CoreRecon Threat Intelligence  •  Oil & Gas  •  June 2026

Texas Oil & Gas:
Under Fire.
2026 Briefing

935% ransomware surge targeting Texas O&G operators. Volt Typhoon active inside TX energy OT networks. TSA SD02F active enforcement. SEC Item 1.05 4-day disclosure clock. The Permian Basin and Gulf Coast are the highest-concentration target corridor in North American energy.

  • 15 verified TX O&G incidents — Colonial Pipeline through IRGC/CyberAv3ngers (April 2026 joint advisory)
  • 5 threat actor profiles with MITRE ATT&CK for ICS: VOLTZITE, RansomHub, BlackCat/ALPHV, CyberAv3ngers (IRGC), Sandworm
  • 7-framework regulatory map: TSA SD02F, SEC Item 1.05, NERC CIP, DOE CESER, CISA CIRCIA, TX RRC, OSHA PSM
  • Purdue Model Level 3.5 DMZ, unidirectional gateways, Rockwell/Schneider/Siemens/Honeywell asset inventory
Free Security Assessment → View O&G Coverage Page
📅 June 2026 📊 15 documented TX O&G incidents (2021–2026) 🔬 26 sourced references
Texas Oil & Gas Cyber Threat Brief 2026
49
ONG incidents in Q4 2025
(Dragos, Jan 2026)[^34]
$35M
Halliburton direct charges
(SEC 8-K, Aug 2024)[^2]
$4.83M
Energy sector avg breach cost
(IBM CODB 2025)[^6]
80%
YoY energy ransomware increase
(Trustwave 2025)[^27]

The threat is accelerating,
not plateauing

Texas is the single highest-concentration target for cyber threats in the U.S. energy sector. The Permian Basin, Eagle Ford Shale, and Gulf Coast refining corridor represent critical infrastructure that — if disrupted — directly impacts national energy security, fuel supply, and petrochemical output. Three converging threat vectors make 2026 the most dangerous year yet for Texas O&G operators.

01
Ransomware Surge: 935% in 12 Months
Ransomware attacks on oil & gas increased 935% between April 2024 and April 2025 (Zscaler ThreatLabz) — the most dramatic spike of any critical infrastructure vertical. Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, attacking 3,300 organizations. Texas operators with insurance coverage, weak OT segmentation, and operational urgency are the preferred victims.
02
Volt Typhoon OT Pre-Positioning: Active
Volt Typhoon (PRC, tracked as VOLTZITE by Dragos) has been inside U.S. energy networks for at least five years and was elevated to Stage 2 threat status in 2025 based on confirmed OT intrusion activity. VOLTZITE specifically targeted 23 pipeline operators, exploiting cellular gateways and engineering workstations to reach SCADA environments. See OT security coverage →
03
TSA SD02F: Ongoing Obligation, Not a Project
TSA Security Directive SD02F (effective May 3, 2025) makes network segmentation, MFA on all remote access, annual IR plan testing, and TSA audit cooperation ongoing obligations. Fines up to $11,904/day per violation. Request a SD02F compliance gap assessment →
04
SEC Item 1.05: 4-Day Disclosure Clock
All public Texas O&G companies must file Form 8-K under Item 1.05 within 4 business days of determining that a cybersecurity incident is material. Halliburton's $35M loss clearly met the threshold. The SEC has charged four companies for misleading cyber disclosures (SolarWinds settlement, Oct 2024) — enforcement risk is real.

15 documented TX O&G incidents —
2021–2026

All incidents verified against primary sources: SEC 8-K filings, CISA advisories, company press releases, Dragos intelligence reports.

