Author: Raquel Carrillo

  • Protecting Operational Technology Environments Through Physical Security Review

    How LSC Helps Oil and Gas Operators Identify and Reduce Physical Risk to Critical OT Systems

    Understand the Role of Physical Security in OT Environments

    Operational Technology (OT) environments supporting pipeline operations are often evaluated through cybersecurity, network architecture, and process resilience. Physical security is a foundational component of OT cybersecurity, yet it is frequently evaluated separately from broader OT risk management efforts. Even well-designed cybersecurity controls can be undermined when unauthorized individuals gain physical access to critical systems, communications infrastructure, or recovery environments. Effective OT security requires both cyber and physical controls working together to protect operational continuity, resiliency, and recovery performance.

    In remote and distributed pipeline environments, physical vulnerabilities can introduce immediate operational disruption, safety exposure, and recovery risk, affecting operations, employee safety, and public confidence.

    LSC helps critical infrastructure operators identify and reduce this risk through structured physical security reviews of critical OT facilities, improving failover readiness, strengthening operational continuity, and reducing exposure to safety and regulatory impacts.
    These reviews also help operators prioritize and implement practical improvements by connecting physical conditions to operational, safety, and continuity outcomes. By aligning recommendations with industry guidance and regulatory expectations, operators can strengthen resilience in a way that is actionable and scalable.

    At a disaster recovery (DR) site, physical security gaps extend beyond unauthorized access, introducing risk to failover readiness and operational continuity. Without appropriate controls and independent supporting infrastructure, such sites may not perform as intended during disruption events.

    A structured review enables operators to identify high-impact vulnerabilities and prioritize practical improvements that reduce risk across their asset base.

    Recognize the Operational Consequences of Physical Security Gaps

    In traditional IT environments, unauthorized physical access can be serious, but in OT environments, it can have far broader consequences. Physical compromise of an OT-supporting facility can quickly escalate into:

    • Increased safety risk to employees and responders
    • Loss of control system availability and operational visibility
    • Damage to critical monitoring or communications infrastructure
    • Disruption requiring emergency response or restoration
    • Loss of situational awareness (alarms, pipeline conditions)
    • Increased regulatory, financial, and reputational exposure

    For many OT facilities, especially remote or lightly staffed locations, weak physical security can undermine cybersecurity controls. If unauthorized individuals can access critical systems without detection, overall risk increases immediately.

    Identify How Real-World Threats Can Disrupt Critical OT Systems

    Credible threat actors are not limited to highly sophisticated attackers. Relevant categories include opportunistic intruders, malicious outsiders seeking disruption or theft, insiders or third parties with knowledge of the facility, and more organized threat actors interested in impairing infrastructure operations or resiliency.

    In facilities with weak layered protection, likely threat behaviors include attempts to gain unauthorized access, exploit low-visibility areas, interfere with critical equipment, avoid detection, and target dependencies that affect continuity or recovery. These actions can lead to loss of system visibility, delayed response to abnormal conditions, or disruption of control system availability during critical events.
    This threat model is particularly important for facilities serving a DR function, where physical and infrastructure weaknesses can undermine performance during disruption events. Without independent supporting infrastructure, these vulnerabilities can extend beyond a localized issue and introduce broader risk to continuity and recovery.

    For public-facing purposes, the threat model should remain category-based and consequence-focused rather than site-specific or procedural. This preserves the value of the analysis while avoiding unnecessary disclosure of sensitive facility protection details.

    In practice, these risks often emerge through conditions such as disaster recovery facilities that retain dependencies on primary-site infrastructure, OT environments located within shared-use facilities, monitoring systems without defined response procedures, communications equipment exposed to environmental hazards, or access controls that can be bypassed through operational practices. While individually manageable, these conditions can collectively increase operational and cybersecurity risk.

    Establish a Resilient Physical Security Framework for OT Facilities

    For a critical OT-supporting pipeline facility, “good” does not mean eliminating all risk. It means reducing the likelihood that a physical or environmental issue will disrupt operation or impair recovery. TSA’s Pipeline Security Guidelines describe a risk-based approach in which operators apply baseline and enhanced security measures, perform periodic assessments, and maintain physical security and access control measures appropriate to the criticality of the facility. API Standard 1164 similarly emphasizes protecting control-system environments and maintaining resiliency.

