actually in the Firmware Here’s a real-world example that illustrates the gap. A deep binary analysis was recently performed on firmware from a major RTU vendor widely deployed across upstream oil and gas operations. This is a reputable vendor whose product has passed
The OT Software Supply Chain Blind Spot Oil & Gas Can't Afford to Ignore
Read the original article
cybersecurity-insiders.com →