A ransomware attack hits a chemical plant, forcing it into a safe state. No one is injured, the site holds steady, and operators initiate a restart—only to find systems remain down. Every attempt to bring them online encounters encrypted processes and altered configurations. The outage stretches into weeks, and losses ripple through the supply chain in both directions. Refineries, chemical plants, and pipeline operators carry this exposure across control systems that run 20 to 40 years.
Marco Ayala, technical director for global energy at ABS Consulting, has spent over two decades inside industrial control system (ICS) security. He frames the risk with the discipline he believes owns it: “Reliability, uptime, and safety are paramount. Cybersecurity affects all these outcomes, making it an engineering problem.” The financial consequences of getting it wrong are escalating. Cyberattacks on U.S. utility companies surged nearly 70 percent in a single year. Dragos and Marsh McLennan estimate worst-case global OT cyber losses at $329.5 billion across all sectors. Waterfall Security reports a 146 percent year-over-year increase in OT sites hit by attacks with physical consequences.
Recovery plans break under real pressure
Shankar Somasundaram, CEO of Asimily, which inventories connected devices across industrial sites, observes how restarts expose flawed assumptions in recovery plans. “I’ve seen plants with a backup of a controller, but the engineer who knew why it was configured the way it was is long gone. So the backup is restoring a state no one can confirm is actually still correct. Plants end up reverse-engineering their own process under immense pressure—mid-outage—which is the worst possible time to learn how your plant functions,” he says.
Written recovery estimates rarely survive contact with a live restore. “We have seen recoveries take a few days longer than planned, while others have been months over schedule,” Somasundaram adds. He emphasizes a critical distinction: backups that have never been restored against a live controller often behave differently when it matters most. “Until you’ve run that restoration for real, you have more of a guess than a hardened recovery capability.”
Vendors become the next constraint. Critical systems frequently require the original integrator or manufacturer physically at the plant to restore operations safely. “Who’s to say that person is available on your timeline? Your backup plan may have assumed a phone call would solve something, when the reality is you’re looking at a two-week wait for someone to hop on a plane,” Somasundaram notes.
The low-priority device opens the door
The entry point often lies where security attention is thinnest. Somasundaram sees a recurring pattern: plants lock down core OT devices but treat IoT devices—facility cameras, sensors, building systems—as afterthoughts because the risk feels smaller. “But IoT devices make just as good a launchpad into the rest of the plant’s network as anything else, and often a better one because nobody’s watching it quite as closely,” he explains. These intrusions often stay off the public record. Production never stops, nothing is provably lost, so the event is filed away as a non-event instead of the warning it actually was.
Hidden assets reachable from the internet
Ayala conducts cold-eye assessments and keeps encountering the same blind spot. “The most common thing plant staff have stopped seeing is the steady accumulation of temporary workarounds on security controls, open and unlocked panels, and ‘temporary’ network connections that have been in place for a year or more,” he says. When he raises concerns, one room answered: “We’ve been running like this for several years without an issue. We will get to it and make sure this time.” Ayala reframes that calm: “The absence of a cyber event so far is not proof of safety, only proof that the site has not yet been seriously tested.”
At one facility, cellular routers and packaged OEM gear had accumulated on lower levels of the OT environment, absent from network drawings. During an incident, encryption malware made it onto an HMI and began spreading laterally. It was caught early before impacting primary control systems. “What finally moved the C-suite was seeing that their trusted enterprise network monitoring tools had completely missed the lower-level assets because they were outside normal visibility,” Ayala recounts. He notes that technical arguments alone rarely work; showing leadership that critical process assets were invisible to existing tools and directly reachable from the internet changed the conversation immediately. The hard part of the review is the conversation, and Ayala lets the room sit in it. “Sometimes you have to let the silence that follows the hard question do the work.”