    In practical terms, a strong target state for a facility includes clear separation of critical OT spaces from shared or general-access areas through effective barriers and access controls. Access is limited, deliberate, and attributable rather than informal or easily bypassed. Physical access is monitored to support deterrence and timely response.

    A mature environment also protects critical systems from non-intrusion threats such as water exposure, power-related disruption, and other physical or environmental conditions that could impair equipment or continuity. Monitoring is not treated as a passive control; it is paired with defined processes and personnel capable of acting on alerts in real time. This is particularly important where cameras and alerting tools have been added as part of remediation.

    For facilities serving a DR or continuity function, “good” further means that the site can perform its intended role during stress conditions. That requires minimizing unnecessary dependencies on the primary environment, reducing common-mode failure risks, and ensuring communications resilience, including independent connectivity where appropriate. In this context, physical security becomes a critical enabler of recovery performance, not just a protective control.

    Finally, good security posture is visible in governance as well as hardware. The operator can explain how the site was assessed, what criticality assumptions were used, which vulnerabilities were prioritized, what improvements were made, and how the controls will be maintained, reviewed, and tested over time. That is the point at which physical security becomes not just a collection of protective devices, but a credible resilience capability aligned with both regulatory expectations and operational needs.

    PRIORITIZING IMPROVEMENTS FOR MAXIMUM RISK REDUCTION

    Most facilities contain dozens of improvement opportunities but only limited resources. Treating every finding equally can divert attention from vulnerabilities that could create the most significant operational consequences.

    LSC helps operators prioritize remediation efforts by evaluating:

    :

    • Potential operational impact
    • Consequence severity
    • Recovery implications
    • Likelihood of occurrence
    • Implementation complexity and cost

    This risk-based approach enables organizations to focus resources on the improvements that deliver the greatest reduction in risk while supporting operational objectives and budget constraints.

    STRENGTHEN OT RESILIENCE THROUGH ACTIONABLE NEXT STEPS

    Physical security in OT environments is not just about preventing unauthorized entry, it is about reducing the likelihood that a facility weakness will escalate into an operational, safety, environmental, or public-impact event. In oil and gas pipeline operations, critical systems often support functions whose failure can affect employees, contractors, and the broader community. Unauthorized access, equipment tampering, or damage to critical OT assets can lead to operational disruption, safety incidents, environmental consequences, and costly recovery efforts. For that reason, physical hardening and environmental risk reduction should be considered essential parts of OT resilience.

    The addition of continuously staffed monitoring further demonstrates how relatively simple improvements can materially improve both detection capability and response readiness. Enhancements such as strengthened access controls, improved monitoring, and environmental safeguards provide layered protection that helps prevent minor vulnerabilities from becoming significant operational events.

    For many operators, the next step is to perform a structured physical security assessment of critical or high-risk OT facilities, establish a prioritized remediation roadmap, and integrate monitoring and resiliency improvements into ongoing operational planning. Because facilities often contain numerous improvement opportunities, prioritization is essential to focus resources on the vulnerabilities that present the greatest operational, cybersecurity, safety, or environmental risk.

    A structured physical security assessment provides operators with a clear, prioritized roadmap to strengthen OT facility resilience. By integrating physical security, cybersecurity, operational continuity, and recovery considerations into a single risk-based evaluation, operators can focus resources where they will have the greatest impact. This type of review also supports broader alignment with evolving federal pipeline security expectations.

    LSC helps clients identify where physical and environmental weaknesses create unnecessary operational risk and implement practical improvements that strengthen protection without disrupting field operations. Drawing on experience across OT cybersecurity, industrial control systems, pipeline engineering, integrity management, corrosion control, and operational risk management, LSC evaluates physical security through the lens of pipeline operations and OT resiliency. This approach helps organizations connect security findings to real-world operational consequences, prioritize improvements, and achieve a practical target state in which critical OT facilities are layered, monitored, resilient, and capable of supporting continuity when needed most.