Then & Now: From Spindletop to cybersecurity, how oil and gas safety evolved

From blowouts and refinery explosions to ransomware and real-time monitoring, this podcast episode examines how the oil and gas industry's approach to safety has changed through the decades.

Key topics covered

  • Early drilling hazards.
  • The invention of the blowout preventer.
  • Offshore safety reform.
  • Process safety management.
  • Smart PPE and predictive maintenance.
  • Cybersecurity.
Listen on Apple buttonListen on Spotify buttonListen on iHeartRadio buttonListen on Podbean button

 

What began as an industry where workers relied on experience, instinct, and often sheer luck has evolved into one built on rigorous safety systems, risk management, and continuous improvement.

In this Then & Now episode of the Oil & Gas ReEnterprised podcast, host Laura Bell-Hammer traces the history of safety in oil and gas, from the uncontrolled Spindletop blowout of 1901 and the invention of the blowout preventer to the structured health, safety, security, and environmental programs that guide operations today.

Along the way, we examine the major events that reshaped the industry's approach to risk. From Piper Alpha and Texas City to Deepwater Horizon, each disaster exposed vulnerabilities that led to lasting changes in regulations, process safety management, offshore oversight, and industry standards. These lessons helped move safety beyond protecting equipment and toward protecting workers, communities, and critical infrastructure.

The episode also explores how technology is redefining safety and security in the modern energy sector. Smart PPE, predictive maintenance, real-time monitoring, and remote operations are helping identify risks before incidents occur. At the same time, growing digital connectivity has expanded the industry's focus to include cybersecurity, with events such as the Colonial Pipeline ransomware attack highlighting the connection between cyber threats and physical operations. As new risks emerge, the question remains: can the industry identify tomorrow's hazards before they become the next major lesson?

Transcript

Laura Bell-Hammer: Welcome back to Then & Now, a podcast series from Oil & Gas Journal ReEnterprised.

I am your host, Laura Bell-Hammer.

On January 10, 1901, a well outside Beaumont, Texas, blew out. The crew on site had no equipment designed to manage it and no real plan for what to do next. It took 9 days to bring the well under control using a valve arrangement crews improvised on site.

About 20 years later, a driller named James Abercrombie worked a well near Houston that blew out three separate times. That third failure is what led him and Harry Cameron on a path that would lead to one of the most important safety innovations in drilling. In those early years, progress was often driven by problems no one had anticipated and solutions no one had planned.

This episode explores how an industry built on that trial and error approach gradually developed the safety systems, standards, and practices that exist today.

For decades, safety was whatever the crew on site decided it needed to be. No department, no policy, no rulebook. Limited formal safety standards in a department dedicated to safety procedures were rare. Hazards were part of the job.

Today, safety reaches far beyond the well site or refinery floor, encompassing worker well-being, emergency preparedness, site security, process safety, and now cybersecurity.

So how did an industry with no safety framework end up governed by rigorous standards and procedures? The change came incrementally, shaped by lessons learned as new hazards emerged and operations grew more complex. Safety was up to the judgment of the crew, relying on experience, instinct, and often a fair amount of luck.

During the Black Gold Age, the industry grew fast and the danger grew with it. Workers understood the risk, but with the rush of the oil boom, they accepted the dangers as the price of opportunity. Deaths and injuries were common, and often they went undocumented.

There's an old line from the Boomtown days. You could measure a roughneck's experience by how many fingers he had left. It is the kind of joke that only works because it was true often enough. Injuries were so commonplace that they became part of the industry's culture and acceptance.

When safety measures were adopted, they were often to protect equipment rather than workers. A damaged rig could halt production and cost money immediately. Injured workers in an era of rapidly growing boom towns were easier to replace. Early safety improvements focused on preventing a specific failure from happening again. New equipment reduced risk and improved control and function.

It took something bigger to change how the industry thought about safety. The push for stronger safety standards did not emerge overnight. It developed over decades as accidents accumulated and the limits of voluntary safety measures became more apparent.

State legislators often stepped in first. Insurers began pricing risk into premiums, and eventually the federal government concluded that a more consistent approach was needed.

In 1970, Congress passed the Occupational Safety and Health Act, creating OSHA. OSHA gave the industry a baseline, but it took three disasters to show regulators exactly where the baseline fell short.

