Offshore environments present unique security risks
Offshore energy infrastructure faces escalating cyber and physical security risks as digital integration exposes operational systems to increasingly sophisticated threats. Modern platforms combining IT, OT, and remote operations create expanded attack surfaces that adversaries exploit for persistent access, disruption, and strategic leverage.
Analysis of maritime incidents shows a shift toward state-linked and organized criminal actors targeting critical infrastructure through ransomware, navigation interference, supply chain compromise, and remote access vulnerabilities. Limited connectivity and legacy systems further complicate defense.
The findings underscore the need for integrated, cyber-physical security frameworks, emphasizing resilience, localized detection, and engineering-driven approaches to safeguard offshore operations.
Offshore vulnerabilities
Offshore platforms exist in strategically valuable, geographically isolated, and often politically sensitive regions, making them attractive targets for both financially motivated cybercriminals and state-sponsored actors. Unlike conventional cyber threats designed for immediate disruption or financial gain, many modern offshore attacks emphasize persistence, stealth, and long-term access. Attackers increasingly seek to establish footholds within offshore control systems, allowing them to gather intelligence, maintain leverage, or execute disruption at a later stage.
Modern offshore operations require complex cyber-physical environments which integrate information technology (IT), operational technology (OT), and human operators. IT connects industrial control systems (ICS) and supervisory control and data acquisition (SCADA) networks. Converging these systems, along with technologies such as low-cost sensing, the industrial internet of things (IIoT), machine learning, artificial intelligence (ML/AI), digital twin technologies, and cloud computing, significantly expands potential attack opportunities and introduces new vulnerabilities.
Historically, OT environments were designed for reliability, availability, and safety rather than security. These systems often operated in isolation with limited exposure to cyber threats. Over the last decade, however, digital transformation has increasingly interconnected OT and IT networks, enabling remote monitoring, centralized control, and data analytics. For example, modern platforms, such as Shell PLC’s Vito and its descendants, have been specifically designed to run remotely from shore, with Whale becoming the company’s first deepwater platform to be started from a control room on land (OGJ, Feb. 16, 2023; OGJ, Aug. 7, 2023; OGJ, Jan. 9, 2025).
A major risk arises when improperly secured remote access pathways, such as VPNs and remote desktop protocols, allow cyber adversaries to infiltrate IT networks and move laterally into OT environments. Once inside, attackers can target critical components such as programmable logic controllers (PLCs) and distributed control systems (DCS), potentially causing severe operational disruption, safety hazards, or manipulation of physical processes. Traditional perimeter defenses, such as firewalls, are no longer sufficient in such integrated architectures. Instead, security controls must be embedded within the OT environment to detect and prevent lateral movement following an initial breach.
Offshore installations suffer from limited, intermittent, and low-bandwidth communications which are often reliant on satellite or microwave links. This poor connectivity hinders the ability to deploy conventional IT-centric cybersecurity solutions and requires local protection strategies which reduce reliance on centralized monitoring or cloud-based analytics. Harsh marine conditions also negatively affect hardware reliability and incident response times.
The limitations of these systems increase attack opportunities and create pathways for cascading failures. For example, a cyber intrusion can propagate into physical disruptions affecting safety-critical systems such as dynamic positioning, rotating machinery, or subsea infrastructure.
Threat landscape
Four primary categories of cyber threats affect offshore installations. The first involves navigation system interference, such as global navigation satellite system (GNSS) and automatic identification system (AIS) jamming or spoofing. These attacks manipulate vessel positioning or identity data, which can be used for sanctions evasion or to create navigational hazards, including collision risks.
Ransomware comprises the second major threat and typically originates in corporate IT environments through phishing campaigns, compromised credentials, or exploitation of exposed services. Once inside, lateral moves into OT systems cause operational disruption while simultaneously exfiltrating sensitive data for extortion.
Remote access pathways provide a third key vulnerability. Offshore operations depend heavily on remote connectivity for maintenance, vendor support, and operational oversight. Weak authentication, poor segmentation, or insufficient monitoring of these channels can provide attackers with trusted entry points into critical systems. Once inside, attackers may gain persistence and move laterally across both IT and OT environments.
