performing-oil-gas-cybersecurity-assessment

Assess oil and gas OT cybersecurity against API 1164, TSA directives, and IEC 62443.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill performing-oil-gas-cybersecurity-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-oil-gas-cybersecurity-assessment
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/ot-ics-security/performing-oil-gas-cybersecurity-assessment
Command: npx skills add https://github.com/xalgord/xalgorix --skill performing-oil-gas-cybersecurity-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Oil and gas facilities run SCADA, DCS, and safety instrumented systems that are difficult to assess safely, and assessors often miss remote sites, unauthenticated protocols, and regulatory gaps. This Skill provides a structured methodology for evaluating upstream, midstream, and downstream OT environments without endangering live operations.

Core Features & Use Cases

  • Segment-aware scoping: Tailors the assessment to upstream wellheads, midstream pipelines, or downstream refineries, covering DCS, SIS, RTUs, and flow computers.
  • Pipeline SCADA evaluation: Checks IT/OT segmentation, DNP3 encryption on radio and satellite links, custody-transfer flow computer authentication, and remote site physical intrusion detection.
  • Regulatory compliance mapping: Maps findings to TSA Security Directives SD-01/SD-02, API 1164, IEC 62443, and NIST CSF with severity-rated findings and remediation timelines.
  • Use Case: A pipeline operator preparing for a TSA SD-02 audit uses this Skill to identify a flat IT/OT network, unencrypted DNP3 links to pump stations, and missing CIP documentation, then produces a compliance gap report.

Quick Start

Perform an oil and gas cybersecurity assessment of our refinery and pipeline SCADA systems against API 1164 and TSA SD-02 and generate a findings report.

Frequently Asked Questions about performing-oil-gas-cybersecurity-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess pipeline SCADA security against TSA directives?

Evaluate IT/OT network segmentation, RTU communication encryption, access controls, continuous monitoring, and patch management against TSA SD-02 requirements. The assessment produces compliance checks with status ratings and gap descriptions mapped to each directive section.

How to safely test oil and gas OT systems without disrupting operations?

Use passive traffic capture on WAN and serial gateways to confirm unauthenticated DNP3 or cleartext IEC 60870-5-104 rather than active probing. Safety instrumented systems like Triconex should only be observed passively, and any active scans should run inside maintenance windows with operations present.

What standards apply to oil and gas cybersecurity assessments?

The assessment covers API 1164 for pipeline SCADA security, TSA Security Directives SD-01 and SD-02, IEC 62443 for industrial control systems, and the NIST Cybersecurity Framework for critical infrastructure.

Can this assessment be used for corporate IT networks of oil companies?

No, it is scoped to operational technology environments such as SCADA, DCS, and safety systems. It explicitly excludes IT-only corporate network assessments, physical-only security reviews, and environmental compliance assessments.

Why are custody transfer flow computers a security concern?

Flow computers often accept unauthenticated Modbus writes that can alter meter factors and flow calculations, enabling financial fraud at custody transfer points. The assessment confirms read-only behavior by passively observing whether any host issues function codes 06 or 16 to the flow computer.