Somewhere in your company there is a screen showing tank levels, line pressure, or flow rates — and behind that screen, a chain of equipment the office rarely thinks about: the HMI software, the radios, the flow computers, the panels your automation vendor wired. Meanwhile, the news keeps carrying stories about cyberattacks on energy companies. If you own or run a small operator, a midstream company, or an energy services firm around Tulsa, the question lands on your desk in a specific form: are we exposed, and whose job is it to fix? This guide answers both.
Who this guide is for
Owners and operations leaders of oil & gas companies with roughly 10 to 100 people — small operators, midstream companies, and energy services firms. It is not written for enterprise SCADA engineers with a security team down the hall. It is written for the person responsible for the whole company — the one who signs the cyber-insurance application.
What do OT and ICS mean in a company your size?
The acronyms sound bigger than they are. OT — operational technology — is hardware and software that monitors or controls physical equipment. ICS — industrial control systems — is the family of systems doing the controlling. In a company your size, that usually means:
- SCADA and HMI screens — often a single aging Windows PC, in the office or at a site, running the software that watches wells, tanks, compressors, or pump stations.
- Measurement and flow computers — the devices producing the custody-transfer and allocation numbers your revenue runs on.
- PLCs and RTUs at field sites — small controllers that open valves, start pumps, and trip shutdowns.
- The telemetry path — radios, cellular modems, and whatever else carries field data back to town.
- The automation vendor’s laptop — which plugs into all of the above, and into other companies’ systems too.
If any of that sounds familiar, you have OT, whether or not anyone in the building uses the word.
How attackers actually reach OT — through the office
Almost nobody attacks a flow computer from the internet. The realistic path into a small energy company’s operational systems runs through the office, because the office is what is exposed — and attacking it is what criminals have industrialized:
- A phished inbox. Someone in the office clicks a convincing email and types a password. The attacker now has a foothold — no field equipment involved yet.
- A flat network. If the office computers, the SCADA PC, and the field radios all sit on one network with nothing between them, whatever lands on any office machine can see the controllers too.
- A remote-access shortcut. A consumer remote tool — a TeamViewer install or similar — was put on the SCADA PC years ago so someone could check it from home. It still works, it is rarely patched or logged, and nobody owns it.
- Shared credentials. The same admin password on the office machines and the HMI box means one stolen password opens both worlds.
This is why CISA and other public reporting have long described energy as a repeatedly targeted sector, and why CISA’s guidance for industrial control systems keeps returning to one theme: separate operational systems from office IT and control what crosses. Be clear-eyed about the other half of the risk, too — an attack that never touches a valve can still stop the business. Ransomware on the office network alone can freeze measurement data, the month-end close, and owner payments.
The practical defense for a 10–100 person energy company
None of this requires an enterprise security program. It comes down to six pieces of work, in roughly this order, each with a named owner.
1. Segment office IT from OT — and write the boundary down
Put a firewall boundary between the office network and everything that touches control or measurement, so a compromised office computer cannot reach a controller. Where data must cross — telemetry flowing from the field into office systems — make the path deliberate: through the firewall, ideally one-way and monitored, instead of “everything can see everything.” Then document it: a drawing that shows what sits on which side and exactly what crosses, agreed with your automation vendor. A boundary that lives in one person’s head is not a boundary — and this separation is achievable at small-company scale with business-grade equipment.
2. Inventory every OT-touching device — including the old Windows box
You cannot protect equipment you do not know exists. List every device on the control and measurement side — the SCADA PC, flow computers, PLCs, RTUs, radios, modems — and who supports each one. The list will almost certainly include an aging Windows machine running the HMI on a version the software vendor will not support upgrading. That is normal, and the honest response is not to pretend it will be replaced next year. Isolate it — its own segment, no reach beyond what it needs, no browsing or email on it — and write it down. A legacy machine that is known and isolated is a managed risk. The same machine sitting quietly on the office network is how companies get encrypted.
3. Control remote access — especially your vendors’
Your automation vendor genuinely needs remote access; that is how a small company gets specialist support. The question is the path. Vendor access should run through a managed, logged route with multi-factor authentication — enabled when needed, recorded when used — not a standing consumer remote tool on the SCADA PC. The same standard applies to your own people checking systems from home. Unmanaged remote access kept for convenience, with no MFA and no log, is precisely what attackers scan the internet for.
4. Protect the IT side properly — it is the actual front door
Because the realistic attack path starts in the office, office-grade security is OT defense. Multi-factor authentication on email, remote access, and admin accounts. Endpoint detection and response — not just antivirus — on every computer. Email security that catches phishing before people have to. Patching on a schedule, with someone confirming it happened. These controls — the core of cybersecurity services sized for companies without a security department — stop the phish-first chain before it starts moving toward the field. They are also what cyber-insurance carriers now ask about by name.
