# Oil & Gas OT cybersecurity

> Pipeline SCADA, compressor and pump stations, and terminals subject to the TSA security directives. We design segmentation that satisfies the directive and survives the field.

Canonical: https://blackbirdcyber.com/sectors/oil-gas  
Blackbird Cyber · https://blackbirdcyber.com/ · sales@blackbirdcyber.com

## The exposure — The directive is the floor, not the ceiling.

TSA SD Pipeline-2021-02 requires segmentation between IT and OT and a plan for degraded operation. Field sites with satellite backhaul and shared vendor credentials make both hard.

Regulations and guidance: TSA SD-02, API 1164, IEC 62443.

- IT / OT segmentation evidence for the directive
- Compressor and pump station remote access
- Operating without SCADA: the degraded-mode plan

## Typical topology

A representative control network for pipeline and terminal operators, by Purdue level:

- L3.5 · DMZ: Pipeline DMZ
- L2 · HMI: Control room HMI
- L2 · SCADA: Pipeline SCADA
- L2 · Historian: Leak detection
- L1 · PLC: Station PLC
- L1 · RTU: Wellhead / valve RTU
- L1 · Safety: ESD system
- L0 · Process: Compressors · pumps · valves · tanks

Exposed path: vendor VPN → L2 · Historian (Leak detection).

## Where we start — Recommended engagements for pipeline and terminal operators.

- [OT Network Architecting](https://blackbirdcyber.com/capabilities/ot-network-engineering): Segmented control networks designed and built to keep the process running.
- [OT Cyber Program Review](https://blackbirdcyber.com/capabilities/ot-cyber-program-review): An independent review of your OT security program against the standards your regulators cite.