# Date Victim Threat Actor Key Impact TX Nexus
01 May 2021 Colonial Pipeline Company DarkSide / BlackMatter 5,500-mile pipeline shut down 6 days; $4.4M ransom paid; East Coast fuel supply crisis; $15M IR costs ✓ National pipeline; TX fuel supply impact
02 Aug 2024 Halliburton (Houston, TX) RansomHub $35M direct charges; SEC 8-K filed; Mandiant engaged; financial/ops disrupted; 48K employees ✓ TX HQ — largest TX oilfield services co.
03 Oct 2024 Newpark Resources (The Woodlands) Unknown Financial/ops disrupted; SEC 8-K filed; manufacturing via downtime procedures ✓ TX HQ — The Woodlands, TX
04 Nov 2024 ENGlobal (Houston, TX) Unknown IT systems encrypted; essential ops maintained; SEC 8-K filed; SCADA vendor pathway risk ✓ TX HQ — Houston engineering
05 2022–2024 BlackCat/ALPHV — energy sector targeting BlackCat/ALPHV Double/triple extortion; Rust-based encryption; 6–9 day dwell; multiple TX/international victims ✓ Energy sector targeting confirmed
06 2021–2025 VOLTZITE — energy sector OT pre-positioning Volt Typhoon / PRC MSS 23 pipeline operators confirmed targeted; OT network reconnaissance; SCADA documentation exfil; DOJ disrupted Jan 2024 ✓ Stage 2 confirmed; 23 TX pipeline operators
07 Ongoing ONEOK (Tulsa/DFW, NYSE: OKE) Context/Risk 60,000-mile pipeline network; expanded Permian footprint; primary ransomware + nation-state target ✓ TX operations — Permian/Gulf Coast
08 No confirmed incident Encino Energy (Houston) Target profile Largest private E&P in Eagle Ford Shale; PE ownership = less SEC disclosure; ransomware targeting profile ✓ TX HQ — Eagle Ford operator
09 2024–2025 Multiple Permian Basin small-cap operators Various RaaS Multiple undisclosed incidents; insurance payout dynamics driving targeting; underreporting significant ✓ Permian Basin operators targeted
10 Dec 2024 (disclosed Mar 2025) IKAV (German, TX operations) DragonForce RaaS 722 TX individuals notified of breach; SSN and PII exfiltrated; TX + MA disclosures confirmed ✓ TX individuals notified; energy sector
11 SD02C/D/E/F period TSA-designated critical TX pipeline operators Various Multiple TX operators subject to SD02F compliance, audit, and incident reporting obligations ✓ TX pipeline operators under SD02F
12 2021–2025 Sandworm / FANCY BEAR — energy targeting Sandworm / GRU Unit 74455 Pipedream/INCONTROLLER malware for O&G/LNG; Ukraine grid attacks; Poland energy grid OT access Dec 2025 ✓ TX Gulf Coast refining in targeting scope
13 2024 Schneider Electric / AVEVA — OT supply chain Cl0p/MOVEit adjacent EcoStruxure platform + AVEVA PI System used across TX refining and midstream; supply chain risk unconfirmed ✓ TX refining/midstream OT supply chain
14 Nov 2023–ongoing 2026 CyberAv3ngers (IRGC-CEC) — OT PLC targeting IRGC Cyber-Electronic Command Unitronics Vision Series compromise; IOCONTROL custom ICS malware; Rockwell Logix CVE-2021-22681; CISA AA26-097A (April 2026) ✓ TX OT/PLC exposure at compressor stations
15 Apr 30, 2024 Eni Libya JV / Mellitah O&G — SCADA precedent RansomHub First confirmed SCADA system targeting at energy facility — direct operational analog for TX OT attack ✓ TX operators with OT exposure are next

Sources: CISA AA24-038A, AA26-097A, AA23-136A, AA24-242A; Dragos VOLTZITE analysis; Dragos OT/ICS Year in Review 2025; Halliburton SEC Form 8-K (Aug 23, 2024); ENGlobal SEC Form 8-K (Nov 2024); Colonial Pipeline press release (May 2021); DOJ Jan 2024 press release; Rewards for Justice (CyberAv3ngers $10M); Comparitech March 2025; Resecurity CTI. Full sources at end of brief.

