TRANSMISSION ACTIVE
// FREQ: GOVCON EPISODE: 022 STATUS: SECURE

022 OT Attacks, AI Risk, and Data Security in the Oil and Gas Industry

The most important fact about the Colonial Pipeline attack is the one most people forget: the ransomware never touched the pipeline. It hit the billing and IT systems — and half the East Coast's fuel supply still shut down for six days, because the company couldn't prove the two worlds were separated. Fresh off a panel at the Data Driven Oil & Gas USA 2026 conference in Houston, the CISO breaks down the three forces converging on the energy sector right now: OT attacks crossing from IT into the systems that physically run operations, the AI rush wiring operational data straight into the control room, and the data security discipline that decides whether an operator rides the wave or wipes out. Because in critical infrastructure, the gap between the governance slide and the segmentation on the network isn't a fine. It's a pipeline shutdown.

JUMP POINTS //

00:32

OT Attacks Are Crossing the IT/OT Line

The dominant critical-infrastructure pattern of 2026: ransomware and wiper activity crossing from IT networks into operational technology — the systems that physically run wells, pipelines, and refineries. Industrial organizations now absorb nearly half of all ransomware and wiper activity, because OT was built for reliability, not security, and it’s increasingly connected to the internet.

03:32

Unsophisticated Attackers Are Still Winning

CISA, the FBI, the DOE, and the EPA issued a joint advisory warning that even unsophisticated actors are breaching oil and gas ICS and SCADA — succeeding through default credentials and exposed remote access. Underneath them, nation-state actors are quietly pre-positioning: getting in, establishing persistent access, mapping operations, and waiting for the opportune moment.

09:19

The Three Universal Marching Orders

Close the gap on OT-crossover attacks with three moves that work in any sector: get internet-facing assets off the public internet behind MFA and jump hosts, segment your network so a breach can’t spread laterally, and build detection that can actually find an intruder who’s already inside.

12:16

The AI Rush and IT/OT Convergence

Straight from the Data Driven Oil & Gas USA 2026 panel: the sector sees $200–400B in projected AI value by 2030, but only 15% of organizations are true AI leaders. AI is hungry for the data that lives in OT — so the industry is bridging the two worlds, and every connection built to feed a model is a path an attacker can travel the other way.

19:28

Case Study — The Colonial Pipeline Attack

One legacy VPN account with no MFA. 100GB of data stolen in two hours. Ransomware that hit only the IT and billing systems — and still forced a six-day shutdown of half the East Coast’s fuel supply, because Colonial couldn’t prove the OT side was clean. The IT/OT convergence lesson in its purest form.

24:31

Securing Your Data — The Marching Orders

Three actions to avoid becoming the next case study: fix the identity and exposed-access gaps Colonial left open, govern your operational data as a security asset instead of just an AI input, and segment IT from OT while pressure-testing the shutdown decision through real functional exercises.

// INCOMING SITREP

The episode covers why IT/OT convergence is the defining risk. The companion Sitrep is the operator's build-plan — how to architect the segmentation, data governance, and shutdown-decision discipline that would have stopped Colonial. Read the SITREP dossier.

ACCESS THE BRIEF »

TRANSMISSION LOG //

A Special Briefing From the Energy Sector

This is a special edition of Status: Secure. The CISO just returned from speaking on a panel at the Data Driven Oil & Gas USA 2026 conference in Houston, so this transmission goes deep on the energy sector — specifically the three forces converging on oil and gas right now: OT attacks crossing from IT into the systems that physically run operations, the AI risk reshaping the industry as it races to adopt, and the data security discipline that separates the operators who ride the wave from the ones who wipe out. And while the focus is energy, the core lesson reaches every organization that connects physical operations to an IT network — which, in 2026, is nearly everyone.

OT Attacks Are Crossing the IT/OT Line

The dominant critical-infrastructure attack pattern of 2026 is ransomware and wiper activity crossing from IT networks into OT — operational technology, the systems that physically run the wells, the pipelines, and the refineries. Industrial organizations now absorb nearly half of all ransomware and wiper activity, and the rise of ransomware-as-a-service has supercharged the problem: attacking OT no longer requires a sophisticated lone actor or a nation-state. You can now pay a service provider to run the attack for you. When an attack reaches OT, it doesn’t just lock files — it can halt physical production.

Why is OT so exposed? Because it was built for reliability and uptime, not security. These are the hardware devices sitting right on the pipes, the wells, the utility lines. For decades, an operator physically walked up to them to make changes. Now they’re connected to the network — and increasingly to the internet — for remote access by staff and vendors. They’re legacy systems, hard to patch, poorly segmented from IT, and full of default settings a field engineer never changed.

