Operational Technology environments at Permian Basin upstream and midstream operators are a top-tier target for nation-state and criminal actors. The 2026 baseline is IT/OT segmentation, OT-specific monitoring, and TSA Security Directive compliance.
Operational Technology (OT) environments at Permian Basin upstream production sites, midstream gathering and processing facilities, and pipeline operators are now a top-tier target for both nation-state actors and ransomware crews. The Colonial Pipeline incident in 2021 was a forcing function — the TSA Pipeline Security Directives that followed have evolved into a binding regulatory regime that affects nearly every operator handling oil, natural gas, or refined products in West Texas.
This guide is for VPs of IT, Operations Technology managers, and CFOs at Permian Basin operators in the 50–500 employee range — a segment that is large enough to be a target, but small enough that a dedicated OT security team is not realistic.
OT — Operational Technology — refers to the industrial control systems that physically operate equipment in the field. SCADA systems controlling wellheads and tank batteries, PLCs running compressor stations, RTUs at pipeline measurement points, HMI workstations in control rooms. Unlike IT environments, OT environments have:
From our engagement work and from public threat reporting, the threat actors targeting West Texas energy infrastructure cluster into three categories:
The Purdue Reference Architecture defines layers from physical equipment (Level 0) up to enterprise IT (Level 4-5). The single most important OT security control is enforcing the boundary between Level 3 (operations) and Level 4 (enterprise IT) with hardware firewalls that allow only specific, known-good traffic. No flat networks. No domain controllers shared between IT and OT. Engineering workstations do not browse the public internet.
You cannot defend what you do not know exists. OT-specific monitoring platforms (Claroty, Dragos, Nozomi, Armis) passively listen to industrial protocols and produce an asset inventory and behavioral baseline. Anomalies — a workstation suddenly speaking to a PLC it has never communicated with before, a firmware version change on a controller, a new device appearing on the OT VLAN — generate alerts. This is not optional in 2026 for any operator subject to TSA Security Directives.
Engineering workstations and HMI terminals are the highest-value pivot point an attacker can land on inside an OT environment. They warrant PAM-grade controls: application allowlisting that prevents any binary outside the approved engineering toolchain from executing, ringfencing that prevents the engineering software from making outbound network connections, and storage controls that prevent USB exfiltration of project files.
OEM vendors (Schneider, Honeywell, Emerson, ABB) routinely require remote access to maintain their installed equipment. These vendor remote access paths are a documented top-three intrusion vector for OT environments. Replace any persistent vendor VPN access with on-demand jump host access through a privileged access workstation, with session recording, MFA, and time-bounded approval.
PLC programs, HMI projects, RTU configurations, and SCADA databases are all engineering intellectual property — and an attacker who corrupts or deletes them can put production offline for weeks. Apply the 3-2-1-1-0 backup rule to engineering configuration the same way you would to corporate finance data.
The TSA Pipeline Security Directives — most recently SD02C and the supplementary directives that have followed — establish binding cybersecurity requirements for owners and operators of TSA-designated pipeline systems. Key requirements include implementing a TSA-approved Cybersecurity Implementation Plan, conducting an annual Cybersecurity Assessment Plan, maintaining IT and OT network segmentation, and reporting cybersecurity incidents to CISA within 12 hours.
For Permian midstream operators, TSA compliance is not optional. The compliance posture also serves as an effective baseline for upstream operators who are not directly TSA-regulated but who supply TSA-regulated infrastructure.
While our headquarters are in Houston, we work with energy operators across the Texas energy ecosystem:
For the corporate IT side of an upstream/midstream operator: see Houston managed IT services. For broader cybersecurity context: cybersecurity services overview and the 2026 Texas SMB Benchmark Report.
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.