Hydrocarbon Engineering Podcast

The cyber threats facing the oil and gas sector are constantly evolving, and are more urgent now than ever before.
We talk to Auke Huistra, Director for Industrial and OT Security at DNV Cyber, about what companies in the energy sector can do to improve their cyber resilience.
 
Listen to discover:
  • How the threat landscape has evolved, alongside a shift in leadership mindset.
  • The five key challenges of cybersecurity.
  • Why the energy transition is reshaping attitudes to cyber risk.
  • How to close the gap between identifying threats in IT and OT environments.
  • What you should be prioritising on your cybersecurity journey.
  • And much more.
This episode of the Hydrocarbon Engineering Podcast is sponsored by Sherwin-Williams Protective & Marine.
 
Sherwin-Williams Protective & Marine delivers world-class industry subject matter expertise, unparalleled technical and specification service, and unmatched regional commercial team support to customers around the globe, including in the energy market. The company’s broad portfolio of high-performance coatings and systems – including protective liquid and powder coatings, as well as fire protection coatings – excel at combating corrosion and help customers achieve smarter, time-tested asset protection. For more information, visit protective.sherwin.com.

Creators and Guests

Host
Callum O'Reilly
Callum leads the editorial teams at Hydrocarbon Engineering, commissioning articles and features, and representing the magazine at industry events.
Guest
Auke Huistra
Director for Industrial and OT Security

What is Hydrocarbon Engineering Podcast?

The Hydrocarbon Engineering podcast: a podcast series for professionals in the downstream refining, petrochemical and gas processing industries.

Callum O'Reilly:

Hello and welcome to another episode of the Hydrocarbon Engineering Podcast. This week we're going to be focusing on the growing cyber threat in the oil and gas sector. We'll talk to Auke Huistra, Director for Industrial and OT Security at DNV Cyber about how cyber threats are evolving, what we can do and the challenges that oil and gas companies face on their journeys to cyber resilience. It's a fascinating topic, and I hope that you will find the discussion useful. So let's talk to Auke.

Advert:

This episode of the Hydrocarbon Engineering Podcast is sponsored by Sherwin Williams Protective and Marine. Sherwin Williams Protective and Marine delivers world class industry subject matter expertise, unparalleled technical and specification service, and unmatched regional commercial team support to customers around the globe, including in the energy market. The company's broad portfolio of high performance coatings and systems, including protected liquid and powder coatings as well as fire protection coatings, excel at combating corrosion and help customers achieve smarter, time tested asset protection. For more information, visit protective.sherwin.com.

Callum O'Reilly:

Welcome, Auke, and thanks for joining us on the Hydrocarbon Engineering Podcast. We've got lots to get through today, but before we dive in, please can you introduce DNV Cyber to our listeners and tell us a little about your current role at the organization?

Auke Huistra:

Yeah, sure. Thank you for having me on this podcast. DNV Cyber is the cybersecurity arm of DNV. We focus on safeguarding the world's most critical infrastructures, but especially focus on energy, maritime and manufacturing. And with energy, you need to think about oil and gas, renewables, power in all different aspects.

Auke Huistra:

In my role as Director of Industry and OT Cybersecurity, I have a team of around 100 OT cybersecurity consultants that work around the world together with operators, asset owners, EPC contractors, vendors, suppliers, to secure operational technology. So the systems that control all these physical processes like drilling, refining, terminals, shipping, power generation, transmission, that's where our daily life is. We assess and test companies, but also capital projects, but also systems, products on the state of cybersecurity, and develop and implement good practices at our clients. And we do that onshore and offshore. So our work goes from highly strategic roadmaps to risk assessments to do very technical testing on systems and test type of work, etcetera.

Auke Huistra:

At the end, we are there to keep operations of our clients safe, resilient, and trustworthy, which is needed in our increasing digital world. So we also have the slogan, We save God the critical. And that's also where I see us on a daily basis.

Callum O'Reilly:

So your most recent energy cyber priority report begins by framing cyber threats as an arms race for the energy sector. Can you unpack what that means,

Auke Huistra:

and why it is more urgent now than ever? When we say it's an arms race, we actually mean that attackers are constantly getting more sophisticated. It's also what we see in the press, are more sophisticated attacks coming up. And at the same time, defenders, where we help out, have to adapt just as quickly. So just by doing what we did today, it's not safeguarding us from the attacks that will come tomorrow.