Supply-chain exploitation comprises the fourth threat. In this scenario, attackers compromise trusted third-party vendors or service providers, using legitimate access channels to bypass perimeter defenses. Recent incidents demonstrate that adversaries increasingly target these access points deliberately, rather than exploiting them opportunistically.
Offshore threat analysis
To better understand offshore-specific threats, a curated dataset comprising significant maritime and offshore security incidents from 2000 through 2026 focused on human access control, equipment handling, navigation systems, and operational performance across sensitive physical and cyber domains (Fig. 1).
Volume of offshore attacks, 2000-2025 (Fig. 1)
Data were collected from multiple open-source reporting platforms and rigorously validated through a multi-step process that removed duplicates, excluded non-malicious events such as weather-related incidents, and filtered out low-impact or unsuccessful incidents. This approach prioritized data quality and ensured that only consequential events were included in the analysis. The dataset incorporated incidents involving both internal personnel and external actors, including contractors and supply-chain participants who require high-level access without high-level background screening.
The research also assessed how existing US regulatory and legislative frameworks support, constrain, or fail to meet modern access-management and operational-security concerns. The study generated original datasets and actionable insights that bridge cyber and physical security considerations with governance and policy gaps.
The findings revealed a significant shift in both the nature of threats and the actors behind them. Between 2025 and 2026, the leading causes of incidents were linked to the rapid and often unsecured integration of IT and OT systems, compounded by rising geopolitical tensions. Key cyber threats included ransomware, GPS spoofing and jamming, and physical disruptions from so-called "dark fleets" comprised of an armada of hundreds of shadow vessels using deceptive tactics to jam and spoof GNSS signals. Moreover, while these threats were external, human error remains the primary vulnerability, as the infrastructure was unable to defend itself.
A large proportion of recent cyber and physical attacks came from organized criminal entities targeting operational continuity and critical infrastructure rather than small-scale opportunistic actors looking to only extract data.
Cyberattacks accounted for about 62% of maritime security incidents, with ransomware comprising about 33% of all cyber methods (Figs. 2-3). Physical security attacks comprised 40.7%, with anchor dragging being the predominant method (18.6%) and explosives (10.2%) second. Drones comprised 5.1% of assaults, indicating the rise of autonomous threats in maritime combat.
Offshore physical-, cyber-attack distribution (Fig. 2)
Attack types (Fig. 3)
The study highlighted a major transition in the threat landscape: state and state-sponsored actors became the dominant source of maritime security incidents, accounting for about 38% of cases (Fig. 4). This figure might be understated due to lack of clear attribution, as many incidents involved unidentified perpetrators suspected of ties to nation-state entities.
Cybercriminal organizations represented the second-largest group at 27%, primarily motivated by financial gain. Non-state militant groups and hacktivists accounted for 17%, while traditional piracy had declined to just 2%. Other actors were transnational criminal organizations (5%). A significant portion of incidents (more than 11%) remain under investigation, and most are suspected to involve state-linked sabotage.
Attack actors (Fig. 4)
Traditional maritime crime, such as piracy and commercial sabotage, has substantially shifted towards state-associated and hybrid cyber-physical threats aimed at critical infrastructure. The operational scope of threats has expanded from purely physical attacks to integrated cyber–physical campaigns that exploit blurred boundaries between systems.
Target selection has also evolved. Of the documented incidents, commercial maritime and logistics assets accounted for 35.6% of targets, while critical infrastructure—particularly subsea cables and pipelines—accounted for 27.1%. Attacks focusing on digital and IT systems comprised 15.3%, and military or government assets represented 11.9%. Fig. 5 breaks down targets in detail.
Attack targets (Fig. 5)
Human factors also represent a critical vulnerability. Insider threats, whether intentional or accidental, are a major source of risk. Survey data indicated that 59% of vulnerabilities are linked to low employee awareness, while 67% involved the use of portable USB devices, highlighting the importance of training and strict device control policies.