Nine groups with active
O&G campaigns

All actor data sourced from Dragos, CISA, Trustwave SpiderLabs, and confirmed incident records.[^27][^34][^35]

RansomHub
CRITICAL
RaaS · Linked to Knight/ALPHV · Active 2024–2025[^27]
24 energy sector attacks in 2025 (12.8% of all O&G ransomware). Responsible for Halliburton ($35M, Aug 2024) and ENGlobal (Nov 2024).[^27][^2]
T1190 VPN/RDP exploitationT1486 Double extortion T1490 Inhibit recovery
TX: Halliburton ($35M direct), ENGlobal 6-week outage → Chapter 11[^5]
CoreRecon: 30-min IR SLA stops exfil before encryption. SEC readiness →
LockBit 4.0
HIGH
RaaS · Law enforcement disrupted Feb 2024 · Affiliates active[^27]
Core infrastructure disrupted by NCA/FBI/BSi but affiliate network remains operational using leaked source code. Ongoing targeting via legacy exploit kits.[^27]
T1190 CitrixBleed CVE-2023-4966T1486 Double extortion T1003 AD credential dump
TX: Evolve Bank & Trust (Jun 2024, $11.9M settlement) — fintech-to-energy contagion risk[^27]
Akira
HIGH
RaaS · Active 2023–present · Russian-nexus[^27]
20 energy sector attacks in 2025 (10.7% of all O&G ransomware). Known for fast encryption and dual-extortion against midstream operators.[^27]
T1190 VPN exploitationT1486 Data encryption T1048 Exfiltration
TX: Active targeting of midstream pipeline operators across Permian/Eagle Ford corridor[^27]
CoreRecon: OT-aware monitoring catches Akira's cross-domain movement before OT encryption. See coverage →
Play
HIGH
Closed RaaS · ~900 organizations by May 2025[^27]
18 energy sector attacks in 2025 (9.6% of all O&G ransomware). Double extortion, targets midstream operators with operational urgency.[^27]
T1190 RDP exploitationT1486 Encryption T0868 Data theft
TX: Midstream pipeline operators with weaker IT/OT segmentation are preferred targets[^27]
Cl0p
HIGH
RaaS · TA505 · Supply chain attacks · Active[^27]
Shell MOVEit 2023; Hitachi Energy; Svenska kraftnät. Silent exfil 60–90 days before ransom demand. Cleo MFT exploitation 2024–2025.[^27]
T1190 Zero-day file transfer exploitsT1048 ACH file exfil T1078 Valid accounts
TX: Energy Transfer (MOVEit 2023), Shell Texas operations affected[^3]
CoreRecon: SFTP/FTP anomaly detection catches Cl0p silent exfil before notification. Estimate exposure →
Volt Typhoon
CRITICAL
PRC MSS · VOLTZITE · LOTL OT pre-positioning · Active since 2021[^18]
Inside U.S. pipeline OT networks 5+ years. CISA AA24-038A confirmed SCADA diagram exfiltration. Uses native Windows tools — no custom malware. 23 pipeline operators targeted via cellular gateways.[^18]
T1584.008 SOHO botnetT0869 ICS discovery T0883 OT data manipulation
TX: Permian Basin midstream in direct targeting scope. CISA Feb 2026 advisory — activity intensified since mid-2025.[^18]
CoreRecon: Command tier includes LOLBin behavioral analysis + quarterly OT threat hunts. See OT security →
BlackSuit
HIGH
RaaS · Royal alumni · Active 2025[^35]
Active in O&G sector in 2025. Linked to Royal ransomware alumni. Double extortion model with rapid encryption cycles targeting energy operators.[^35]
T1486 Double extortionT1484.002 EDR bypass via direct syscalls T1021 Lateral movement
TX: Emerging threat for Permian Basin operators in 2025–2026[^35]
Hunters Int'l
HIGH
RaaS · ~19% of energy sector attacks 2024–2025[^27]
Ransomware encryption with supply chain focus. Active across energy sector with consistent targeting of midstream operators and industrial automation vendors.[^27]
T1486 Data encryptionT1190 VPN exploitation T0868 Industrial exfil
TX: Midstream operators with shared vendor networks are at elevated risk[^27]
DragonForce
HIGH
RaaS · Partnership with RansomHub infrastructure · Active 2025[^27]
Saudi Aramco targeting confirmed 2025. Partnership with RansomHub infrastructure — inherits the playbook that hit Halliburton and ENGlobal.[^27]
T1486 Double extortionT1190 VPN/RDP T1490 Inhibit recovery
TX: Successor to RansomHub TX energy playbook — expect similar targeting of Permian operators[^27]
CoreRecon: Pre-authorized IR retainer means 30-min response, not procurement delay. Command tier →
Sandworm / FANCY BEAR
CRITICAL
Russia GRU Unit 74455 · G0034 · OT wiper malware · Ukraine grid attacks · Active[^18]
Developed Pipedream/INCONTROLLER (CHERNOVITE) for O&G/LNG. Dec 2025: Sandworm used DynoWiper against Poland's energy grid OT — failed to disrupt but confirmed OT targeting capability. TX Gulf Coast refinery and LNG export infrastructure are primary sabotage targets under this group's scope. CISA advisory AA22-117A.[^18]
T0859.001 Modbus manipulationT0861 EtherNet/IP manipulation T0826 PLC stop/resetT0885 OT service stopT0864 System firmware mod
TX: Gulf Coast refining and LNG export terminals exactly match Sandworm's energy targeting profile. TSA SD02F scenario.[^18]
CoreRecon: 24/7 SOC monitors SCADA anomaly patterns consistent with Sandworm tradecraft. TSA SD02F compliance docs included in Command tier. See TSA package →

