V57 · Texas Oil & Gas / Midstream Operations · TSA SD-Pipeline-2021-01D · TSA SD-02F (effective May 3, 2025) · SEC Item 1.05 4-Business-Day Clock · CIRCIA 72-Hr · RRC 16 TAC §3.71 · TDPSA §541 · HSE / SCADA Air-Gap Myth · Volt Typhoon IT/OT (Dragos VOLTZITE) · SDVOSB Co-Prime

SCADA is not air-gapped. Halliburton lost $35M in Aug 2024. Colonial shut down the East Coast from a single VPN credential. Texas midstream is in scope for five parallel clocks right now.

Texas oil & gas operators (upstream E&P, midstream pipelines, gas processing, downstream refining) are squarely in scope for a five-regulator stack: TSA SD-Pipeline-2021-01D series + TSA SD-02F (effective May 3, 2025) — the new Cybersecurity Implementation Plan requirement on the 100+ in-scope pipeline operators; SEC Item 1.05 4-business-day cyber-incident disclosure — Halliburton's August 2024 SEC 8-K Item 1.05 confirmed $35M direct loss; CIRCIA 72-hr CISA reportable-cyber-incident notification for in-scope energy + pipeline entities; TDPSA §541 enumeration coverage for SCADA-derived PI + employee PI; RRC of Texas 16 TAC §3.71 pipeline damage-prevention + cyber-induced release reporting pathway.

935% YoY ransomware surge vs. oil & gas (Zscaler 2025). Dragos VOLTZITE tracking cellular RTU/SCADA gateway credential compromise in U.S. energy 2024–2025. Colonial Pipeline (Houston-origin, May 2021) shut down the entire 5,500-mile pipeline from a single reused VPN credential with no MFA. Hanna UT Pump Station TX PLC ransomware proof-point. ENGlobal Corp (Houston TX, Nov 2024) — 6-week business outage. Newpark Resources (Woodlands TX, Oct 2024) ransomware confirmed. PI historian exfil + Modbus/DNP3/OPC-UA/EtherNet-IP engineering workstation exposure + Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix vendor-IT remote-access.

30-min IR SLA. SDVOSB-certified. TX-resident analysts. Pre-authorized SCADA isolation playbook. SD-02F CIP authorship. SEC Item 1.05 4-business-day disclosure workflow. RRC §3.71 incident reporting pathway.

Free SCADA / OT Posture Assessment — $2,500 Value Download the TX Oil & Gas Threat Brief →
$35M
Halliburton TX
RansomHub direct loss
SEC 8-K Item 1.05
935%
YoY ransomware surge
vs. oil & gas
Zscaler 2025
< 30min
CoreRecon IR SLA
beats TSA SD-02F
12-hr CISA clock
4days
SEC Item 1.05
cyber-incident
disclosure clock
⏱️
TSA SD-02F effective May 3, 2025. The Transportation Security Administration's Security Directive 02F requires pipeline operators (expanded set) to author and maintain a Cybersecurity Implementation Plan (CIP) reviewable by TSA on a 12-hour window; to validate the CIP annually; to implement specific OT security controls including network segmentation, access control, and incident reporting; and to report cyber incidents to CISA within the TSA-specified clock. Smaller gas gathering + processing operators below the 100-operators TSA threshold still carry parallel obligations under RRC of Texas 16 TAC §3.71 (pipeline damage-prevention + cyber-induced release reporting), 49 CFR Part 192/195 PHMSA, 30 CFR §250 (offshore), and where defense-adjacent — CMMC 2.0 32 CFR Part 170 + DFARS 252.204-7012 72-hr DIBNet clock.
TX Threat Reality — Operator Anchors

Five verified TX oil & gas anchors. Plus the single most-watched U.S. incident of the decade (Colonial).

SCADA networks are not air-gapped. The history of the last five years proves it. These five anchors frame why TX oil & gas operators — particularly midstream pipelines with public SEC disclosure exposure — cannot defer SD-02F authorship, RRC §3.71 reporting workflow, or pre-authorized SCADA isolation.