In 1988, a condensate gas leak on the Piper Alpha platform ignited, triggering a series of explosions and a fire that engulfed the platform in the North Sea and killed 167 people aboard. Investigators, led by Lord Cullen, traced the disaster to a permit to work system that had broken down in a shift handover where critical information about ongoing maintenance simply never made it to the crew.

The Cullen inquiry made recommendations that reshaped offshore safety, such as formal safety management systems, mandatory safety cases, and a permit-to-work process rebuilt around the exact failure that caused Piper Alpha.

Refining brought a different type of risk into focus, catching major process failures before they became catastrophic events. In 2005, an explosion at a Texas City refinery killed 15 workers and injured more than 170 during the startup of a process unit. Investigators from the U.S. Chemical Safety Board traced it to failures in process safety, hazard identification, operating procedures, and safety culture.

After Texas City, the CSB pushed the industry to look beyond personal injury rates and address the conditions that can lead to catastrophic process safety events. The investigations went beyond equipment failure. Investigators called for stronger process safety indicators and better management of change, including how companies handle staffing and budget decisions. They also highlighted the importance of mechanical integrity, engineered safeguards, fatigue prevention, and stronger OSHA oversight of high-hazard facilities.

Those suggestions led to the API Recommended Practice 754, which established standardized leading and lagging process safety indicators and gave companies a more consistent way to monitor conditions that could precede a major accident. It is still the industry's go-to for measuring process safety performance.

Each of these events exposed a different weakness in how the industry managed risk. And as exploration pushed farther offshore and into harsher environments, the next lesson would come from the wellhead itself.

In 2010, the Deepwater Horizon blowout killed 11 workers and caused the largest offshore oil spill in U.S. history. A surge of natural gas bypassed a flawed cement seal and the blowout preventer, a technology Abercrombie helped pioneer decades earlier failed to seal the well, highlighting the limits of even the industry's most trusted safety systems.

That systemic failure forced the industry into strict new regulations covering well integrity, third-party equipment testing, and continuous real-time monitoring. The response reached far beyond the well itself.

Deepwater Horizon prompted a re-examination of how offshore drilling was regulated, including whether one single agency, the Mineral Management Service, could responsibly oversee safety while also managing leasing and revenue collection. The government split the functions into three separate agencies with the Bureau of Safety and Environmental Enforcement, BSEE, taking offshore safety and environmental oversight specifically.

Most recently, in April 2026, the Department of the Interior announced a plan to consolidate BSEE and the Bureau of Ocean Energy Management into a new marine minerals administration aimed at streamlining offshore oversight under a single structure.

Piper Alpha, Texas City, and Deepwater Horizon demonstrate a recurring pattern into the industry's safety history. Each exposed vulnerabilities that had gone unaddressed, and each promoted changes in how risk is managed. Over time, those lessons were incorporated into the structured health, safety, security, and environment, or HSSE programs that guide operations today.

While HSE programs vary by company, most share the same objective: integrating worker safety, asset integrity, environmental protection, and security into a single risk management framework. The reasoning is straightforward. A weakness in one area can quickly affect the others.

Before a new worker ever picks up a tool, they go through structured onboarding that establishes safety and security expectations from day one. It is quite different from the learn-as-you-go approach that had defined much of the industry's early workforce training.

Training does not end after orientation.

Workers regularly renew certifications for high-risk tasks, and many companies maintain formal competency programs that track qualifications and ensure personnel are trained for the work they perform.

One of the biggest changes in the industry's approach to safety is the stop work authority, the right of any worker at any level to halt a task the moment something appears to be unsafe, without asking for permission first and without fear of retaliation.

The cultural change extends beyond equipment and procedures. Workers who were once expected to adapt to risk are now expected to challenge it. Changes in safety are evident not only in policies and training but also in the equipment workers use every day.

Traditional personal protective equipment such as hard hats, protective clothing, and steel-toed boots provided a passive layer of protection. Today's smart PPE goes further using sensors and wireless communications to monitor conditions and deliver real-time information to workers and supervisors. Wearable devices can monitor conditions such as gas concentrations, air quality, and temperature while also tracking indicators like heart rate and body temperature to help identify fatigue and heat stress. Smart helmets add GPS for location tracking, fall detection, and instant communication. Smart glasses allow technicians and supervisors to collaborate remotely during inspections, repairs, or training.

Together, these technologies provide real-time information that can help workers avoid hazards and respond more quickly when conditions develop.