Recent attacks place maritime infrastructure in an ambiguous position where coercive actions deliberately fall below the threshold of conventional warfare while achieving strategic objectives. Adversarial nation-states, whether acting directly or through intermediaries, now comprise a substantial proportion of attacks. Such tactics rely on ambiguity and deniability, complicating attribution and inhibiting an armed response. Under these conditions, traditional deterrence frameworks and legal mechanisms are often ineffective.
New security paradigm needed
Traditional perimeter-based security models are no longer adequate. Existing regulatory structures, such as the transportation worker identification credential (TWIC) program and maritime security (MARSEC) levels, provide a baseline but are often fragmented and insufficiently aligned with modern operational realities. Emerging principles such as zero trust architecture offer promise but require more cohesive implementation across maritime systems.
Cyber and physical risks must be treated as a unified problem with integrated frameworks which reflect interdependencies between information systems, operational technology, and physical assets in ports, offshore installations, and subsea infrastructure. Policy and regulatory structures should no longer treat cyber and physical security as separate domains and should be updated to account for hybrid threats.
New frameworks need to address legal and regulatory gaps in cyber-enabled, subthreshold attacks on maritime infrastructure. These policy developments will require coordination at national and international levels.
Existing international laws, including those under the United Nations Convention on the Law of the Sea (UNCLOS), are not well-suited to handling cyber-enabled or ambiguous acts of sabotage. Improved mechanisms for attribution, intelligence sharing, and coordinated response are necessary to reduce the strategic advantage held by adversarial actors.
In response to these risks, structured cybersecurity frameworks, such as the International Society of Automation (ISA)/International Electrotechnical Commission (IEC) ISA/IEC 62443-4-1 “Security for industrial automation and control systems,” provide guidance for incorporating cybersecurity into the lifecycle of industrial systems, from development through deployment and eventual retirement. This standard and others like it encourage organizations to adopt consistent, well-vetted practices rather than ad hoc security measures.
Cyber-Informed Engineering
Cyber-informed engineering (CIE) provides a holistic level of protection by shifting away from the traditional view of cybersecurity as a purely technical or compliance-driven function. It integrates threat awareness and consequence analysis directly into system design and operational decision-making.
This approach requires collaboration between cybersecurity professionals and engineering teams who traditionally operate in separate IT and safety, reliability, and performance silos, respectively. By focusing on operational, safety, and environmental consequences of cyber threats, CIE establishes a shared framework for evaluating risk.
Using these principles, a unified OT management layer, for example, can provide additional monitoring capability by accessing network topology, device identity, firmware versions, and communication patterns. This visibility helps operators detect anomalies, identify unauthorized connections, and maintain accurate asset inventories despite intermittent connectivity.
Configuration governance forms another key pillar of deterrence by establishing secure baselines for devices, controllers, and network components. Many advanced threats operate by making subtle configuration adjustments that enable persistence or weaken defenses without immediately disrupting operations. Automated comparisons of current system-states against trusted baselines enables early detection of such changes. In offshore environments, where response times may be delayed by logistics or weather conditions, early detection is especially critical to prevent escalation.
Secure network segmentation
Offshore environments require segmentation strategies to account for limited bandwidth, high latency, and intermittent links. These limitations challenge effective solutions that over-rely on external connections.
Traditional segmentation, which depends heavily on centralized control or external connectivity, may not function effectively in high-latency, low-bandwidth environments. Under these conditions, by the time an intrusion is detected, an attacker may have already moved laterally within the system to strike elsewhere.
For offshore, therefore, segmentation enforcement must occur locally, close to the protected assets. Techniques such as micro-segmentation, combined with deep packet inspection and firewall rules, help isolate critical systems to prevent lateral movements.
Unsecured remote access by maintenance, vendor support, and operational teams to perform different activities provides another critical path for attack. Best practices include strong authentication mechanisms, encrypted communication channels, least-privilege access controls, and continuous session monitoring. Additionally, the use of jump servers in demilitarized zones (DMZs) mediates and secures access between external users and internal systems.
