Oil & Gas
Protect pipeline SCADA and upstream operations from Triton-scale threats
Triton/Trisis, Industroyer2, and the Colonial Pipeline ransomware attack demonstrated that oil and gas critical infrastructure faces sophisticated, consequences-maximising attackers. ManySignal monitors OT networks, SCADA access, and IT/OT boundaries — with TSA Security Directive compliance built in.
$4.5M
Colonial Pipeline ransom — and $5B in economic disruption
12 hrs
TSA Security Directive incident notification window to CISA
Triton
First malware targeting safety instrumented systems — petrochemical plant
SD-02E
TSA directive mandating cybersecurity plans for critical pipelines
How ManySignal protects oil and gas operations
Pipeline SCADA and control system monitoring
Oil and gas SCADA systems controlling pipeline compression, valve operations, and custody transfer points are regulated by TSA Security Directives. ManySignal integrates with OT security platforms monitoring DCS, PLC, and RTU communications on Modbus, DNP3, and OPC-UA protocols — correlating control system anomalies with IT identity and network events.
- Abnormal remote access to pipeline SCADA systems
- TSA Security Directive SD-02E control monitoring
- Custody transfer system integrity monitoring
Pipeline SCADA and control system monitoring
Upstream operational data and reservoir model protection
Seismic survey data, reservoir simulation models, and field production data are high-value assets targeted by competitor intelligence operations and nation-state actors. ManySignal monitors access to seismic interpretation platforms (Petrel, Kingdom), reservoir simulation tools (Eclipse, CMG), and production databases — detecting bulk access and exfiltration attempts.
- Petrel and Kingdom seismic data access baselining
- Reservoir model bulk export anomaly detection
- Contractor access to asset-specific exploration data
Upstream operational data and reservoir model protection
Offshore and remote operations monitoring
Offshore platforms and remote production facilities connect to onshore operations via satellite and MPLS links with limited bandwidth and high latency. ManySignal's detection engine operates in edge-deployment mode at remote sites, with event correlation and escalation to the onshore SOC. It detects unauthorised remote access to Distributed Control Systems (DCS) and vessel management systems.
- Remote site edge deployment with onshore SOC escalation
- Satellite link anomaly detection — unusual traffic to operational systems
- Vessel management system access monitoring for offshore assets
Offshore and remote operations monitoring
Standards and regulations supported
Oil and gas security — common questions
How does ManySignal support TSA Security Directive compliance for pipeline operators?
ManySignal addresses TSA SD-02D and SD-02E requirements for critical pipeline and LNG facility operators: network segmentation monitoring (detecting connections across OT/IT boundaries), access control monitoring for OT systems (privileged access to SCADA from IT networks), and incident reporting (the 12-hour notification requirement to CISA for confirmed or potential cyberattacks). Evidence packages are formatted for TSA assessment reviews.
Can ManySignal monitor Honeywell, Emerson, or Yokogawa DCS systems?
ManySignal monitors DCS environments via integration with the OT security platforms that operate passively on DCS networks — Claroty, Nozomi, and Dragos all support Honeywell Experion, Emerson DeltaV, and Yokogawa CENTUM. ManySignal ingests structured telemetry from these platforms and correlates control system events with IT identity events in the entity graph. No agents are deployed on DCS hardware.
How does ManySignal address the Triton/Trisis malware threat against safety systems?
Triton targeted Safety Instrumented Systems (SIS) — specifically Schneider Electric Triconex — by manipulating safety controllers to disable safety shutdowns. ManySignal detects Triton-related indicators: unusual communication between engineering workstations and SIS hardware, Triconex proprietary protocol anomalies, and lateral movement from IT networks toward safety system segments. Detection is based on the TTPs documented in CISA ICS Advisory ICSA-18-240-01.
Does ManySignal integrate with Honeywell Forge or Emerson's operational technology platforms?
ManySignal can ingest security events from Honeywell Forge Security, Emerson's Plantweb Digital Ecosystem, and Yokogawa's OpreX security offerings via their syslog or REST API log outputs. This allows integration with plant-specific security tooling while consolidating alerts in ManySignal for correlation with IT events and centralised SOC response.
How does ManySignal support monitoring for LNG facilities under FERC jurisdiction?
FERC's Critical Infrastructure Protection (CIP) standards for LNG facilities under 18 CFR Part 380 require cybersecurity programmes covering access controls and incident response. ManySignal provides continuous monitoring evidence aligned to FERC's cybersecurity assessment framework, and supports the incident reporting requirements to CISA and FERC applicable to LNG facility operators.
See OT/SCADA monitoring in action
Walk through pipeline SCADA anomaly detection, TSA Security Directive evidence collection, and Triton-pattern hunting — in one session with our OT security team.