Another change has been the industry's growing ability to identify and address risks before workers are exposed to them. Facilities monitor networks that track pressure, temperature, vibration, and equipment health in real time. Automated control and safety systems can respond in seconds, while predictive maintenance tools help operators address problems before equipment fails.

Together, these systems allow many tasks to be monitored and managed remotely, reducing the need for workers to be positioned near potentially hazardous equipment. But even the most advanced safeguards cannot eliminate risk entirely. Companies must also prepare to respond when an incident, natural disaster, or security threat occurs.

Companies regularly drill emergency response plans tailored to specific threats, recognizing that a hurricane, fire, or security threat may each require a different response. Operators may use formal incident management frameworks that bring site personnel, emergency responders, and outside agencies together under a common structure. Mass notification systems can alert an entire facility or region within seconds, helping ensure that everyone understands both the threat and their role responding to it.

Security responsibilities have expanded just as much as safety, covering the people and infrastructure within a facility, not just its perimeter. Modern sites rely on layered access control, surveillance systems, and continuous monitoring while preparing for threats that extend beyond traditional trespassing or vandalism. Insider threats, bomb threats, and active shooter incidents incorporate security planning, scenarios that would have received far less attention a generation ago.

The security no longer stops at the entrance gate or fence line. As industrial control systems become connected to broader networks, a new category of risk emerged. The systems that monitor and operate everything from wellheads to refinery units created new points of exposure, making cybersecurity an essential part of modern risk management.

Cyber security has become an industry-wide concern as oil and gas operations have become increasingly connected. The risk extends across the value chain. Cyber attacks affect the IT network through phishing, stolen credentials, or ransomware, and can disrupt business operations or expose sensitive information. Attacks on OT networks, the control systems used to monitor and operate industrial equipment and processes, can cause physical destruction, massive operational downtime, severe safety hazards, as well as financial loss.

The response has evolved from voluntary industry guidance in cybersecurity practices toward more structured risk management programs. Government agencies, along with many others, provide broader cybersecurity guidance for critical infrastructure in OT environments. The consequence of cyber attacks became particularly visible in 2021, when ransomware forced Colonial Pipeline to shut down its operations.

The attack targeted the company's IT network rather than its pipeline control systems, but the company halted its operations as a precaution, temporarily disrupting fuel deliveries across the Northeast. The incident demonstrated how closely IT systems and physical operations had become connected and how a cyber attack does not necessarily have to compromise industrial control systems to disrupt the movement of energy.

The Colonial incident prompted a regulatory response. The Transportation Security Administration issued the pipelines industry's mandatory cybersecurity requirements. The directive was focused on critical pipeline systems considered high risk due to national security or public safety. Operators were required to perform assessments on critical IT and OT systems, implementing local and remote access controls, network segmentation, as well as monitoring and detecting potential threats.

Since then, additional directives have been added, expanding the coverage to include all cybersecurity standards applied across the pipeline industry. Colonial was not an isolated event. Earlier attacks had already demonstrated the potential for malware to cause widespread disruption within an energy company.

In 2012, the Shamoon malware attack at Saudi Aramco infected thousands of workstations, providing an early example of the scale at which a cyber attack could affect a major oil producer.

Any company that relies on connected systems to operate, whether it is a major integrated producer or a smaller operator, faces the potential for a cyber incident to disrupt production, compromise critical systems, or create safety risk. The question is no longer whether a company is large enough to be a target, but whether it is prepared for what happens when a cyber incident reaches its operations.

For decades, many of the industry's biggest safety changes came after something went wrong. The question now is whether the industry can keep moving that learning process further upstream, identifying the next risk before it becomes the next major incident. Because if there's one thing that the history of safety and security in oil and gas shows, it's that the definition of what needs to be protected never stops changing.

That's it for today's Then & Now. Thanks for listening.

This piece was created with the help of generative AI tools and edited by our content team for clarity and accuracy.

About the Author

Laura Bell-Hammer

Statistics Editor

Laura Bell-Hammer is the Statistics Editor for Oil & Gas Journal, where she has led the publication’s global data coverage and analytical reporting for more than three decades. She previously served as OGJ’s Survey Editor and had contributed to Oil & Gas Financial Journal before publication ceased in 2017. Before joining OGJ, she developed her industry foundation at Vintage Petroleum in Tulsa. Laura is a graduate of Oklahoma State University with a Bachelor of Science in Business Administration.

Sign up for our eNewsletters
Get the latest news and updates