5. Back up as if the close depends on it — because it does
Tested backups are what turn a ransomware event from a negotiation into an interruption. Back up the systems the office runs on — land, production accounting, well files, Microsoft 365 — with at least one copy that ransomware on your network cannot reach, and test restores on a calendar instead of assuming. Schedule that work, like all maintenance, around month-end close rather than during it. And where your vendors allow it, keep exported configurations for field devices — flow computer setups, PLC programs — stored safely on the office side, so a failed or compromised device can be rebuilt instead of reverse-engineered.
6. Write the incident plan that names your automation vendor
One page is enough. Who gets called and in what order — your IT partner, your automation vendor, your insurer, your attorney. What gets disconnected first, and who is authorized to say so. And the question that separates a bad day from a crisis: can we operate manually, and for how long? If the SCADA screen goes dark, can pumpers read gauges and write paper tickets — for a day? A week? Settle that in a calm month, with your automation vendor in the room. Our guide to the first 24 hours after a cyberattack covers what the plan gets used for when the day comes.
Who owns what — the honest answer
There is a clean division of labor here, and it is worth insisting on. An IT partner runs the office side — computers, servers, email, connectivity, backups — and owns the network boundary that separates office from operations, documented and coordinated with your automation vendor. Your automation and measurement vendors run the control systems themselves — the SCADA software, HMIs, PLC and RTU programming, flow computer configurations. Neither should pretend to do the other’s job, and the two must coordinate at the boundary, because that is where both problems and attackers cross. That is the stance NSN Management takes with oil & gas companies in Tulsa: we run the IT side, we hold the line, and we work with your automation vendor at it.
| System or task | Who owns it |
|---|---|
| Office computers, servers, Microsoft 365, email, phones | Your IT partner |
| Network design, segmentation, and the documented IT/OT boundary | Your IT partner, coordinated with the automation vendor |
| SCADA software, HMIs, PLC and RTU programming | Your automation vendor, with your operations team |
| Measurement and flow computer configuration | Your measurement or automation vendor |
| The managed, logged remote-access path vendors use | Your IT partner provides and monitors it; vendors use it |
| Backups of office systems — and exported device configs where vendors allow | Your IT partner |
| The incident plan and the decision to operate manually | Leadership, with the IT partner and automation vendor named in it |
What this looks like in Tulsa
Tulsa has enough energy companies that none of this should be exotic to your IT partner. NSN Management has been Tulsa-owned since 2012 and works with operators, midstream companies, and energy services firms as the IT team for the office side of the business — and a careful neighbor to the operational side: segmentation designed and documented, vendor remote access managed, backups tested around the close, and the automation vendor’s number written into the plan.
If you cannot say today where the line between your office network and your control systems runs — or who could cross it — that is the place to start, and it is a conversation before it is a project — book a Discovery Call with NSN Management and we will walk your network, your remote access, and your backups — and show you exactly where the boundary stands.
Questions Tulsa businesses ask about this
What is the difference between IT and OT?
IT (information technology) runs information: computers, servers, email, and business systems like land and production accounting. OT (operational technology) monitors and controls physical equipment: SCADA and HMI software, PLCs, RTUs, and measurement devices such as flow computers. ICS (industrial control systems) is the umbrella term for the control side. The two fail differently, are supported by different vendors, and should be separated by a documented network boundary.
Can our IT company manage our SCADA system?
No — and that is the right answer. SCADA software, HMIs, and PLC or RTU programming belong to your automation and measurement vendors. What a good IT partner owns is the office side and the network boundary between the two: the segmentation that keeps an office infection away from controllers, the managed remote-access path your vendors use, and the coordination with your automation vendor when something crosses the line.
Do small operators really get targeted?
Yes. CISA and other public reporting have long identified energy as a repeatedly targeted sector, and most attacks are automated — criminals phish and scan for exposed remote access at scale, then see what they have caught. A small operator with a flat network and a standing remote tool on the SCADA PC is an easier target than a major, not a smaller one. And an attack that never reaches OT can still freeze measurement data, the close, and owner payments.
Do we have to replace the old Windows PC running our HMI?
Often you cannot — the software may only run there, and the automation vendor controls the upgrade path. The realistic answer is to isolate and document it: its own network segment, no reach to anything it does not need, no email or browsing on it, and a written plan for eventual replacement. Known and isolated, it is a managed risk; sitting on the office network, it is an incident waiting to happen.
Where do we start?
With visibility. Inventory every device that touches OT, map whether the office network can reach field controllers, and list every remote-access path into your systems — including your vendors’. Then work in order: segmentation, remote-access control, IT-side hardening with MFA and endpoint detection and response, and tested backups. A Discovery Call with NSN Management walks through exactly this.