Oil, gas, and energy operators run two networks that increasingly touch each other: the business IT network and the operational technology (OT) systems controlling pumps, compressors, turbines, breakers, and pipelines. A breach that means downtime and cleanup on the IT side can mean a physical safety incident on the OT side. Here's what a defensible OT/ICS security program looks like in practice: SCADA testing, NERC CIP compliance, IEC 62443 zoning, and the segmentation model tying it together.
Why OT Security Isn't Just IT Security With Extra Steps
Standard IT security ranks confidentiality first, then integrity, then availability. Industrial control systems (ICS), including SCADA (supervisory control and data acquisition) platforms, flip that order. Availability and physical safety come first, because these systems run 24/7 physical processes: a compressor station, a substation, a wellhead. A routine IT-style vulnerability scan that would be harmless against a server can crash a PLC (programmable logic controller) or an HMI (human-machine interface) and take a process offline or worse.
That's why OT networks are usually mapped to the Purdue Model: Levels 0–3 cover the OT side (the physical process, basic control, supervisory/SCADA-HMI functions, and site operations), while Levels 4–5 cover the IT side (business planning and enterprise systems). Most modern architectures also insert a Level 3.5, an industrial DMZ (demilitarized zone), as a filtered buffer between OT and IT, replacing pure air-gapping with firewalled, logged data exchange. If your organization operates in this space, our oil, gas & energy industry page covers the broader security picture beyond OT alone.
SCADA and ICS Penetration Testing: "Do No Harm" Comes First
Testing a SCADA or ICS environment isn't the same exercise as testing a corporate web app. The standard approach starts with passive reconnaissance (read-only packet capture, protocol analysis, and a review of network diagrams and configurations) before any active testing begins. Active exploitation is reserved for test benches or "digital twins" that mirror the production environment, not the live systems running the actual process. The rule every credible ICS testing methodology repeats is simple: do no harm.
For an operator, that means choosing a testing partner who scopes engagements around safety and knows when to stop at reconnaissance rather than push into active exploitation on a live control system. Our penetration testing services are scoped this way for ICS/SCADA environments, not treated as a copy-paste of a standard network pentest.
NERC CIP: The Standards That Apply
NERC (North American Electric Reliability Corporation) is the FERC-designated Electric Reliability Organization for the bulk power system in North America; FERC (the Federal Energy Regulatory Commission) approves and enforces the standards NERC develops. The active CIP (Critical Infrastructure Protection) standards that matter for compliance today span CIP-002 through CIP-014, covering areas including:
- CIP-002: categorizing BES Cyber Systems
- CIP-003: security management controls
- CIP-004: personnel and training
- CIP-005: electronic security perimeters
- CIP-006: physical security
- CIP-007: system security management
- CIP-008: incident reporting and response
- CIP-009: recovery plans
- CIP-010: change management and vulnerability assessment
- CIP-011: information protection
- CIP-012: control-center communications
- CIP-013: supply chain risk management
- CIP-014: physical security of transmission stations
Two dates worth diarizing: CIP-015-1, covering internal network security monitoring, took effect September 2, 2025, and CIP-003-9, which tightens vendor remote access and supply chain requirements, begins enforcement April 1, 2026. Continuous internal monitoring is exactly the gap a managed detection capability is built to close: see our SOC as a Service offering if you need eyes on the network around the clock rather than just at audit time.
Full details of each standard are on NERC's official CIP standards page.
IEC 62443: Zones, Conduits, and Security Levels
Where NERC CIP is a regulatory requirement for the North American bulk power system, IEC 62443 is the international standards series most operators use to structure OT security more broadly. The core idea is zones and conduits: a zone groups assets that share the same security requirements, and a conduit is the controlled path (firewall, authentication, encryption, logging) between zones.
The most relevant parts of the standard:
- 62443-1-1: concepts and models
- 62443-2-1: the asset owner's security program
- 62443-3-3: system security requirements and Security Levels
- 62443-4-2: component-level security requirements
Security Levels run from SL0 (no specific protection) to SL4 (protection against sophisticated, well-resourced attackers, including nation-state actors). Mapping your assets to zones, your data flows to conduits, and your risk tolerance to a target Security Level gives you a structured way to prioritize spend instead of trying to secure everything to the same standard.
The Threat Isn't Hypothetical
OT-targeted intrusions against energy infrastructure are an active, ongoing concern, not a future risk. CISA (the Cybersecurity and Infrastructure Security Agency) has documented Volt Typhoon, a PRC state-sponsored actor, pre-positioning inside US critical infrastructure IT networks, including energy, with footholds observed for as long as five years, and disclosed OT-network access at a Massachusetts electric and water utility lasting roughly a year; see CISA's advisory AA24-038A. More recently, a Russia-linked threat actor struck Poland's energy sector on December 29, 2025, hitting over 30 wind and solar farms plus a combined heat-and-power plant with wiper malware that damaged remote terminal units and erased HMI data; Polish authorities attributed it to the FSB-linked Berserk Bear group, while some researchers pointed instead to the GRU-linked Sandworm group; CISA issued an alert amplifying the Polish CERT's findings in February 2026, covered here. Both cases targeted the OT layer directly, not just the IT network around it.
A Practical Starting Checklist
If you're building or reviewing an OT/ICS security program, a reasonable first pass looks like:
- Map your environment to the Purdue Model and confirm you have a real industrial DMZ, not just a firewall rule between flat networks
- Scope any penetration test around OT-specific safety rules: passive first, active testing on a test bench or digital twin
- Confirm which NERC CIP standards apply to your BES Cyber Systems, and diary the CIP-015-1 and CIP-003-9 enforcement dates
- Define zones and conduits under IEC 62443 and assign a target Security Level per zone based on actual risk
- Put continuous monitoring in place for OT network traffic, not just periodic audits
If you'd rather talk through where your environment stands against these points, get in touch and we can walk through it together.
Frequently Asked Questions
What's the difference between OT security and IT security?
IT security typically prioritizes confidentiality first; OT security prioritizes availability and physical safety first, because OT systems control real-world physical processes running continuously rather than just handling data.
Is it safe to run a penetration test against a live SCADA system?
Standard practice is passive reconnaissance and protocol analysis on the live system, with any active exploitation done on a test bench or digital twin instead of production, following a strict "do no harm" principle.
Who enforces NERC CIP compliance?
FERC (the Federal Energy Regulatory Commission) approves and enforces the CIP standards that NERC (the North American Electric Reliability Corporation) develops for the bulk power system.
What are zones and conduits in IEC 62443?
A zone is a group of assets that share the same security requirements, and a conduit is the controlled, secured communication path (firewalled, authenticated, encrypted, and logged) between two zones.
What is the Purdue Model's industrial DMZ?
It's Level 3.5 in the Extended Purdue Model, a filtered buffer zone between OT (Levels 0–3) and IT (Levels 4–5) that replaces a pure air gap with controlled, monitored data exchange.
Are attacks on energy sector OT systems actually happening?
Yes. Documented cases include Volt Typhoon's multi-year prepositioning in US critical infrastructure networks and a Russia-linked wiper attack on Poland's energy sector in late December 2025 (attribution disputed between Russian state-linked groups), both confirmed in CISA advisories.



