Skip to main content

OT security for oil & gas refineries: a threat model

A refinery is a continuous chemical process wrapped in decades of control technology. A structured look at who threatens it, through which paths, and what defence in depth means on site.

13 May 2026

OT security for oil & gas refineries: a threat model

The asset, seen as an attacker sees it

A refinery is a continuous, high-energy chemical process governed by layers of control: field instruments, distributed control systems, and, standing above them all, the safety instrumented systems that shut the process down before physics does. The adversary's map is the network that connects these layers to each other, to the corporate business systems, and to the vendors who maintain them.

Threat actors and their aims

Three actor classes matter. Criminal groups seek extortion leverage, encrypting business systems and betting the operator will pay to protect throughput. State-linked actors seek pre-positioning and, at the extreme, sabotage; intrusions targeting refinery safety systems specifically have been publicly documented, which marks the outer edge of intent. Insiders and careless contractors, finally, provide the access others exploit.

The paths in

The recurring intrusion paths are unglamorous: the IT/OT boundary crossed via shared services and flat networks; vendor remote access with standing credentials; engineering workstations that touch both worlds; removable media in commissioning and turnaround work; and the temporary connections of a thousand contractors during a shutdown. Turnarounds, when the site is crowded and change is constant, are the high-risk season.

Defence in depth, refinery edition

The defence maps to the paths: hard segmentation between business and control networks with brokered conduits, independent protection and rigorous change control around safety systems, time-limited and monitored vendor access, locked-down engineering workstations, media discipline, and passive monitoring across the control network. Above all: rehearsed procedures to run or safely shut the process when the screens cannot be trusted.

The bottom line for refinery operators

For operators of continuous, high-energy processes, the practical advantage is to defend the paths an attacker actually uses rather than an abstract perimeter. That means hard segmentation between business and control networks, independent protection and strict change control around the safety instrumented systems that stand as the last barrier before physical catastrophe, time-limited and monitored vendor access, locked-down engineering workstations, and disciplined control of removable media, especially through turnarounds, when the site is crowded and change is constant. The decisive capability, though, is human and rehearsed: procedures to run or safely shut the process when the screens can no longer be trusted. Operators who invest there protect people, plant and throughput together, and deny an adversary the leverage that comes from a process they can quietly manipulate.

Common questions

What are the main cyber threats to refineries?

Criminal ransomware seeking extortion leverage over throughput, state-linked intrusion seeking pre-positioning or sabotage (including documented targeting of safety systems), and insider or contractor negligence.

What is the most common intrusion path into refinery OT?

The IT/OT boundary and remote access: flat networks, shared services, standing vendor credentials and dual-homed engineering workstations, with removable media prominent during turnarounds.

Why do safety instrumented systems deserve special protection?

They are the last automated barrier before physical catastrophe. They warrant independent segmentation, strict change control and monitoring separate from the basic process control system.

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.