The Evolution of Cybersecurity in Oil and Gas Post-Aramco Hacks: A Comprehensive Overview

Large organizations often only prioritize cybersecurity after experiencing significant disruptions to their core operations, forcing them to dedicate substantial resources to bolster their cyber defenses.

Ross Brewer, VP and Managing Director EMEA at Graylog, highlights this critical insight about the prevailing attitude towards digital threats in the oil and gas sector up until 2021.

In May of that year, the Colonial Pipeline in the US was paralyzed by a ransomware attack. A month later, hackers demanded $50 million after infiltrating Saudi Aramco’s data systems.

David Bicknell, Principal Thematic Analyst at GlobalData, describes these incidents as a pivotal “wake-up call” for oil companies and governments, including the White House. “Global critical infrastructure remains highly vulnerable due to increasingly complex geopolitical dynamics,” Bicknell tells Power Technology. “We are navigating through particularly challenging times for cybersecurity.”

Early Warnings

The oil and gas sector had an early warning nearly a decade earlier. In 2012, Saudi Aramco faced a ransomware attack that compromised 35,000 computers and disrupted daily operations.

“In response to the 2012 attack on Aramco, major organizations have significantly enhanced their cybersecurity measures,” Brewer notes. “In recent years, the industry has adopted more stringent protocols and practices to prevent attacks and reduce vulnerabilities. This includes rigorous vetting of vendors and comprehensive testing of new systems before installation.”

For Saudi Aramco, securing its infrastructure and assets led to a memorandum of understanding with US-based Dragos, but only after the 2021 breach. Brewer acknowledges that there is still much work to be done.

“The global petrochemical sector is at the intersection of activism and geopolitics, making it a prime target for various cyber threats,” Brewer asserts. “It’s essential for these organizations to adopt a proactive cybersecurity stance, incorporating advanced monitoring systems to detect and mitigate threats effectively.”

In 2023, ransomware attempts affected one in ten organizations worldwide, marking a 33% increase from the previous year, when the figure was one in thirteen, according to Check Point Research.

A Target on the Oil and Gas Sector

With cyberattacks on utilities increasing by over 200% in 2023, Bicknell’s observation that many of these attacks target utility companies holds significant relevance.

Oil and gas firms are particularly vulnerable due to their ties to nation-states. Companies like Gazprom in Russia, Chevron and Exxon in the US, Equinor in Norway, ENI in Italy, and Great British Energy in the UK are all notable targets.

These large conglomerates are crucial revenue sources for their countries, making them appealing targets for cyber activists seeking to disrupt a rival’s economic interests, often through distributed denial of service (DDoS) attacks.

The continual profitability of oil and gas companies has attracted more mainstream cybercriminals, drawn by the substantial rewards of successful ransomware attacks.

“Financial gain is the primary driver behind most cyberattacks on the oil and gas industry,” Brewer explains. “Hackers employ spear phishing, ransomware, and supply chain attacks to steal sensitive data and demand ransom. The potential for widespread disruption makes this sector particularly lucrative for criminal groups.”

With government support, it’s anticipated that oil and gas companies will increase their investment in top-tier cybersecurity systems. However, maintaining vigilance throughout the organization is essential, as Brewer concludes: “Oil and gas firms must strengthen basic cyber hygiene practices and develop robust forensic capabilities to detect and address suspicious activities across various attack vectors.”

More Articles & Posts