Physics repeats itself, but software doesn’t
Ayala’s argument draws from a recent ABS Consulting white paper, “OT Cyber Resilience and Business Continuity for Global Energy Facilities,” which leans on process safety as a template. Standards like ISA/IEC 62443 for control-system security run alongside IEC 61511 for safety instrumented systems. Apu Pavithran, CEO of Hexnode, notes where the comparison breaks down: “For example, a valve predictably fails based on known parameters, but an attacker prefers novel techniques to disrupt in new ways. The digital world breaks in far less predictable—and far more targeted—ways than the physical.” Engineers carry one mechanical habit into software that does the most damage: “It’s a fallacy to think that certification is one-and-done. Unlike machinery built to last decades, the constant evolution of software and sheer speed of new vulnerabilities mean teams need to constantly check and recheck for patches.”
Insurers are writing the rules now
Insurance carriers now conduct annual OT security audits of refining and chemical sites, with findings feeding directly into premiums. Pavithran sees underwriting stepping into the space a mandate would occupy. “Plenty of industrial sites still sit outside any binding cyber mandate, and underwriting is surprisingly effective at filling this regulatory vacuum.” However, operators stumble on proof. “Most can describe their security efforts yet struggle to continuously prove them. Insurers want a current asset inventory and a patch cadence with exceptions documented.” An underwriter reaches its verdict on one condition: in the eyes of an insurer, no record means no evidence of control.
The talent gap: people who can do this are retiring
The sector is being told to run a three-to-five-year resilience roadmap at every site simultaneously. The work demands someone fluent in both control rooms and networks—a person who has stood on the floor during a process upset in the small hours. That profile takes fifteen to twenty years to develop, and the technicians who carry it are aging out. Pavithran favors building replacements inside the plant. “A lot of what makes that person valuable doesn’t travel with them. They know their specific plant, but real site knowledge comes on the job. Realistically, the next generation should come from internal conversion rather than external recruitment.” He notes the sector has crossed a shift this size once before: “Today’s veterans were yesterday’s novices facing a major move from airgapped environments to always-on machinery.”
The underlying challenge is that OT cybersecurity is fundamentally different from IT cybersecurity. Control systems are designed for reliability and safety, not security. Patching is difficult because it may require shutting down production. Legacy systems often run unsupported operating systems. The convergence of IT and OT networks has expanded the attack surface, yet many organizations still allocate roughly 20 percent of their cybersecurity budget to OT, with the rest going to enterprise tools. This misalignment leaves critical infrastructure vulnerable.
Operators also struggle with asset management. A 2023 study by the SANS Institute found that nearly half of industrial organizations have incomplete asset inventories. Without knowing what is on the network, it is impossible to secure it. Ayala’s cold-eye assessments consistently uncover devices that have never been cataloged. He urges operators to think like attackers: “If you can’t see it, you can’t protect it. And if it’s reachable from the internet, someone will find it.”
The recovery problem is compounded by the fact that many backup systems are never tested. Somasundaram advises companies to conduct restore drills at least annually, under conditions that mimic real incidents. “The goal is not just to verify that the backup works, but to ensure the right people know how to execute the restore in a high-pressure environment.” He also warns against relying on vendors who may not be available during a crisis. Developing in-house recovery expertise is critical.
Finally, the human element remains the weakest link. Social engineering attacks targeting plant operators are increasing. A single phishing email can give an attacker credentials to the OT network. Training must go beyond annual compliance modules to include realistic simulations of ICS-specific attacks. The industry standards body ISA is developing a role-based certification program for OT cybersecurity professionals, but adoption is slow.
One question at a walkdown can reveal the state of security. Somasundaram would set aside paperwork and test one thing: “What I’d want to know is whether anyone can tell me what’s really on the plant’s network and what those things are allowed to talk to. I would ask to see the asset inventory and check it against reality. In a ceremonial program, that inventory is a spreadsheet that was accurate the day someone built it and has been drifting ever since, with devices on the floor that never made it in and old entries still sitting on the list long after the equipment is gone.” He weighs the answer for one thing: “Ask how they know their inventory is current, and a real program describes an ongoing process. A ceremonial one describes the last audit, in the past.”
The energy sector’s OT cybersecurity talent crisis is not just about numbers—it is about institutional knowledge disappearing. As the veteran workforce retires, companies must accelerate knowledge transfer, invest in training programs specifically for OT, and adopt automation where possible to reduce manual dependencies. The alternative is a future where every recovery becomes a guessing game, and the cost of getting it wrong grows with each passing year.
Source: Help Net Security News