These controls must be designed to operate reliably even under degraded network conditions, ensuring consistent protection regardless of connectivity limitations. Defense in depth—layering multiple security controls to create redundancy and resilience—provides the most effective counter to cyber-attacks. This principle is a pillar of ISA/IEC 62443 (Fig. 6).
ISA/IEC 62443 Security zones, conduits (Fig. 6)
Edge-based detection
Given the limitations of offshore connectivity, edge-based detection provides more reliable monitoring than centralized monitoring systems. Edge-based systems analyze network traffic, industrial protocols, and device behavior locally, enabling faster detection of anomalies and reducing dependence on high-bandwidth data transmission.
Localized analysis improves response times, which is critical in safety-sensitive environments where delays can lead to cascading failures. While advanced AI-driven detection models show potential, their complexity and resource requirements may limit their practicality offshore. In many cases, simpler signature-based or rule-based systems, combined with strong segmentation and access controls, provide reliable protection when combined with strong segmentation and access controls.
Zero-day threats
Zero-day vulnerabilities—previously unknown flaws in software or hardware that lack patches or detection signatures—are immune to traditional security tools such as signature-based detection systems and compliance-driven controls. In OT environments, this problem is particularly acute because many systems cannot be easily patched or restarted without disrupting critical operations. As a result, zero-day exploits can persist undetected and only become apparent when they cause operational anomalies.
Results of recent cyberattacks revealed the vulnerability of SCADA servers, safety instrumented systems (SIS), and smart metering infrastructure. These assets typically have high availability requirements and limited tolerance for downtime, making proactive remediation difficult. Furthermore, many OT environments rely on legacy equipment, proprietary protocols, and long asset lifecycles, all of which complicate vulnerability management and limit the applicability of IT-centric cybersecurity models.
Cyber adversaries are shifting from data theft to operational disruption. Attackers are increasingly targeting OT-specific components such as human-machine interfaces (HMIs), PLCs, and safety systems, indicating an intent to affect physical processes rather than just digital assets. This evolution introduces the potential for real-world consequences, including infrastructure disruption, equipment damage, and safety incidents.
Three recent major cyber incidents illustrate these risks:
- In the Ukraine, a power-grid attack exploited unknown vulnerabilities and operator workflows to disrupt electricity supply. It marked the first confirmed cyber-induced power outages affecting civilian populations.
- In the US, a pipeline ransomware attack originated in an IT system and cascaded into OT disruptions, even without direct manipulation of control systems.
- In Saudi Arabia, a petrochemical cyber-attack targeted instrumented safety systems, potentially causing physical damage and loss of life.
These case studies collectively demonstrated that cyber incidents do not require direct physical manipulation to cause significant disruption. In some cases, uncertainty alone can lead operators to shut down systems as a precaution, resulting in substantial economic and social impacts.
Current cybersecurity standards, while valuable for establishing baseline controls, are insufficient to address zero-day risks (see table). These frameworks are largely designed around known threats and periodic assessments, rather than real-time detection of unknown exploits. This creates an imbalance in which attackers can exploit unknown weaknesses while defenders are constrained by operational limitations. A shift toward engineering-based resilience, enhanced monitoring capabilities, and adaptive response strategies better manages zero-day exposure and strengthens overall cyber resilience in energy operations.
Industry-Standard zero-day limitations (Table)
Holistic maritime security
Multidomain security strategies—such as security operations integration, cloud asset management, and continuous monitoring—have become essential for managing risk across geographically dispersed ports, vessels, offshore installations, and subsea infrastructure.
Attack preparedness and prevention require a layered security approach which includes continuous monitoring through advanced sensing technologies, AI-driven anomaly detection, and real-time maritime domain awareness systems.
Integration of unmanned physical systems, such as unmanned surface vessels (USVs) and unmanned aerial vehicles (UAVs), with cyber defense capabilities significantly enhances surveillance, response speed, and overall maritime security effectiveness. Some estimates suggest up to a 40% improvement in patrol efficiency using this approach.
