When did you last change your login password for your personal computer? If your approach to cybersecurity is anything like mine, then it was set back when the system was brand spanking new and fresh out of the box 10 years ago. Has its operating system been updated recently? Nope, why bother updating a system or software that is used to write the occasional email or store pictures? It doesn’t house the launch codes for the country’s nuclear arsenal. We just need to keep the antivirus software current and all is well in cyberland, right?
While the examples above are a bit extreme and too focused on personal computing, for those entities looking to do harm, it is an ideal setup. And especially so in those times when a personal computer is used to remotely access a work server to access a file or send an email.
The use of digital technologies and increasing dependence on cyberstructures has exposed the oil and gas industry to new sets of vulnerabilities and threats, according to a DNV GL press release. The organization recently delivered a study to the Lysne Committee—appointed by the Norwegian Ministry of Justice and Public Security—that revealed the top 10 most pressing cybersecurity vulnerabilities for companies operating offshore Norway. The issues are equally applicable to oil and gas operations anywhere in the world.
In the list of 10, there are the well-known, like lack of cybersecurity awareness, the use of mobile devices and storage units (i.e., smart phones and flash drives) and vulnerable software. Remote work during operations and maintenance also made the list.
The vulnerability falling in the No. 10 spot is the use of outdated and aging control systems in facilities. With more than 70% of the world’s oil and gas production coming from mature fields, it is a concern of particular note.
“Many installations on the Norwegian Continental Shelf are designed to have a lifetime of between 15 and 25 years, and a number of these have been allowed to operate for longer. This means a lot of the equipment and software is outdated and not very well adapted to today’s digital vulnerabilities,” the executive summary stated. “The digitization of the sector is taking place continuously. ‘The Internet of Things’ will lead to more units with digital vulnerabilities.”
According to the release, DNV GL believes vulnerabilities can be addressed through a risk-based approach, using the bow-tie model familiar in safety barrier management. This allows companies to identify the threats to and vulnerabilities of assets and operations and plan barriers to prevent incidents and mitigate the consequences of cyberrisks.
To access the report (in Norwegian) or a brief synopsis (in English), visit dnvgl.com/oilgas/download/lysne-committee-study.html.
Contact the author, Jennifer Presley, at jpresley@hartenergy.com.
Recommended Reading
McKinsey: Big GHG Mitigation Opportunities for Upstream Sector
2024-11-22 - Consulting firm McKinsey & Co. says a cooperative effort of upstream oil and gas companies could reduce the world’s emissions by 4% by 2030.
US Drillers Cut Oil, Gas Rigs for Second Week in a Row
2024-11-22 - The oil and gas rig count fell by one to 583 in the week to Nov. 22, the lowest since early September. Baker Hughes said that puts the total rig count down 39, or 6% below this time last year.
Coterra Takes Harkey Sand ‘Row’ Show on the Road
2024-11-20 - With success to date in Harkey sandstone overlying the Wolfcamp, the company aims to make mega-DSUs in New Mexico with the 49,000-net-acre bolt-on of adjacent sections.
Suriname's Staatsolie Says Exxon has Withdrawn from Offshore Block
2024-11-20 - Suriname's state-run oil company Staatsolie said on Nov. 20 that U.S. oil giant Exxon Mobil has withdrawn from its offshore block 52, and block operator Petronas Suriname E&P will take over its 50% stake.
Comments
Add new comment
This conversation is moderated according to Hart Energy community rules. Please read the rules before joining the discussion. If you’re experiencing any technical problems, please contact our customer care team.