That last point is the quiet scandal of the sector. CISA, the FBI, the Department of Energy, and the EPA issued a joint advisory warning that even unsophisticated actors are successfully probing oil and gas ICS and SCADA systems — succeeding through default credentials and exposed remote access. Field engineers install these systems and leave the factory settings in place, because they’re operators, not security staff — and the default credentials are publicly known. When CISA sounds the alarm about unsophisticated attackers, the message is that the basic attacks are still working. That’s a verdict on the defense, not the attacker.

The Nation-State Layer: Pre-Positioning

Beneath the opportunists sit the nation-state actors, and their 2026 behavior is quiet pre-positioning: get in, establish persistent access, map the operations through patient reconnaissance, and wait for the most opportune moment. In December 2025, an actor compromised OT and ICS across Poland’s energy sector — renewable plants and a combined heat and power plant — entering through vulnerable internet-facing edge devices and deploying wiper malware that damaged remote terminal units, the actual equipment in the field.

CSIS reported this year that Iran has shifted from episodic, symbolic attacks to sustained pre-positioning — sitting inside energy, water, and transportation networks to create latent risk they can trigger during a future crisis. Imagine an adversary pre-positioned across multiple utilities simultaneously, waiting for a single geopolitical trigger to act on all of them at once. The chaos that could create is the entire point of the strategy.

And here’s why this reaches every sector, not just energy: the exposed edge device and the flat, unsegmented network that lets an unsophisticated ransomware actor reach OT is the exact same door a nation-state actor walks through to pre-position. The playbook is sector-agnostic. Healthcare has connected medical devices on the same networks as IT. Manufacturing and logistics run ICS. Even a corporate building has connected HVAC and access-control systems. Energy is simply where the consequences are most physical and most visible.

The Three Universal Marching Orders

For any organization with an operational footprint, three moves close the gap on OT-crossover attacks and the pre-positioning behind them:

Get your internet-facing assets off the public internet.

Nearly every one of these incidents started with an exposed, internet-facing device. Inventory everything reachable from the public internet — especially anything touching operations — and put it behind MFA and jump hosts. Remote access is a legitimate operational need; a public IP protected by a manufacturer’s default password is not remote access, it’s an open door.

Segment your network so a breach can’t spread.

The reason an IT compromise becomes an OT catastrophe is flat network architecture — once an adversary is in, they move laterally across everything. With real segmentation, you can lock down a compromised zone and keep the rest of operations running. Segmentation is what shrinks the blast radius when, not if, something gets in.

Make sure you can detect an intruder who’s already inside.

Pre-positioning works because the adversary is quiet and most organizations only watch the perimeter. Many operators have monitoring and logging on paper — but no one is watching, no alerts, no rules, no one investigating. Assume someone may already be inside and build the visibility to find them. Even an old-school honeypot — a decoy “crown jewel” asset — will surface an intruder who’s already resident.

The AI Rush and IT/OT Convergence

The back half of the briefing came straight from the conference floor. The entire agenda in Houston was AI and data — predictive maintenance, drilling optimization, reservoir modeling, AI-driven completions, and OT data feeding decisions back into the control room. The sector sees enormous value: a projected $200 to $400 billion in cumulative value AI could bring to oil and gas by 2030. But the number that should stop every executive is this — only about 15% of organizations qualify as true AI leaders. The other 85% are experimenting, and many are bolting AI onto data and networks that were never secured for it.

Here’s the structural problem. For decades, oil and gas ran two separate worlds — IT for the business, OT for the physical process, often air-gapped, frequently reporting to entirely different executives. AI collapses that separation, because AI is hungry for data and the most valuable data lives in OT. So the industry is connecting OT to IT, to the cloud, to AI platforms — bridging the two worlds to feed the models. That convergence is the entire value proposition of data-driven operations. It is also the entire security problem. Every connection you build to move OT data toward an AI model is a path an attacker can travel in the opposite direction — from IT, into OT, into the physical process.

AI multiplies the risk two ways. First, it widens the attack surface — every new pipeline from an operational sensor to a cloud model is a new door. Second, when you “close the loop” and let AI-driven decisions act on operations, corrupted data or a poisoned model doesn’t just give a bad answer — it can drive a bad physical action. AI in an operational environment turns a data-integrity problem into a safety problem. And there’s a sharper edge still: AI ruthlessly exposes the weak controls you already have. Over-permissioned accounts that sat harmless for years become live exposures the moment an AI assistant will happily surface data to anyone authorized to ask.