Named Anchor 1
Halliburton TX $35M RansomHub (Aug 2024)
Halliburton — Houston-headquartered oilfield services major. Aug 20, 2024 confirmed RansomHub ransomware attack. Q4 2024 SEC 10-K disclosed ~$35M direct recovery cost. SEC 8-K Item 1.05 cyber-incident disclosure filed within 4-business-day clock from materiality determination. Corporate IT taken offline; IT-billing/OT-SCADA interface attack surface validated. Halliburton is the precedent-establishing TX oil & gas SEC Item 1.05 disclosure.
Source: Halliburton Q4 2024 SEC 10-K (filed Feb 2025) + 8-K Item 1.05 (filed Aug 2024) + RansomHub kill-chain profile (CrowdStrike 2024 Global Threat Report).
Named Anchor 2
Colonial Pipeline — VPN Credential
Colonial Pipeline (Houston-headquartered, May 2021) — largest U.S. refined-fuels pipeline (5,500 miles). Shut down the entire pipeline for 6 days after a single reused VPN credential allowed DarkSide access to the corporate IT network. East Coast fuel supply disrupted; ~$4.4M ransom paid. The Colonial case is the structural reason why every midstream OT-adjacent VPN must enforce phishing-resistant MFA — and the documented the inability-to-bill-without-IT panic that drives pre-authorized SCADA isolation playbook adoption.
Source: U.S. Department of Homeland Security Colonial Pipeline Incident Review (public statement June 2021); Colonial Pipeline CEO statements to Senate HSGAC June 2021; DarkSide Bitcoin blockchain analysis (Elliptic, May 2021).
Named Anchor 3
Newpark Resources Woodlands TX (Oct 2024)
Newpark Resources (NYSE-listed oilfield services, HQ Woodlands TX) — confirmed ransomware attack October 2024. Woodlands TX HQ operations affected; OFS supply-chain exposure for upstream Permian + Eagle Ford customers. Confirms TX-based OFS-adjacent operators are in active targeting — and validates the SEC Item 1.05 disclosure posture for any NYSE-listed TX OFS firm.
Source: Newpark Resources SEC 10-Q filing Q4 2024 + company press statement October 2024.
Named Anchor 4
ENGlobal Corp Houston TX — 6-Week Outage
ENGlobal Corp (Houston TX-based automation services to midstream + upstream operators) — November 2024 ransomware attack; business operations remained offline for ~6 weeks per January 2025 SEC update. Of the unique risk vectors: ENGlobal was a third-party SCADA integrator whose clients included multiple Texas midstream operators — a single ENGlobal compromise cascades across multiple downstream operator customers. This is the documented third-party-SCADA-integrator cascade pattern.
Source: ENGlobal Corp SEC 10-Q + 8-K Item 1.05 filings (Nov 2024 + Jan 2025 update).
Named Anchor 5
Dragos VOLTZITE + Hanna UT Pump Station TX PLC
Dragos VOLTZITE tracking (2024–2025) documents PRC state-sponsored activity cluster targeting OT networks in U.S. energy — including cellular RTU/SCADA gateway credential compromise + Modbus/DNP3 read-and-write reconnaissance + persistence in IT networks adjacent to OT VLANs. Hanna UT Pump Station Texas — Dragos-public case study of confirmed PLC ransomware affecting a Texas pump station — the OT-level proof that pre-positioned compromise of TX oil & gas OT is real, not theoretical.
Source: Dragos 2024 + 2025 ICS/OT Threat Intelligence Reports (VOLTZITE cluster + Hanna UT case study).
Cross-link: TX Oil & Gas Threat Landscape Deep-Dive

For the broader midstream-deep-dive intelligence brief on the same anchors (Halliburton, Newpark, ENGlobal, Hanna UT, plus full Dragos adversary catalogs), see /blog/oil-gas-tx — Texas Oil & Gas Cybersecurity 2026: OT/ICS Ransomware, Pipeline Operator Breaches & the Downtime Math.

The Regulatory Stack — TX Oil & Gas Operator Exposure

Five parallel reporting clocks. Four regulators. One operator.

Texas oil & gas operators do not face one regulatory framework — they face five overlapping ones, each independent of the others, each with its own enforcement arm, each with its own penalty structure. A single material cyber incident triggers parallel narratives on the same set of facts across TSA SD-02F, SEC Item 1.05, CIRCIA, TDPSA, and RRC 16 TAC §3.71.