Auke Huistra:

And I think that's where we came up with the term arms race. Energy's infrastructures are now deeply digitalized, which of course is great from an efficiency perspective, but it also expands the attack surface for cyber attackers quite a bit. We see at the same time that geopolitical tensions are rising and that cyber operations are part of that whole attack pattern that we see. And of course, you see it on a daily basis in Ukraine, but we see it also in different areas as well. So that combination of more connectivity, more incentives, also financial incentives, but also politically motivated incentives, and more capable attackers means that the energy sector has to move faster than ever to stay ahead.

Callum O'Reilly:

So you mentioned geopolitical tensions, Auke, and there's also factors such as nation state actors increasing their activity. So how has the threat landscape evolved for oil and gas companies over the past few years?

Auke Huistra:

If I look at our own report, the amount of people that are concerned about threat actors, and then especially criminal gangs and state actors are mentioned there, that have increased over the last three years, going over 70% of the people being concerned about, for example, state actors in our last report. And I think that's quite crucial. And that's also what, of course, we see if you look at all the incidents that hit the newspapers these days. We see increasingly amounts of incidents popping up. I think the latest one was the attack on the energy sector in Poland.

Auke Huistra:

That was quite recently where it was clear that state sponsored attackers, probably from Russia, attacked the power sector. In this case, it was solar and wind energy systems, to really cause problems. Luckily, was detected in an early stage so that no really physical damage was done. But it's the type of attacks that we see coming up more and more. Not all the incidents hit the news.

Auke Huistra:

Like, for example, Zscaler, one of the bigger companies looking into, for example, ransomware attacks, they show that I think in the period between April 2425, there was a 935% increase in oil and gas ransomware, which is huge. And that's also what we see ourselves in the work that we do for our clients, is that there is more and more malware coming up, sometimes with the idea of industrial espionage, sometimes really with the idea to mess up the operations of the customers. Luckily, there's also still more and more capabilities to detail and to do something before they really have an impact on the operations. But it's something that comes up also in the North Sea, for example, where there is Volkswagen Norwegian gas inputs to Europe. They play a key part in the continent's energy security and their potential attack, a target for cyber attacks as part of Russia's weaponizing of energy.

Auke Huistra:

And these operations and particularly the remote operations, they rely on tightly integrated OT, subsea systems, and satellite communications. And we see that there is more and more interest from state actors on these kinds of operations. And that's, of course, worrying. And that's also why we need to be vigilant and also work together to be able to stop these attacks before they really have an impact.

Callum O'Reilly:

Now, as you mentioned, Auke, your research shows a significant rise in executives viewing cybersecurity as a top business risk, which I suppose is welcome in in some ways, but also concerning in others. But I was wondering what shifts in leadership mindset you have seen across operators and asset owners.

Auke Huistra:

Yeah, you're right. Our last cyberprotocol research showed that within these energy companies, cybersecurity threats are taken seriously at the highest levels, As two in three energy professionals, or 65% actually, said that their leadership views cybersecurity as their greatest current risk to their business, which is quite something, because there are many other risks as well, like physical security risks, safety risks, financial risks, etc. But they see cybersecurity now as their top priority. And I think the biggest shift is that cybersecurity is not longer seen just as an IT issue, because it was always the case. If there was something with cyber, the finger was pointed at the IT guys to ensure that they would fix the problem.

Auke Huistra:

I think the understanding now more and more comes along that cyber can also hit the operations itself, the physical processes of a refinery or often a wellhead platform or whatever in that whole oil and gas value chain. It's now more a business continuity issue where leaders understand that the cyber incident can shut down production, can impact safety, can have a damaging effect on the reputation, and can disrupt the whole energy supply chain. So we're also seeing executives becoming more comfortable talking about cyber risks in operational terms, like for example, downtime, financial exposure, resilience, rather than only the technical jargon that was mentioned in the past. It is becoming a board level topic, and that's a very positive change. It's also needed, by the way, since new legislation that is coming up also puts the accountability for cybersecurity really onto board members on an individual level.