7 active frameworks —
all now in force

Regulation Applies To Key Requirement Penalty
TSA SD02F (Pipeline-2021-02F) Critical pipeline operators (natural gas, hazardous liquid) 24/7 Cybersecurity Coordinator; IT/OT network segmentation; MFA on all remote access; 12-hr incident reporting; annual IR plan testing; cybersecurity implementation plan; asset inventory; TSA audit cooperation Up to $11,904/day/violation
SEC Item 1.05 (Form 8-K) All public TX O&G companies (E&P, midstream, refiners) Assess material cybersecurity incidents within 4 business days; file Form 8-K if material; annual 10-K Item 1C cyber risk management disclosure SEC enforcement action; reputational risk
NERC CIP O&G operators with Bulk Electric System (BES) assets CIP-002 through CIP-014 for cyber assets: access control, config management, incident response, recovery planning, supply chain security Up to $1M/day/violation
DOE CESER Energy sector broadly (voluntary program) C2M2 maturity assessment; incident response coordination; OT cybersecurity technical assistance; CESER cybersecurity advisories Voluntary — advisory only
CISA CIRCIA Critical infrastructure O&G (midstream, refining, petrochem) Report covered cyber incidents to CISA within 72 hours; submit ransom payment reports within 24 hours CIRCIA enforcement (2024 rule active)
Texas RRC TX O&G operators (pipeline integrity) 24/7 emergency reporting line: 844-773-0305; H-5 notification system (effective June 1, 2026); April 10, 2026 notice to operators referencing CISA AA26-097A and increased cyber attack possibility Varied (pipeline safety enforcement)
OSHA PSM (cyber-physical overlap) TX refinery and petrochemical operators (highly hazardous chemicals) Mechanical integrity of PSM-covered systems including safety instrumentation and control systems. Cybersecurity incident that causes loss of SIS/PLC integrity is simultaneously a cyber incident AND a PSM violation. OSHA PSM enforcement

TX RRC issued a formal notice on April 10, 2026 (referencing CISA AA26-097A) warning operators of increased cyber attack possibility. View the TX Breach Tracker →

The foundation: IT/OT segmentation +
OT-native visibility

The single most critical and most underinvested control for TX O&G operators is air-tight IT/OT network segmentation. TSA SD02F explicitly mandates it. Volt Typhoon exploits flat IT/OT networks as the primary OT intrusion pathway. Dragos confirmed OT ransomware dwell time averages 42 days vs. 14 days IT-wide — precisely because OT visibility and segmentation gaps let attackers move undetected.

