---
title: "Secure Oil & Gas SCADA/DCS Networks | Control"
url: https://fire-vault.com/control-for-oil-and-gas
description: "Protect safety instrumented systems and DCS/SCADA environments in the oil and gas sector by physically controlling all data paths to and from the OT zone.…"
lang: en-GB
---

Oil and Gas

# Control Path Protection for Upstream, Midstream, and Refinery

Oil and gas operations span remote wellheads, offshore platforms, pipelines, and refineries. Each environment runs safety-critical control systems that must remain isolated from corporate networks and external threats.

- Safety system tampering
- Ransomware on DCS
- Remote wellhead intrusion
- Vendor persistent access

Back to Control: https://fire-vault.com/solutions/control

Image: Offshore oil and gas infrastructure at night (https://fire-vault.com/assets/sector-square-oil-gas-BKpiP-l9.jpg)

The exposure in numbers

01

DCS and SIS isolation from corporate IT

100% DCS and SIS isolation from corporate IT

02

Persistent vendor paths to safety systems

Zero Persistent vendor paths to safety systems

03

Operational zones with independent governance

5 Operational zones with independent governance

04

IEC 62443 and NIS2 compliance evidence

Full IEC 62443 and NIS2 compliance evidence

The Challenge

## Oil and gas face converging cyber-physical risks.

01

### Safety System Exposure

Safety instrumented systems increasingly share network infrastructure with DCS and business systems, creating paths to the last line of defence against catastrophic events.

02

### Remote Operations

Offshore platforms and remote wellheads rely on satellite and radio communications for control, with limited visibility into who is accessing what.

03

### Contractor Access

Dozens of specialist contractors require access to different control systems, each creating persistent pathways that outlive the maintenance window.

Oil and Gas

> In oil and gas, a compromised control system is not a data breach. It is a potential safety incident with consequences measured in lives, environmental damage, and billions in liability.

The Scenario

### Scenario: Refinery DCS Compromise via Contractor VPN

Attackers compromise a control system integrator through a targeted phishing campaign. Using the integrator's VPN credentials, they access the refinery DCS network through a maintenance connection that was left active between scheduled visits. Over three weeks, they map the process control network and deploy modified logic on key programmable controllers. When activated, the modified logic causes a distillation column to operate outside safe parameters. The safety instrumented system should intervene, but its engineering workstation was reachable from the same network segment. With Control, the contractor VPN path is physically severed between maintenance windows. The SIS exists on a separate, disconnected network. The attack cannot reach safety systems because the path does not exist.

"We had 23 active contractor VPN tunnels into our DCS network. When we audited them, seven belonged to contractors whose projects had ended more than a year ago. The tunnels were still live."

Module deployment · oil and gas network

## Where each Control module is deployed across SCADA, DCS and safety.

Oil and gas operators run a corporate estate, SCADA across pipelines and terminals, DCS at process plants and SIS at the safety layer. Control puts a real boundary between each layer.

Grounded in IEC 62443-3-2, API Standard 1164 and TSA Pipeline Security Directives.

L5

Internet / Cloud

External

Cloud services

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

External traffic stops at the perimeter.

L4

Enterprise

IT

ERP

Email

SOC / SIEM

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Office estate has no path into SCADA on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server

Patch & AV

Data broker

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Data crosses the DMZ on controlled routes only.

L3

Operations

OT

Historian

Engineering

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate

Engineering and SCADA on separate fabrics.

L2

Supervisory

OT

Pipeline SCADA

DCS HMI

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Control changes require approval before they move.

L1

Basic control

Field

DCS controllers

PLCs

RTUs

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Safety sits behind its own boundary.

SIS

Safety systems

Field

Safety PLC

ESD

F&G

Safety integrity. Last line of defence.

Safety integrity. Last line of defence.

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Field kit ties to named engineers.