Auke Huistra:

Like, for example, the NIS2 EU directive clearly states that board members have accountability for cybersecurity, and they could potentially go to jail if they don't take good care of it.

Callum O'Reilly:

Auke, I just wanted to return to something you mentioned about IT versus OT just a moment ago. And I was wondering, are organisations generally better at identifying threats in IT environments than they are at operational technology. And what makes OT cybersecurity fundamentally different?

Auke Huistra:

That's something that I always wondered why companies invest much more in IT security than in securing their OT environments. But it's clearly what we see in daily practice. But it also what comes back from the energy priority report, where more than half of energy professionals believe that their OT defenses lack their IT defenses, and that more than two thirds of them acknowledge that their organizations are more vulnerable to OT cyber events than ever before. So that says something. In IT operations, it's quite normal to have detection and monitoring tools looking after these environments.

Auke Huistra:

But in OT environments, it's still an upcoming thing. There are more and more tools that can do it and a lot of vendors supplying these kinds of monitoring sensors and tooling to do it, but it's still not implemented everywhere and it's still lagging behind. Of course, companies learn, and that's also what I see in the oil and gas industry, especially the big companies. They have been implementing this kind of tooling more and more in the OT space as well, having specifically tailored solutions for that. Because what you don't want is that these kind of monitoring tools disrupt the operational processes, which is, I think, something that also makes it different from an IT to an OT perspective.

Auke Huistra:

Because what works in the IT space not always works in the OT space. In the past, there have been multiple incidents where IT tools were implemented in the OT space, but then started to disrupt the networks in the OT environments, leading to sometimes hiccups, sometimes even downtime. So that's also where you see that the market has created more and more tools that are geared and specifically created to operate in these sensitive OT environments.

Callum O'Reilly:

And you dedicate a section of your report to talking about the energy transition and how it is reshaping attitudes towards cyber risk. So can you explain why energy companies cannot succeed in the energy transition without cybersecurity?

Auke Huistra:

Yeah, I think the energy transition on itself is a massive challenge, which is increasingly complex because the technology that are underpinning these transitions are largely digital and scaling rapidly. And that's also where we think and we strongly believe that if you don't have your cybersecurity in place, it's also almost impossible to reap the benefits and to succeed in the energy transition because the energy transition has digitalized the environment a lot and also created a bigger attack service, as I mentioned before. And you can only do that in a good, stable way if cybersecurity is in place. And it's also where often these discussions is cybersecurity is an add on, it is an extra cost, where we always say, well, it's an investment in making it possible to digitalize, and in that sense also to support that whole energy transition, because that transition is huge and can only be done if digitalisation is in place.

Callum O'Reilly:

So let's move on to the challenges of cyber security, of which there are many and they are always evolving. So your report outlines five in particular. Can you guide us through them, Auke?

Auke Huistra:

One of the challenges is that we see that it's clearly needed to broaden the efforts to secure OT. Mentioned before, the energy system has been tackling IT security already for decades, but securing the OT space has started more recently and is an increasingly urgent challenge. Of course, the bigger companies already started a bit longer ago, but when we operate and we test companies also in the oil and gas space, we still see that the OT environments are not having OT on a mature level. It's often easy to find weaknesses. If we do, for example, pen testing, it normally does not take a lot of time to get into environments and to take full control of the OT network, for example.

Auke Huistra:

What is happening and where it becomes more vulnerable is where OT, of course, has become more networked and connected to IT environments, which is already happening over the last fifteen, twenty years, but is increasingly growing. The connectivity is increasingly growing with the need to push up data into the IT network or even into the cloud. So that also comes with new challenges. So broadening that effort to secure OT, I think, is a crucial one. The other one, which is maybe the biggest worry, is that we need to be able to secure complex supply chains.

Auke Huistra:

Because if you look at, for example, a refinery or a platform in the ocean or pipelines, Often the operations is partly be done by third parties, sometimes fully as, contractors working on it. All the systems, etcetera, are being delivered by suppliers as well that need to have remote access to do remote work on the systems. So there's a lot of different elements in these supply chains. And what our research has shown was that only half of the energy professionals are confident that their organization has full visibility on the cybersecurity vulnerabilities in their supply chain, which is quite worrying, but also I think something that I can relate to based on the work that we do ourselves with the customers, often they have quite a good view on what they do themselves, but what the risk is of all these parties working in their environment is often not seen. So these supply chains are really a major worry for energy companies, also because tracked actors go to the suppliers and sub suppliers more and more to gain access to companies operating large assets.