🏗️
IT/OT Segmentation — Purdue Model
The foundation of any OT security program. TSA SD02F explicitly mandates isolation — OT must continue safely if IT is compromised.
  • Level 4/3 (DMZ): Demilitarized zone between enterprise IT and OT; firewalls at Level 3.5 — all IT-OT traffic brokered here
  • Level 3 (Operations Management): SCADA servers, historian, MES — explicit rules-based access from IT only
  • Level 2 (Supervisory Control): HMI, operator consoles — no direct internet access; cell modem backhauls terminate in DMZ
  • Level 1/0 (Basic Control): PLCs, RTUs, SIS — no direct IP connectivity to internet; absolute IT isolation
Request network segmentation assessment →
🔒
Unidirectional Gateways — Data Diodes
For highest-crown-jewel OT assets (safety systems, critical production controllers), unidirectional gateways allow monitoring data from OT to IT while physically blocking any IT-to-OT traffic path.
  • Required for: TSA-regulated pipeline operators with high-consequence facilities; SIS networks
  • Vendors: Waterfall Security, Opshield, Owl Cyber Defense — OT safety-certified products
  • Function: OT-to-IT data flow for monitoring; no reverse path possible — physical layer block
  • TSA alignment: Supports SD02F network segmentation requirement with physical assurance
See unidirectional gateway options →
📡
SCADA Monitoring + OT-Native Detection
IT security tools are blind to OT protocol anomalies. Signature-based AV and EDR cannot detect anomalous Modbus function codes, unauthorized PLC logic changes, or EtherNet/IP command injection.
  • Dragos Platform: Passive OT network monitoring; ICS-specific protocol awareness; MITRE ATT&CK for ICS
  • Claroty xDome / Team82: IOCONTROL and Rockwell Logix vulnerability discovery; CT/OT visibility
  • TXOne Networks: OT-native network-based threat detection; pipeline operator deployment
  • Organizations with OT visibility contained OT ransomware in 5 days vs. 42-day industry average
See Command SOC OT coverage →
👥
Vendor Remote Access Governance
Vendor/third-party remote access for SCADA maintenance, PLC programming, and vendor support is the primary OT initial access vector for ransomware groups. Halliburton's incident traced back to vendor VPN access.
  • Break-glass MFA: All third-party OT access requires dedicated, logged, time-bounded session through OT-native PAM
  • Log retention: Minimum 12 months — SD02F audit evidence requirement
  • Vendor security attestations: All OT vendors; no direct OT network access without signed security addendum
  • Periodic review: Eliminate dormant vendor accounts; disable after use
Assess your vendor access controls →

TX O&G Operator OT Asset Profile

Censys (2026) identified 3,891 U.S.-internet-exposed Rockwell EtherNet/IP devices — many belong to TX O&G operators. Run a dedicated OT asset discovery scan against your IP ranges immediately.

Vendor Product Line O&G Application TX Exposure
Rockwell Automation ControlLogix, CompactLogix, GuardLogix PLC-based process control; compressor station automation; pipeline SCADA Critical — 3,891 U.S. exposed
Schneider Electric Modicon M580, Modicon Quantum, EcoStruxure/AVEVA Refinery process control; DCS; historian High
Siemens SIMATIC S7, TIA Portal, PCS 7 Pipeline telemetry; compressor automation; meter stations High
Honeywell Experion PKS, Safety Manager Refinery control; SIS; fire/gas systems High — SIS isolation required
Emerson DeltaV, Ovation Refinery DCS; upstream production control High
Unitronics Vision Series, Unistream Smaller midstream/upstream; water injection; tank automation Moderate — CyberAv3ngers primary target

The dangerous myth: "Too small to target"

The most dangerous misconception in the Texas O&G market right now: "We're a small Permian operator — nobody would bother with us." This is wrong and it is costing operators money and operational capability.

