13 May 2026

The asset, seen as an attacker sees it
A refinery is a continuous, high-energy chemical process governed by layers of control: field instruments, distributed control systems, and, standing above them all, the safety instrumented systems that shut the process down before physics does. The adversary's map is the network that connects these layers to each other, to the corporate business systems, and to the vendors who maintain them.
Threat actors and their aims
Three actor classes matter. Criminal groups seek extortion leverage, encrypting business systems and betting the operator will pay to protect throughput. State-linked actors seek pre-positioning and, at the extreme, sabotage; intrusions targeting refinery safety systems specifically have been publicly documented, which marks the outer edge of intent. Insiders and careless contractors, finally, provide the access others exploit.
The paths in
The recurring intrusion paths are unglamorous: the IT/OT boundary crossed via shared services and flat networks; vendor remote access with standing credentials; engineering workstations that touch both worlds; removable media in commissioning and turnaround work; and the temporary connections of a thousand contractors during a shutdown. Turnarounds, when the site is crowded and change is constant, are the high-risk season.
Defence in depth, refinery edition
The defence maps to the paths: hard segmentation between business and control networks with brokered conduits, independent protection and rigorous change control around safety systems, time-limited and monitored vendor access, locked-down engineering workstations, media discipline, and passive monitoring across the control network. Above all: rehearsed procedures to run or safely shut the process when the screens cannot be trusted.
The bottom line for refinery operators
For operators of continuous, high-energy processes, the practical advantage is to defend the paths an attacker actually uses rather than an abstract perimeter. That means hard segmentation between business and control networks, independent protection and strict change control around the safety instrumented systems that stand as the last barrier before physical catastrophe, time-limited and monitored vendor access, locked-down engineering workstations, and disciplined control of removable media, especially through turnarounds, when the site is crowded and change is constant. The decisive capability, though, is human and rehearsed: procedures to run or safely shut the process when the screens can no longer be trusted. Operators who invest there protect people, plant and throughput together, and deny an adversary the leverage that comes from a process they can quietly manipulate.

