← All briefings

Oil and Gas Ranks Worst in Three OT Security Categories

Oil and gas holds the worst score in three separate operational technology security categories. Dragos's 2026 sector findings put malware protection and detection gaps at 37% of oil and gas assessments, vulnerability management findings at 31%, and poor IT/OT segmentation at 29%. Each of those is the highest share of any industrial sector. A fourth finding explains the other three. Default or weak credentials appeared in 26% of assessments.Those four numbers describe one condition. The sector operates a large population of controllers that cannot verify who is talking to them, on networks that cannot enforce a boundary, watched by tools that cannot distinguish an operator from an intruder.

Why do these findings compound?

Because each one is survivable alone and dangerous together. A flat network is tolerable when every device authenticates each session independently. A weak credential is contained when segmentation limits what it reaches. Oil and gas leads in both categories, which means a single valid credential reaches process control with nothing in the path to challenge it.

Dragos also reports that in 13% of its 2025 incident response cases, malware executed with no visible interface or process for conventional tooling to catch. In an environment where unauthorized traffic is indistinguishable from authorized traffic, silence is the expected outcome.

Two threat groups are working the sector specifically

VOLTZITE has compromised cellular gateways across U.S. midstream operations and extended into upstream and downstream environments, reaching engineering workstations and dumping configuration files and alarm data to learn which conditions trigger which responses.

AZURITE, newly designated in 2026, targets oil and gas engineering workstations and exfiltrates alarm data, configuration files, process information, and operator credentials. Dragos assesses with moderate confidence that the group is developing OT-specific attack capability. It has not yet been observed disrupting operations.

Neither group is described as depending on zero-days. Both collect credentials and process knowledge, which is what preparation looks like before disruption.

How exposed is the equipment?

Measurably. On April 7, 2026, the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command issued a joint advisory on Iranian-affiliated exploitation of internet-facing Rockwell Automation and Allen-Bradley programmable logic controllers across government, water, and energy targets. Censys then counted the exposure: 5,219 internet-facing Rockwell PLC hosts worldwide, with 3,891 of them, 74.6% of the global total, in the United States.

The composition matters more than the count. 771 of those hosts also expose VNC and 280 expose Telnet, both of which are direct paths to HMI and SCADA displays. 292 expose Modbus. Nearly half sit on a single mobile carrier's network, which is the signature of field equipment whose only route to the outside world is a cellular modem.

That description matches oil and gas geography exactly. Wellheads, gathering lines, compressor stations, remote pump stations, and tank batteries sit where fiber does not reach, visited by a technician on a monthly rotation. The connectivity that made remote monitoring affordable is the same connectivity that put the controller on the public internet.

The mitigations that followed the advisory were sound: remove devices from direct internet exposure, disable cellular where it is not essential, shut off VNC and Telnet, set physical mode switches to RUN. None of them give a controller the ability to authenticate a session. They reduce the exposure of a device that still trusts anything that reaches it.

Why PKI never closed this gap

PKI was never viable at these sites, so there is no failed deployment to point to. A certificate authority requires reachable infrastructure, and a compressor station on an intermittent cellular link has none. Certificates expire, and a controller commissioned in 2011 with a fifteen-year service life will outlast several certificate lifecycles and most of the people who remember the renewal schedule. Certificate operations assume an operator who can reach the device to perform them.

The result is not badly managed cryptography. It is the absence of authentication entirely, which is why 26% of assessments still find default or weak credentials on production equipment. The credential stayed at default because nothing in the architecture ever offered an alternative.

What improving posture actually requires

Three properties, measured directly against the four findings:

  • Authentication that works without reachable infrastructure. Air-gapped capable, functional over intermittent cellular and satellite links, with no dependency on a central authority being online at the moment of connection.
  • No persistent credential on the device. A controller that holds no static secret has no default password to find, no stored key to harvest, and nothing an adversary can replay after the fact.
  • A footprint that fits the hardware already installed. Sub-1MB and embedded, running on the constrained controllers in the field rather than requiring the capital program that replaces them.

How AKM changes each number

AKM delivers encryption and authentication to OT endpoints PKI could never reach. A pre-shared crypto seed algorithmically generates unlimited key material, keys refresh with every session, and every packet is independently verified. Provision once, and the device runs without further human intervention.

Against the credential finding, there is no static credential to be left at default, weak, or shared. AZURITE's collection of operator credentials from an engineering workstation returns material that expired with the session it belonged to.

Against the segmentation finding, AKM authenticates communication between functional groupings of OT systems. That delivers microsegmentation with no certificate authority, no certificate lifecycle to manage, and no plant network redesign. It is Zero Trust enforced at the protocol layer rather than at a firewall that field equipment sits behind on paper only.

Against the detection finding, packets from an unauthorized source fail verification instead of blending into normal traffic. The 13% of cases where malware ran silently depended on a network where an intruder's traffic looks exactly like an operator's.

Against the vulnerability management finding, a controller that cannot be patched can still be protected. AKM operates at the protocol layer and secures sessions to and from a device whose firmware is not going to be updated this decade.

The compliance case follows the technical one

TSA Security Directive Pipeline-2021-02 and its successors require network segmentation that prevents IT/OT lateral movement, multi-factor authentication for remote OT access, and continuous monitoring, with civil penalties reaching $25,000 per day per violation. IEC 62443 zone and conduit requirements ask for the same authenticated boundaries. Both frameworks describe outcomes that assume a device can verify who is talking to it. On most oil and gas field equipment today, that assumption does not hold.

The four assessment findings share one root cause. Field controllers in oil and gas cannot verify what connects to them, and every downstream gap follows from that. Closing it is a protocol decision, and it can be made on the equipment already in the ground.

About AKMSecure

AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.

LinkedIn Twitter