Riding the Wave Without Wiping Out

The panel’s framing was “riding the AI wave” — moving fast without wiping out. The wave is real and it isn’t going away, so the question is what separates the operators who ride it from the ones who go under. The answer: segmentation and governance are the surfboard, not the drag. The organizations that ride it well build their connections deliberately, with control over what data flows where and who can touch it. The ones who wipe out connect everything to everything to move fast — and build the adversary a highway into the control room.

Going fast and going secure are not opposites here. The same disciplined data architecture that makes an AI model reliable is what keeps it from becoming an attack path. You don’t have to choose between riding the wave and securing it — but you do have to build the board before you paddle out.

Case Study: Colonial Pipeline

To ground all of this, the episode walked the case study every energy executive half-remembers — and the details are the whole lesson. In May 2021, the DarkSide ransomware group got into Colonial Pipeline’s network through a single compromised VPN account — a legacy account with no MFA and a password harvested from an unrelated breach. One credential, no MFA. Once inside, they moved laterally thanks to the lack of segmentation, stole roughly 100GB of data in about two hours, and deployed ransomware that encrypted the corporate IT systems.

Here’s what most people get wrong: the ransomware hit Colonial’s IT network — billing and business systems. It never compromised the OT network, the actual pipeline control systems. And yet Colonial proactively shut the entire pipeline down anyway — because they didn’t know, which tells you they lacked the monitoring and segmentation to prove the OT side was clean. Out of caution to stop the spread, and because the billing systems needed to sell and move fuel were down, an IT-side attack took down physical operations across half the East Coast’s fuel supply without the attackers ever touching a control system. That is the IT/OT convergence lesson in its purest form.

The consequences: a six-day shutdown, fuel shortages and panic-buying across 17 states, gas over $3 a gallon for the first time since 2014, a presidential emergency declaration, and a $4.4 million ransom paid because the CEO — who later testified before Congress — didn’t know how deep the compromise went. The experts’ verdict: preventable. Two basic measures would have stopped it — an access review that would have caught and killed the dormant account, and MFA on that VPN.

And the forward-looking point that ties it to the AI conversation: Colonial happened in 2021 with relatively limited IT/OT connection. The AI rush is deliberately increasing that connection at every operator, building far more pathways between the business network and the operational one. If a lightly connected 2021 network produced Colonial, the densely connected, AI-fed networks being built right now raise the stakes dramatically — unless the segmentation and governance are built deliberately.

The Marching Orders: Securing Your Data

The episode closed on data security — because the first thing DarkSide did at Colonial, before encrypting anything, was steal 100GB of data. Three actions to avoid becoming the next case study:

Fix the Colonial failure first: identity and exposed access.

Don’t let another company’s emergency go to waste. Run the access review, enforce MFA everywhere, and kill dormant and legacy accounts. These are the exact controls that would have stopped Colonial.

Govern your operational data as a security asset, not just an AI input.

Before operational data flows into a model, establish access controls and integrity protections — know who can touch it, prove it hasn’t been tampered with, and control where it goes. Attackers exfiltrate data as their first move; the AI rush concentrates that data and wires it to operations, making governance a security control, not just an AI enabler.

Segment IT from OT and pressure-test the shutdown decision.

This is why you run business continuity and DR functional exercises — not a room full of people talking through a plan, but a real test that creates stress and forces the hard call: We have IT ransomware, we can’t instantly confirm OT is clean — do we shut down or not? That is the exact decision that cost Colonial six days.

OT attacks are crossing from IT into the physical world, the AI rush is widening the attack surface faster than the sector is securing it, and Colonial already showed us how it ends. The opportunity in front of oil and gas is real — hundreds of billions of dollars of it — and so is the risk, because every connection built to reach that value is a connection an adversary can travel the other way. Mission success starts with closing the gap between the AI strategy and the security practice — between the governance on the slide and the segmentation on the network.

Go Deeper: The Operator’s Build-Plan

This episode covers why IT/OT convergence is the defining risk of the AI era in oil and gas. Our companion Sitrep is how you fix it — the operator’s build-plan behind these marching orders: architecting real IT/OT segmentation with a Purdue-style boundary, closing the identity gaps Colonial left open, governing operational data as a security asset, and pressure-testing the shutdown decision before an incident forces the question. If this briefing gave you the landscape, the Sitrep gives you the blueprint.

Trust but verify your own posture. Fix the identity gaps Colonial left wide open. Govern your operational data as a security asset. Segment IT from OT before you ride the wave. Execute the standard.

// DECODED TRANSCRIPT

Access the full text logs of this transmission for compliance and review purposes.

SILENCE THE NOISE. AMPLIFY THE SIGNAL.

INTELLIGENCE IS USELESS IF YOU AREN'T LISTENING.

Join The Watch to receive New Episode Alerts, Strategic Breakdowns, and Guest Intel delivered to your inbox.