Fort Worth 24

collapse
Home / Daily News Analysis / Marathon Petroleum’s CISO on OT security automation, supply chain risk

Marathon Petroleum’s CISO on OT security automation, supply chain risk

Jul 28, 2026  Twila Rosenbaum  4 views
Marathon Petroleum’s CISO on OT security automation, supply chain risk

In a wide-ranging discussion, Mary Rose Martinez, Chief Information Security Officer at Marathon Petroleum, shared her insights on how the energy giant is adapting its cybersecurity posture as automation and digitization transform operational technology (OT) environments. Martinez leads security for a sprawling network of refineries, pipelines, and terminals across the United States, and she addressed several critical areas: the erosion of traditional air-gapped OT boundaries, the use of the Purdue model to balance security with production continuity, supply chain risk management, workforce skill development, and partnerships with government agencies.

Fading Air-Gaps and Expanding Attack Surfaces

Martinez noted that the longstanding assumption that OT environments are isolated from IT networks is no longer valid. “We have had to make the mindset shift that the traditional concept of air-gapping operational technology environments is effectively dissipating,” she said. As refineries and pipelines become more digitized, industrial control systems such as programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems are increasingly exposed to the same threat landscape that has long plagued enterprise IT. This digital transition is not unique to energy; manufacturing, transportation, and other critical infrastructure sectors face similar challenges. The consequence is that security teams must continuously reassess their protective and defensive controls to ensure they remain adequate and effective as automation deepens.

Architecting Defenses Around Unpatchable Systems

A key operational reality in industrial environments is that many assets, such as catalytic crackers in refineries, cannot be rebooted on a standard Patch Tuesday schedule. Martinez emphasized that Marathon’s commitment to safe, reliable, and environmentally sound operations drives its cybersecurity approach. The company leverages the Purdue Enterprise Reference Architecture (PERA) model, a hierarchical framework that segments OT networks into levels from physical process to enterprise. By implementing appropriate security controls at and between the information and OT layers, the team creates space to synchronize security actions with regular operational cadences, minimizing disruption while managing risk. She explained that this architecture allows for patching, monitoring, and incident response to occur during planned maintenance windows or operational downtime, rather than forcing immediate, disruptive updates that could halt production.

Supply Chain Risk in an Automated Ecosystem

Automation often arrives bundled with vendor platforms, third-party models, and remote support tunnels. Martinez identified the greatest risks in the supply chain as those where companies have the least visibility and control. “We have greater control over how our environment is accessed and least control over our vendors’ products or security practices,” she said. These risks extend beyond direct third-party vendors to nth-party vendors deeper in the supply chain. To mitigate these exposures, Marathon performs thorough due diligence and assessments before onboarding new products or services. The company also relies on strong contractual language that requires vendors to adhere to specific security standards and to notify Marathon of material changes. Additionally, forming strategic partnerships with key vendors is valuable, allowing Marathon to provide input on product design, receive early warnings about vulnerabilities, and jointly respond to incidents to restore operations as quickly as possible. The energy sector’s reliance on OT vendors like Siemens, Rockwell, and ABB means that a single compromised update or remote support session could cascade across multiple sites, making vendor risk management a top priority.

Bridging the Workforce Skill Gap

As processes become more automated, the workforce must adapt. Martinez acknowledged a potential skill gap between those who understand the chemistry and physics of refining and those who understand the code that controls the systems. She referenced the concept of “Calm Technology,” where systems are as invisible as possible in support of human tasks. To achieve this, the people developing, securing, and providing digital systems must deeply understand business processes and operations. Simultaneously, some democratization of digital know-how is necessary. Technology advances, especially in artificial intelligence, are lowering the barrier to codification, but they do not eliminate the need to cross-skill personnel—they simply change the skilling required. Marathon develops various learning pathways to increase digital fluency across the company, tailored to different roles and interests. For example, operators might learn to read log data, while IT staff might shadow refinery engineers. This cross-pollination ensures that the human backstop remains meaningful even as autonomous systems take over routine tasks. The company also invests in simulation training and red-team exercises that challenge both OT and IT personnel to work together under realistic attack scenarios.

Regulatory Pressure and Threat Landscape

Critical infrastructure operators face growing pressure from agencies like CISA and the Transportation Security Administration (TSA), which issue directives and regulations. At the same time, state-aligned actors are actively probing energy systems. Martinez noted that Marathon understands its role in the nation’s critical infrastructure and continually adjusts its strategies and controls based on the threat landscape. The team re-evaluates the efficacy of its protective and defensive controls in proportion to technology advancements. Partnerships with government agencies are key: they provide intelligence that helps Marathon appropriate resources most efficiently, and Marathon provides input into security regulations to ensure they are operative and effective for the industry at large. For example, Marathon participates in information-sharing groups like the Oil and Natural Gas Information Sharing and Analysis Center (ONG-ISAC) to receive timely threat indicators and share anonymized incident data. The company also works with CISA’s Cybersecurity Performance Goals and the TSA’s pipeline security directives, which mandate specific measures for critical pipelines.

IoT and Edge Computing in OT

A related trend mentioned in the broader industry context is the proliferation of Internet of Things (IoT) sensors and edge computing devices that bring connectivity closer to the process. These devices often lack traditional security controls and can introduce new vulnerabilities. Marathon must account for these when updating its Purdue model layers. Edge gateways that aggregate sensor data and send it to the cloud create additional entry points for attackers. Martinez indicated that the company is investing in network segmentation, strict access controls, and continuous monitoring to manage these endpoints.

Incident Response and Recovery

The CISO also touched on incident response planning for OT environments. Unlike IT systems, where an incident might mean isolating affected machines, in OT the priority is to maintain safe operations. Marathon has developed playbooks that coordinate between cybersecurity teams and process control engineers. These playbooks are tested through tabletop exercises and full-scale drills that simulate attacks on SCADA systems or PLCs. Recovery from an OT incident can take weeks if controllers need to be re-commissioned, so the company maintains detailed backups of configuration files and has alternative manual control procedures in place.

Future Outlook

Looking ahead, Martinez expects that the convergence of IT and OT will accelerate, especially with the adoption of 5G private networks in industrial settings. This convergence will require even tighter integration between security teams and operations departments. She also anticipates that AI-driven security analytics will become essential for detecting anomalies in process behavior, such as a valve opening at an unusual time, which could indicate a cyber intrusion. Marathon is piloting machine learning models that monitor sensor data for signs of tampering or misconfiguration, alerting operators before physical damage occurs.

In summary, Marathon Petroleum’s approach to OT security under Martinez’s leadership is pragmatic and layered. By acknowledging that air-gaps are gone, using the Purdue model to architect defenses without stopping production, proactively managing supplier risk, cross-skilling its workforce, and working closely with government partners, the company aims to stay ahead of adversaries who increasingly target energy infrastructure. The key takeaway for other critical infrastructure operators is that security must be an enabler of automation, not an obstacle, but it requires constant evolution and investment.


Source: Help Net Security News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy