What problem does it solve?
Oil and gas facilities run SCADA, DCS, and safety instrumented systems that are difficult to assess safely, and assessors often miss remote sites, unauthenticated protocols, and regulatory gaps. This Skill provides a structured methodology for evaluating upstream, midstream, and downstream OT environments without endangering live operations.
Core Features & Use Cases
- Segment-aware scoping: Tailors the assessment to upstream wellheads, midstream pipelines, or downstream refineries, covering DCS, SIS, RTUs, and flow computers.
- Pipeline SCADA evaluation: Checks IT/OT segmentation, DNP3 encryption on radio and satellite links, custody-transfer flow computer authentication, and remote site physical intrusion detection.
- Regulatory compliance mapping: Maps findings to TSA Security Directives SD-01/SD-02, API 1164, IEC 62443, and NIST CSF with severity-rated findings and remediation timelines.
- Use Case: A pipeline operator preparing for a TSA SD-02 audit uses this Skill to identify a flat IT/OT network, unencrypted DNP3 links to pump stations, and missing CIP documentation, then produces a compliance gap report.
Quick Start
Perform an oil and gas cybersecurity assessment of our refinery and pipeline SCADA systems against API 1164 and TSA SD-02 and generate a findings report.