DAS detection of underwater threats
As an example of technology to monitor both cyber and physical domains, distributed acoustic sensing (DAS) provides persistent underwater awareness by transforming fiber-optic cables into distributed sensor arrays. DAS can detect acoustic, thermal, vibration, and strain disturbances along subsea infrastructure, allowing it to identify threats such as unauthorized vessels, underwater vehicles, or anchor-drag events. By analyzing low-frequency acoustic signatures, the system can classify and localize potential intrusions with high precision.
DAS is complemented by IIoT systems that provide real-time operational data, including temperature, pressure, and flow rates. This contextual information enhances the system’s ability to interpret anomalies and distinguish between normal operation variances and potential threats.
The integration of these sensing platforms (DAS, specialized AUVsensors, IIoT telemetry) requires interoperability and data fusion at the edge, as offshore environments limit reliable long-distance communication due to poor radio-frequency propagation underwater. Critical threat classification and response orchestration, therefore, must be pushed to the local processing layer to avoid unacceptable latency in communications to and from a centralized shore processor.
Edge computing plays a key role in enabling local data processing and rapid decision-making. Machine learning and deep learning models deployed at the edge analyze data streams in real time, identifying anomalies and executing automated responses without relying on delayed communication with centralized systems. This allows for immediate actions such as network lockdowns, dispatching autonomous underwater vehicles (AUVs), or issuing platform-wide alerts.
The centralized cloud integration layer supports edge computing by performing computationally intensive tasks, such as model updates based on broader data patterns and centralized monitoring. This layered architecture balances the need for real-time responsiveness with centralized oversight and optimization.
Threat classification relies on correlated input from multiple data sources. For example, a combination of anomalous acoustic signals detected by DAS, irregular telemetry data from IIoT sensors, and suspicious network activity can indicate a coordinated sabotage attempt by an unauthorized underwater vehicle. The machine learning models running on the edge then execute an automated decision.
These autonomous actions—such as initiating a controlled network lockdown, immediately dispatching a high-precision AUV to the threat location, or triggering a general platform alert—occur without the delay of human intervention, fulfilling the core objective of the unified framework.
By matching multi-temporal data streams to objects using statistical association techniques, such a system can achieve up to 95-99% detection accuracy in maritime environments.
This piece was created with the assistance of generative AI tools and was edited by our content team for clarity and accuracy.
Bibliography
Burns, M., “Access Management and Operational Security in Critical Infrastructure: A Longitudinal Evaluation of Cyber and Physical Security Breaches in Marine Environments,” OTC-36839-MS, Offshore Technology Conference, Houston, Tex., May 4-7, 2026.
Elshahawi, E. and Hosam Abu Zeid,H.A., “Securing Offshore Ecosystems Against Cyber and Sabotage Threats,” OTC-36764-MS, Offshore Technology Conference, Houston, Tex., May 4-7, 2026.
Felipe Sabino Costa, F.S., “Cyber-Informed Security Architecture for Offshore Energy and Maritime OT Systems,” OTC-36860-MS, Offshore Technology Conference, Houston, Tex., May 4-7, 2026.
Hoxha, B.B., “Zero-Day Threat: The Silent Cyber War on Energy Infrastructure,” OTC-36928-MS, Offshore Technology Conference, Houston, Tex., May 4-7, 2026.
Pretlove, J., Royston, S., and Biringer, F., “Remote Operations for Autonomous Offshore Facilities: Design, Testing and Independent Validation of Secure and Robust Automation,” OTC-37012-MS, Offshore Technology Conference, Houston, Tex., May 4-7, 2026.
About the Author
Alex Procyk
Upstream Editor
Alex Procyk is Upstream Editor at Oil & Gas Journal. He has also served as a principal technical professional at Halliburton and as a completion engineer at ConocoPhillips. He holds a BS in chemistry (1987) from Kent State University and a PhD in chemistry (1992) from Carnegie Mellon University. He is a member of the Society of Petroleum Engineers (SPE).