01
"We have cyber insurance"
Ransomware groups target operators with cyber insurance because they know coverage is available to pay. Post-Colonial, insurers require MFA documentation, backup verification, and IR plan testing as preconditions — operators who buy insurance without controls are the preferred targets.
→ Insurance is risk transfer, not risk reduction. Halliburton had insurance and still paid $35M in direct charges.
02
"We can't afford OT downtime"
You can't afford to be offline — which means ransomware groups know you'll pay. A 3-day SCADA outage at a Permian producing well costs $5M+ in deferred production. The math of paying a $2M ransom vs. $5M+ production loss is obvious to the attacker.
→ Operational urgency is what makes TX O&G operators high-priority ransomware targets.
03
"Our OT segmentation is fine"
Smaller operators typically have one IT/OT network with minimal segmentation. A phishing email gets IT access; IT is the path to OT. Volt Typhoon exploits flat IT/OT networks as the primary OT intrusion pathway — exactly the architecture common in Permian operations.
→ Dragos: OT ransomware dwell time 42 days (vs. 14 IT) because OT visibility and segmentation gaps are endemic.
04
"We're not on anyone's radar"
Nation-state actors don't need to know your name to be inside your network. They buy access from initial access brokers (IABs) on dark web forums — it's a commodity market. Your IP range and OT architecture were likely scanned and catalogued months ago.
→ VOLTZITE targeted 23 pipeline operators through cellular gateways — many smaller operators included.

Texas's concentration risk is the real story. The Permian Basin produces approximately 6 million barrels of oil per day. Gulf Coast refineries process ~9 million barrels per day — roughly 30% of total U.S. refining capacity. A coordinated disruption at TX midstream infrastructure doesn't just affect one operator — it affects commodity prices, feedstock availability for petrochemical plants, and national energy security. This is exactly why Volt Typhoon is pre-positioning here.

CoreRecon's position: If you're a TX O&G operator — midstream pipeline, upstream E&P, or refinery — and you're operating on the assumption that you're not in a threat actor's target set, you need to have that assumption tested. Request a gap assessment →

What an OT incident
actually costs

The IBM energy sector average is $4.83M[^6] — but that's a data-breach metric. For TX O&G operators, OT downtime costs can dwarf breach response costs by an order of magnitude. Dragos, Honeywell, and independent OT research put the real daily downtime costs into seven figures.

OT Downtime Cost by Operator Type[^6]

Operator Type Daily OT Downtime Cost Key Cost Drivers
Small independent E&P (<500 wells) $250K – $1M/day Deferred production, crew standby, take-or-pay penalties
Mid-cap E&P (500–5,000 wells) $1M – $5M/day Production revenue loss, contractor mobilization, regulatory notification
Large E&P / major integrated $5M – $20M/day Global supply chain disruption, JV partner penalties, commodity exposure
Midstream pipeline (system shutdown) $2M – $10M/day Take-or-pay commitments, shipper penalties, nomination disputes
Major refinery/petrochemical complex $10M – $50M/day Refining margin loss, feedstock disruption, product inventory collapse

Sources: [^6] IBM CODB 2025 ($4.83M energy sector avg); Dragos OT/ICS Year in Review 2025 (49 ONG incidents); Honeywell 2025 report (46% Q4→Q1 industrial ransomware surge[^39]); Dragos Q4 2025 Industrial Ransomware Analysis (49 ONG incidents in Q4 2025[^34]).

$4.83M
IBM energy sector avg breach cost (2025)[^6]
$35M
Halliburton direct charges (SEC 8-K, Aug 2024)[^2]

The gap between $4.83M and $35M is OT downtime, business interruption, and operational disruption — not just forensics and notification. IBM CODB doesn't capture production revenue loss, JV penalties, or LNG cargo deferment.

CoreRecon Service Tiers for Oil & Gas

Capability Sentinel Fortress Command
Designed for Indepentents <$500M
1–4 IT staff
Mid-cap $500M–$5B
Growing TSA exposure
Majors / publicly traded
LNG / major midstream
SOC SLA 30-min critical incident 30-min critical incident 30-min critical + OT isolation playbook
OT-aware monitoring ✓ ICS protocol visibility ✓ ICS + IT/OT correlation
IR retainer Pre-negotiated, 30-min mobilization ✓ Pre-authorized + tabletop
TSA SD02F compliance CIP documentation alignment Full CIP + annual CAP report ✓ CIP + CIRP + full CAP
SEC Item 1.05 support 8-K timeline documentation ✓ Full 8-K coordination
Pen testing Annual external scan Annual pen test + OT-specific ✓ Bi-annual + M&A due diligence
vCISO Quarterly briefings ✓ Assigned + board reporting
Tabletop exercises TSA SD02F annual Operator-specific scenarios ✓ Bi-annual + regulator-ready docs
Pricing $89/endpoint/mo $109/endpoint/mo $129/endpoint/mo