Auke Huistra:

So in my own experience, for example, I worked at a pipeline company where they used SolarWinds as a network management tool. SolarWinds got compromised. And by that compromise, the attackers were also able to get a foothold into the environments of these companies. And that's something that is continuously ongoing and something that you need to take care of. The third one was the AI head, the artificial intelligence cyber arms race, where AI is used by the attackers to quickly create all kinds of new attack paths to develop malware, to create phishing schemes, etcetera.

Auke Huistra:

And on the other hand, more and more AI is being used to for the defense. So for detecting and monitoring of these environments, there also a race between the attackers and the defenders as well. The fourth one was about the tightening regulation. I think all over the world governments are now tightening regulations. And that is also giving a push, by the way, to the companies to start working on cybersecurity.

Auke Huistra:

Because also the research showed that the biggest motivator to start implementing cybersecurity is actually regulations. So compliance to regulations is often the reason why companies start investing in cybersecurity. We always say it's nicer, it's also good that it's there, that it pushes for starting to work on it, but only compliance to regulations will not make you secure. So you need to do more and more than that. And the last one, the last challenge that we saw was the skills gap and enhancement of what we call the employee vigilance, because often the people, the co workers, are the ones that see that something is wrong.

Auke Huistra:

So a lot of attacks are being seen in that sense as well. But to address all the cybersecurity challenges, you need to have a trained workforce, and not only your own workforce, but also the workforce of your suppliers. They need to be aware, they need to know what they need to do. And then I don't only talk about the cybersecurity professionals themselves, but especially the engineers and operators that run these plants and operations. They need to know who to contact, what to look for, etc.

Auke Huistra:

To be able to detect potential incidents quickly, but also to respond in a proper way.

Callum O'Reilly:

And as you know, Auke, oil and gas companies have many strategic and often competing priorities. So how can they best manage to prioritise cybersecurity alongside all of these other priorities that they have?

Auke Huistra:

Yeah, what we always advise is to make cybersecurity part of the overall risk management processes. So if you do risk management on a plant, for example, you look at it from all different kinds of perspectives, and then you try to weigh risks and also come up with an approach that is often called a LARP, as low as a reasonable practicable, where you will not mitigate every risk, but you will mitigate the biggest risks of the risks that have the biggest impact, but also in a way that still makes it possible to make a profit. Because of course, I think bringing risks back to zero is not something that is realistic and possible. And so bringing in cybersecurity into these overall risk management strategies, I think, is the best way forward. And we help many companies to do it that way.

Auke Huistra:

And it also shows the engineering community that the risk is actually there, that it can also have a big impact on their operations, And often is also an eye opener for them to start working on cybersecurity and not seeing it anymore as a problem from the IT department. But there's something that they need to act upon themselves. And that's where I've seen that engineers became really pointing at IT departments towards ambassadors for cybersecurity and started to implement all kinds of controls themselves to ensure that the operation at which often their baby is not harmed by cybersecurity attacks. If I then look at what is needed for that is one clear governance to ensure that cyber is part of business decision making, that there's also clear visibility on the OT domain because that's something that we see as often lacking. So just knowing what assets you'll have and also what normal behavior of these assets entail, I think that's crucial.

Auke Huistra:

If we come into companies and we ask, please give us an asset inventory of an up to date network drawing of the plant, we often get something that is certainly not up to date, if there is something at all. So then people need to find pieces and we need to glue it together. But having that OT visibility is crucial. The third one is incident readiness, because you can do all kinds of protective measures, but still incidents can happen intentionally or unintentionally. Incidents probably will happen and you need to be ready for it.

Auke Huistra:

Like you practice for all kinds of safety related incidents. You also need to practice the cyber related ones as well, so that everybody knows what to do in case an incident is happening. And we also have seen, at least I've also seen customers that I've worked with myself, that the ones that had an incident and had trained for it were much better geared up to face the incident and to get back to normal and quickly than the ones that hadn't. The other one is that vendor and supply chain security part, which I mentioned already before, and also the investment in people to make sure that cybersecurity, like safety, is embedded in every function in the company and not only left up to the cyber security professionals.