L0

Physical

Field

Pumps

Valves

Sensors

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

DCS baselines, PLC programs, SIS logic, recipes and the recovery sets you need to rebuild from.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   At every Purdue boundary
   Each layer sits on its own physical fabric. A compromise in one does not walk into the next.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the L5 to L4 link and the L4 to L3.5 link
   Real hardware off switches on the public and office boundaries, cutting the live path into operations when needed.
3. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the L5 to L4 link and inside the L3.5 DMZ
   Before data feeds operations, Validate checks its origin and integrity. A spoofed reading does not become a process action.
4. Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   Inside the L3.5 DMZ
   Telemetry and operational data land inside a defined route. Nothing streams unattended.
5. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   On the L2 to L1 link
   Pushing a change to a controller holds until the right approval is in place.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the L1 to SIS link and the SIS to L0 link
   Safety and field access ties to named engineers with the right authority and the right device.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Sovereign Process Data

All process control configurations and safety system logic remain within the agreed jurisdiction in NATO-approved Firevault Bunkers.

02

### Multi-Party Access Control

Contractor and vendor access requires sign-off from both operations and HSE teams before any path is activated.

03

### IEC 62443 Evidence

Automated compliance logging maps directly to IEC 62443 zone and conduit requirements and NIS2 Article 21 outcomes.

04

### Satellite Failover

Out-of-band management ensures control plane access to offshore and remote facilities independent of primary communications.

05

### Tamper-Proof Logging

Every contractor session, configuration change, and access authorisation is recorded in immutable logs on physically separate infrastructure.

06

### Verified Safety Configuration Baselines

Verified baselines of SIS logic and safety configuration enable restoration of control-plane state during total compromise scenarios.

Demo to Live

## Adoption Guide

Step 1

#### Process Network Assessment

Map all network paths between corporate IT, DCS, SIS, and contractor access points across upstream, midstream, and downstream operations.

Step 2

#### Zone and Conduit Design

Design physically separated zones aligned to IEC 62443 requirements with Control modules governing each conduit between zones.

Step 3

#### Single Facility Pilot

Deploy at one facility with full zone separation, contractor access governance, and compliance logging to validate operational procedures.

Step 4

#### Enterprise Rollout

Phased deployment across all facilities with verified configuration baselines, continuous compliance evidence, and out-of-band management.

Step 1

#### Process Network Assessment

Step 2

#### Zone and Conduit Design

Step 3

#### Single Facility Pilot

Step 4

#### Enterprise Rollout

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

## Explore More

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure
https://fire-vault.com/control-for-critical-infrastructure

### IEC 62443 Framework

Industrial automation security and Purdue model compliance.

Learn more about IEC 62443 Framework
https://fire-vault.com/solutions/control/frameworks/iec-62443

### Supply Chain Threat

Disconnect third-party paths when not in active use.

Learn more about Supply Chain Threat
https://fire-vault.com/control-for-supply-chain-risk

### Control for OT Environments

Physical-path governance for SCADA, ICS and industrial control data.

Learn more about Control for OT Environments
https://fire-vault.com/control-for-ot-environments

### Control for Utilities

Zone and conduit governance for power, water and gas networks.

Learn more about Control for Utilities
https://fire-vault.com/control-for-utilities

### NIS2 Framework

Article 21 outcomes evidenced through physical path governance.

Learn more about NIS2 Framework
https://fire-vault.com/solutions/control/frameworks/nis2

Questions

## Frequently Asked

Oil and Gas blueprint

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-oil-and-gas#webpage",
    "url": "https://fire-vault.com/control-for-oil-and-gas",
    "name": "Secure Oil & Gas SCADA/DCS Networks",
    "description": "Protect safety instrumented systems and DCS/SCADA environments in the oil and gas sector by physically controlling all data paths to and from the OT zone.…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-oil-and-gas#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-oil-and-gas#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Secure Oil & Gas SCADA/DCS Networks",
        "item": "https://fire-vault.com/control-for-oil-and-gas"
      }
    ]
  }
]
```