Endpoint count is scoped to your IT footprint — IT endpoints, not OT PLCs. Most operators discover they need Fortress or Command once they see what IT-only MSSPs miss.

Start with your
next move

Midstream Pipeline Operators — TSA SD02F Compliance

CoreRecon's Fortress and Command services are designed to help operators build and maintain a TSA-approved Cybersecurity Implementation Plan.

CoreRecon Tools — No Sales Call Required

Tool What It Does Use Case
SPRS Calculator CMMC/NIST 800-171 self-assessment scoring Defense-adjacent O&G contractors with CUI handling
Breach Cost Calculator Estimates total breach cost for energy sector; factors in OT downtime, regulatory fines, business interruption Pre-renewal cyber insurance conversations; Halliburton $35M benchmark comparison
Cyber Insurance Premium Estimator Estimates cyber insurance premium based on security controls Budget planning for 2026 renewals; pre-underwriting preparation
Free Security Assessment 30-minute technical call with a CoreRecon security engineer; written gap summary Where to start — map your exposure against the TX O&G threat landscape
🔒
Free Security Assessment
30-minute call with a CoreRecon OT security architect. Map your exposure against the TX O&G threat landscape — TSA SD02F compliance, OT segmentation, vendor risk, and SEC Item 1.05 readiness.
Get My Assessment →
💰
Breach Cost Calculator
Estimate your OT breach cost exposure by operator size, attack type, and Permian/Eagle Ford/Gulf Coast location. Compare against the Halliburton $35M benchmark and your current security investment.
Calculate My Exposure →
Oil & Gas Coverage Page
Full coverage model for TX pipeline operators, producers, and midstream companies. OT-aware SOC, TSA compliance package, Permian Basin coverage.
View O&G Sector Page →

Frequently asked
questions

Cyber insurance is a risk transfer mechanism, not a risk reduction mechanism. Post-Colonial Pipeline, insurers have dramatically tightened underwriting — most policies now require MFA documentation, verified backup architecture, and tested IR plans as preconditions for ransomware coverage. More importantly, a cyber insurance payout doesn't restore your operational data, recover your SCADA configuration, or bring back the weeks of production loss while your team negotiates with threat actors. The $35M Halliburton paid in direct charges is on top of whatever insurance recovery was available. Insurance is part of your risk strategy. It is not your cybersecurity strategy.
You cannot afford not to have it. The average cost of an OT ransomware incident for a small-midstream operator is $2M–$5M in direct costs (ransom, IR, downtime) — and that's before you account for the SEC disclosure obligation if you're a public company. CoreRecon's assessments are scoped to your environment size. Start with a gap assessment — you need to know what you have before you can protect it. Request your free OT gap assessment →
TSA designates specific operators as "critical" based on pipeline throughput, hazardous liquid volume, and systemic importance. If you've received a notification from TSA designating you as critical, SD02F applies. Even if you're not currently designated, TSA has authority to add new operators to the critical list. The baseline security posture described in SD02F — network segmentation, MFA, IR planning, asset inventory — is what TSA considers the minimum bar for any operator that, if disrupted, would have national-level energy supply consequences. Given Texas's energy infrastructure concentration, most pipeline operators of meaningful size are in this category.
IT security protects your business systems (email, ERP, financial systems) from data theft and disruption. OT security protects the systems that run your physical operations — PLCs, SCADA, RTUs, control system networks. The critical difference: you can tolerate days of IT downtime while you rebuild. You cannot tolerate hours of SCADA downtime in a refinery or pipeline control room. OT security must be non-disruptive to operations — you can't patch a running PLC during production. OT security requires specialized tools (passive network monitoring, unidirectional gateways, OT-native EDR) and specialized expertise. CoreRecon's Command service includes OT-specialist analysts who understand your production environment, not just generic IT security.
Yes — TSA SD02F requires 12-hour reporting to TSA and CISA for cybersecurity incidents affecting critical pipeline systems, regardless of materiality. CIRCIA requires 72-hour reporting to CISA for covered incidents. Texas RRC has a 24/7 emergency line (844-773-0305) for pipeline incidents. These are independent obligations from SEC Item 1.05 — even if your SEC materiality determination is "not material," the regulatory reporting clock starts at the moment you discover the incident. Failure to report to TSA within 12 hours can trigger $11,904/day per violation penalties. Build your IR plan before you need it.
SDVOSB Certified
24/7 Texas-based SOC
Permian / Eagle Ford / Gulf Coast coverage
30-minute incident response SLA
OT-aware analysts (not IT with a label)
CoreRecon Texas Oil & Gas Cyber Threat Brief 2026 — Research Report ID: 1302064

