Insight
Five Factors Impacting OT Cyber Risk in the Energy Sector

Marco Ayala is Technical Director, Global Energy for ABS Consulting and Energy Market Lead for the ABS Cyber. An ISA-certified cybersecurity trainer with more than 22 years of experience in industrial control system security across the energy, oil and gas, and chemical sectors, he serves as President and National Sector Chief, Energy for InfraGard National Members Alliance, a volunteer role fostering collaboration between the FBI, private sector and stakeholders to protect US critical energy infrastructure. He also serves as Chair of the Threat Analysis and Cybersecurity Committee and Cybersecurity Coordinator for the Gulf of Mexico Area Maritime Security Committee Outer Continental Shelf.
Marco Ayala
Technical Director, Cybersecurity - Global Energy
Safety-Focused Sectors Facing Cyber Exposure
As a result of rapid digitalization, vendors come in, systems get connected and remote access gets provisioned. That creates an exposure profile into which no single person in the organization has full visibility without OT cyber controls in place.
Meanwhile, investment lags because downstream and midstream operations run on slim margins. Without a regulatory mandate creating urgency, and with the Chemical Facility Anti-Terrorism Standards (CFATS) program having lapsed without reauthorization, many facilities do not have a regulatory need to prioritize OT cybersecurity investment.
The result is a sector that is simultaneously safety-conscious and cyber-exposed.
Here’s why the old risk model no longer works. The traditional risk model in chemical and energy operations was built on a layered defense concept: process control as the first line, safety instrumented systems as the second and passive protection (relief valves, secondary containment, emergency response) as the final backstop.
This model assumes each layer is independently intact.
Cyber Events Do Not Respect Layer Independence
When an adversary gets hold of an OT asset, they are not simply locking up a server. They may be inhibiting or manipulating the very systems that process safety management programs assume will function as designed. A compromised process control system, for example, may generate false readings that operators act on in good faith.
“You don’t want to rely on those passive and active controls as your only enforcement. And as we’ve seen in history, even your mechanical fail safes can either fail, rupture, be breached or not act appropriately when needed.” – Marco Ayala
The energy sector has already seen attacks specifically engineered to exploit safety-instrumented systems, capable of overriding protection mechanisms—some of the most dangerous ICS-targeted attacks ever recorded. The digital attack surface in modern energy facilities has also expanded dramatically beyond the plant fence line. Remote vendor access is now standard, with service level agreements bringing authorized third parties into control system networks routinely.
As the industrial internet of things rewires facility risk, the perimeter you thought was protecting you no longer exists. Risk management frameworks must reflect our current reality of ever converging IT and OT systems.