Callum O'Reilly:

And how can companies achieve the next stage of cybersecurity maturity? What should our listeners be prioritising on their cybersecurity journeys?

Auke Huistra:

Yeah, that's a bit in line with what I mentioned in the previous question. So you need to look at it from a holistic perspective. You need to embed it into your daily operations. We recently did a big programme for an oil and gas terminal company where we first did an assessment and then found that policies and procedures were missing, people were not trained, but it was also not a clear overview of all the activities that would be needed. So what we did there, we worked with the company itself, but also with the supplier that run most of the operation, and embedded all the cybersecurity activities into their terminal management system, clearly stating which activities need to be done on a daily basis, on a weekly basis, on a monthly basis, or maybe even on a yearly basis.

Auke Huistra:

Having that clear guidance on which activities need to be done, I think is crucial. But again, it all starts also there with that clear governance visibility of the OT domain as two of the main drivers, but then also having that defensible architecture, as we often call it. So we make sure that you have proper segmentation in the networks, for example, that if an incident happen happens, it can't spread easily across the whole operations, but will remain in the boundaries of that network segment. For example, as one of the important items, detection and monitoring to ensure that you will see an incident if it happens, and also you will then be able to quickly respond, I think are the most important ones. And the last one would be embedding it in business continuity plans to ensure that if things happen, how to respond, what action can be taken and also what alternative measures can be taken to bring at the end what's most important and that operational process back to life again as quickly as possible.

Auke Huistra:

Maturity comes from consistency. So it's not so much the size of the budget, it's really about the discipline of the approach. It's not a quick fix that you can do. There's not that golden bullet. It really starts with basic hygiene first, and then implementing all of the rest.

Callum O'Reilly:

And looking ahead, what role do you see emerging regulations and frameworks playing in shaping cybersecurity readiness in oil and gas?

Auke Huistra:

I think certain regulation is the biggest driver for action. And that's at least what we also see and also hear back in our cyber priority report. And I also see it with the clients I work with myself as well directly. Often being regulated comes also with attention from the top level because management is used to that from all kinds of other regulations as well. So regulation like NIS2 in Europe and TSA regulations in The US and all kinds of sector specific standards across the world are pushing companies towards a high level of transparency and resilience.

Auke Huistra:

And these rules at the end raise the bar for everyone. That's a good thing. In the current regulation, for example, there's a big focus on the supply chain. There's also regulation coming up specifically for product vendors with more smart elements in it, like for example, in the Cyber Resilience Act in Europe. And all these elements together really push the bar for everyone.

Auke Huistra:

And that's, I think, a good thing to have. But as said, it's not enough. You will need to do more. You will need to understand where the risks are and you will constantly need to monitor the networks for what is happening.

Callum O'Reilly:

Great, Auke, thank you so much for joining us and for providing your expertise on this increasingly important overlooked area and of the energy sector, we really appreciate you sharing your thoughts with us so thank you.

Auke Huistra:

Thank you very much for having me.

Callum O'Reilly:

That brings us to the end of this episode, a huge thank you to Auke from DNV for walking us through the findings of the energy cyber priority report and for helping us understand what they mean in practical terms for the oil and gas sector. If there's one clear takeaway it's that cyber security is no longer a purely technical issue sitting in the IT department. It's a board level priority, a core enabler of operational resilience and a critical foundation for the energy transition. As digitalization accelerates and threat actors grow more sophisticated, it's clear that standing still simply isn't an option. Thanks for listening to the podcast, and if you enjoyed this episode, don't forget to subscribe.

Advert:

This episode of the Hydrocarbon Engineering Podcast is sponsored by Sherwin Williams Protective and Marine. Sherwin Williams Protective and Marine delivers world class industry subject matter expertise, unparalleled technical and specification service, and unmatched regional commercial team support to customers around the globe, including in the energy market. The company's broad portfolio of high performance coatings and systems, including protected liquid and powder coatings as well as fire protection coatings, excel at combating corrosion and help customers achieve smarter, time tested asset protection. For more information, visit protective.sherwin.com.