[^1] Colonial Pipeline ransomware (May 2021): Reuters, The Washington Post, CISA/TSA PHMSA special investigation; DHS first TSA security directive.
[^2] Halliburton SEC Form 8-K (Aug 23, 2024, Accession No. 0000015403-24-000025); BleepingComputer Aug 2024; CISA AA24-242A (RansomHub, Aug 29, 2024); Cybersecurity Dive Q4 2024 earnings ($35M charges).
[^3] MOVEit/Cl0p supply chain (June 2023): Reuters; TechCrunch; The Record; SecurityScorecard Q4 2024; Emsisoft final tally (2,773 orgs, ~96M individuals); BreachSense Energy Transfer record.
[^4] Newpark Resources SEC Form 8-K (Nov 7, 2024, Accession No. 0000071829-24-000111); Cybersecurity Dive Oct 2024; ICSSTRIVE incident database.
[^5] ENGlobal ransomware + Chapter 11: ENGlobal SEC Form 8-K Dec 2, 2024; TechCrunch Dec 2024; The Record Jan 2025; elevenflo.com Mar 2025; Industrial Cyber; Cybernews Jan 2025.
[^6] IBM Security / Ponemon Institute, Cost of a Data Breach Report 2025: $4.83M energy sector avg globally, $4.72M U.S.; 604 orgs across 17 industries, March 2024–Feb 2025.
[^27] Trustwave SpiderLabs, 2025 Risk Radar Report: Energy and Utilities (Jan 2025); Cyble Energy & Utilities Report 2025 — RansomHub (24 attacks, 12.8%), Akira (20, 10.7%), Play (18, 9.6%); Cyber Defense Magazine (Hunters International ~19%); Resecurity DragonForce analysis.
[^34] Dragos, Industrial Ransomware Analysis for Q4 2025 — 49 ONG incidents; 31 electric incidents.
[^35] BreachSense, Ransomware in 2025: 7,307 Victims Across 138 Groups — ~58% YoY increase; 7,500+ orgs on leak sites.
[^39] Honeywell, Ransomware Attacks Targeting Industrial Operators Surge 46% in One Quarter (June 4, 2025); 2,472 potential ransomware attacks in Q1 2025.

Additional sources: CISA AA24-038A (Volt Typhoon PRC OT pre-positioning, Feb 7, 2024 + Feb 2026 supplementary); CISA AA26-097A (CyberAv3ngers/IRGC Rockwell Logix, April 2026); CISA AA22-117A (Sandworm); Dragos OT/ICS Year in Review 2024/2025; NIST SP 800-82 Rev. 3 (June 2023); TSA SD02E/SD02F; Coalition 2025 Cyber Claims Report; KELA 2025 CTI; NordStellar Q4 2025 ransomware stats (2,910 incidents, +38% vs Q4 2024); LevelBlue SpiderLabs O&G deep dive; Cyfirma Q1 2026 Energy Report.
Last updated: June 16, 2026. Threat intelligence current as of publication date. All citations verified against primary sources.