Industry · Energy · GCC

Penetration testing for oil, gas & energy — where cyber risk is physical risk

In the energy sector, a compromised controller can stop a refinery or defeat a safety system. We deliver safety-first OT and IT penetration testing for GCC operators — aligned to NCA OTCC, IEC 62443 and the Aramco and SABIC supply-chain standards — that proves risk without ever threatening the physical process.

Oil & GasPetrochemicalsOT SecurityNCA OTCCIEC 62443SACS-002
Energy Security: Safety First · Passive-First OT · Purdue Model · NCA OTCC 2-10 · IEC 62443 · Aramco SACS-002 · SABIC CyberTrust Energy Security: Safety First · Passive-First OT · Purdue Model · NCA OTCC 2-10 · IEC 62443 · Aramco SACS-002 · SABIC CyberTrust
// TL;DR

Oil, gas and petrochemical operators face a threat class most industries do not: attacks that cross from IT into operational technology and interfere with the physical process, up to and including safety systems. The 2017 Triton malware, which targeted a Saudi petrochemical plant's safety instrumented system, is the defining example. Testing this sector requires a safety-first, OT-aware approach — passive on production-critical layers, active only on replicas or in maintenance windows, structured around the Purdue Model. GCC energy operators are typically critical national infrastructure, subject to the NCA ECC and the NCA OTCC (penetration testing control 2-10), with vendor supply-chain standards like Aramco SACS-002 and SABIC CyberTrust layered on top. We test both IT and OT, mapped to those controls and IEC 62443, and never threaten the process.

// 01 Why oil & gas needs specialist penetration testing

Energy is the sector where cybersecurity and physical safety converge most sharply. A refinery, a pipeline or a petrochemical plant runs on operational technology — programmable logic controllers, SCADA systems, human-machine interfaces and, critically, safety instrumented systems designed to prevent explosions and releases. An attacker who reaches those systems can do far more than steal data: they can halt production, damage equipment, or interfere with the safety layer that protects people and the environment.

This is not hypothetical for the region. In 2017, the Triton (also called Trisis) malware specifically targeted the safety instrumented system of a Saudi petrochemical plant — the first malware written to attack the last line of physical-safety defence. It is the clearest possible illustration of why energy operators cannot rely on standard IT penetration testing, which is not designed to account for the fragility of legacy controllers or the catastrophic cost of disruption. Testing here has to be built around the physical process from the first day of scoping.

// 02 The regulatory and supply-chain drivers

GCC energy operators sit under a stack of overlapping obligations, most of them driven by their status as critical national infrastructure.

NCA OTCC

OT Cybersecurity Controls

Saudi Arabia's Operational Technology Cybersecurity Controls (OTCC-1:2022) govern OT/ICS environments; control 2-10 covers penetration testing. Mandatory for CNI operators.

NCA ECC

Essential Controls

The Essential Cybersecurity Controls apply to the operator's IT estate as the national baseline.

SACS-002

Aramco supply chain

Vendors and contractors accessing Saudi Aramco environments must satisfy the SACS-002 cybersecurity standard.

CyberTrust

SABIC supply chain

SABIC's CyberTrust programme imposes cybersecurity requirements on its supply chain and partners.

Internationally, IEC 62443 is the primary OT security standard — its zones-and-conduits model and security levels (SL1–SL4) are the reference for how a plant should be segmented and defended, and NIST SP 800-82 provides the technical testing guidance. We map findings to whichever combination of these applies to your operation, so a single engagement produces evidence for the regulator and for your vendor obligations.

// 03 What we test in an energy environment

An energy engagement spans both worlds — the IT an attacker uses to get in, and the OT they are trying to reach — structured around the Purdue Model that layers a plant from the physical process up to enterprise IT.

Layer

Corporate IT (L4/L5)

The enterprise network and internet-facing systems that provide an attacker's initial foothold. Tested as a standard IT engagement.

Layer

Industrial DMZ (L3.5)

The IT/OT boundary — the single most important control. We test whether segmentation actually prevents a pivot from IT into OT.

Layer

Supervisory & control (L2/L1)

SCADA servers, HMIs, engineering workstations, PLCs and RTUs — assessed passively on production, actively on replicas or in maintenance windows.

Layer

Safety systems (L1)

Safety instrumented systems — the Triton target — assessed with the greatest care, given their role in preventing physical catastrophe.

// 04 What we commonly find in energy environments

CriticalSegmentation

IT/OT boundary eroded

An industrial DMZ that was correctly designed at build, then undermined by years of remote-access, monitoring and vendor exceptions — letting a corporate-network foothold reach the control layer.

CriticalAccess

Default credentials on controllers

Vendor defaults and shared engineering passwords with no MFA on devices that can reprogram the physical process.

HighRemote access

Vendor remote-support exposure

Always-on vendor VPNs and remote-support tooling into the OT environment, often without MFA — a leading real-world entry vector.

HighLegacy

Unpatched legacy HMIs

Engineering workstations and HMIs on end-of-life Windows that cannot be patched without vendor re-validation, holding the software that programs the PLCs.

// 05 Regulator- and supply-chain-ready reporting

An energy operator's report has to serve several masters at once: the NCA for OTCC and ECC compliance, the operator's own safety and engineering leadership, and often a customer such as Aramco or SABIC enforcing supply-chain requirements. We structure the deliverable so every finding is mapped to the relevant control reference — OTCC 2-10, ECC 2-11, IEC 62443 zones — with severity expressed in terms of both cyber and process risk, and remediation guidance appropriate to an OT environment where "just patch it" is rarely an option. Because retesting is included, you can evidence closure to the regulator and to your supply-chain partners. Our full OT approach is set out in the OT/ICS penetration testing service.

// 06 Frequently asked questions

Why does oil and gas need specialist testing?

Because a cyber weakness is a physical-safety weakness. Attacks can halt production or defeat safety systems, as Triton demonstrated against a Saudi petrochemical plant. Standard IT testing is not built for OT fragility.

Which regulations apply?

In Saudi Arabia, NCA ECC (IT) and NCA OTCC (OT, control 2-10) for CNI operators, plus vendor standards like Aramco SACS-002 and SABIC CyberTrust; IEC 62443 internationally.

Can you test without disrupting production?

Yes — passive on production-critical layers, active only on replicas or in maintenance windows, with agreed stop conditions.

What does it cover?

IT (initial access), the IT/OT boundary, and OT itself — SCADA, HMIs, PLCs and safety systems — structured around the Purdue Model.

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Leads safety-first OT and IT engagements for GCC energy operators — scoped around the physical process and reported for the NCA, IEC 62443 and supply-chain standards like Aramco SACS-002.

Protecting energy infrastructure?

We scope OT/ICS and IT engagements around your process and risk tolerance — passive-first, with stop conditions agreed up front and findings mapped to NCA OTCC, IEC 62443 and your supply-chain obligations.

Schedule an OT scoping call → OT/ICS testing →