⛓️
TSA SD-Pipeline-2021-01D + SD-02F
Top 100+ hazardous liquid + natural gas pipeline operators + LNG facility operators. SD-02F (effective May 3, 2025) expands the operator set + requires an annual Cybersecurity Implementation Plan (CIP) reviewable by TSA on a 12-hour window; OT security controls (network segmentation + access control + ITA testing); incident reporting to CISA within the TSA-specified clock. Smaller TX gas LDCs exempt from TSA but still bound by 49 CFR Part 192/195 PHMSA + RRC 16 TAC §3.71.
📊
SEC Item 1.05 — 4-Business-Day Clock
SEC Form 8-K Item 1.05 (effective December 18, 2023) requires publicly-traded companies to disclose material cybersecurity incidents within 4 business days of materiality determination. Halliburton's Aug 2024 SEC 8-K Item 1.05 disclosure set the precedent for TX oil & gas SEC-registered issuers. ConocoPhillips, Pioneer, EOG, Halliburton, Schlumberger, Newpark, ENGlobal, plus midstream MLPs with public senior unsecured notes — all in scope for Item 1.05.
⏱️
CIRCIA — 72-Hr CISA Clock
Cyber Incident Reporting for Critical Infrastructure Act (6 USC §681d, final rule pending). 72-hour CISA cyber-incident reporting on covered entities in energy + pipelines. Runs concurrent with TSA SD-02F + SEC Item 1.05. The CIRCIA narrative is one of four that must be drafted in parallel from a single set of forensic facts after a material incident.
⚙️
RRC of Texas 16 TAC §3.71
Texas Railroad Commission pipeline damage-prevention + incident notification. Under HB 1208 (2023) and SB 3 / SB 1928 (2025 — Texas Oil & Gas Cybersecurity Initiative), RRC has explicit pathways for reporting cyber-induced releases of hazardous liquids + gas, and service disruption to critical customers. RRC §3.71 narrative runs concurrent with TSA SD-02F + SEC Item 1.05 + CIRCIA. TX-only regulator with deep pipeline operating-data visibility.
📋
TDPSA §541 + §521.053
Texas Data Privacy and Security Act §541.002 enumerates sensitive PI categories. For gas LDCs + retail gas marketers + co-op operators handling customer billing data, TDPSA enumeration applies. §521.053 breach notification to the Texas Attorney General within required timing. Any oil & gas operator that maintains customer-facing billing or large-scale employee PI is in scope.
🛡️
CMMC 2.0 32 CFR Part 170 (Defense-Adjacent)
Where the TX oil & gas operator is in the defense fuel supply chain (jet fuel for MILCON bases, marine fuel for Naval ships, MILSPEC lubricants), DFARS 252.204-7012 72-hr DIBNet + 252.204-7021 (CMMC as a condition of award) + NIST SP 800-171 Rev 2 (110 controls) Flow-down from Defense Logistics Agency (DLA) Energy contracts. CMMC Phase 2 enforcement Nov 2026. SDVOSB co-prime advantage counts toward DFARS 252.219-7003.
🌐
Volt Typhoon IT/OT Pre-Positioning
CISA/NSA Joint Advisory AA24-038A (Feb 2024) documents PRC state-sponsored Volt Typhoon pre-positioned access inside U.S. critical infrastructure — including Texas energy — since 2021. The actor lives off the land with built-in network admin tools and prioritizes OT/IT. Dragos VOLTZITE tracking (2024–2025) confirms cellular-RTU/SCADA-gateway credentials as a primary targeting vector — exactly the Layer-0/1 surface most TX midstream operators underestimate as outside CISO scope.
📑
30 CFR §250 — Offshore O&G Security
Bureau of Safety and Environmental Enforcement (BSEE) offshore operating + security requirements under 30 CFR §250. Gulf of Mexico (TX OCS) operators face parallel offshore-side cybersecurity obligations: SEMS (Safety and Environmental Management Systems) integration with IT/OT incident reporting, BOEMRE/BSEE incident notification, and the BSEE audit cycle for OCS platforms. Midstream-to-offshore pipeline approaches require a parallel cybersecurity posture on the offshore side.
Attack Surface — TX Oil & Gas Operator Specifics

SCADA air-gap myth. Cellular RTU gateway. PI historian exfil. Vendor-IT remote access. All in scope.

Generic enterprise EDR misses the TX oil & gas attack surface because the workflow-specific risks are unique to OT. Cell-gateway credentials, Modbus broadcasts, PI historian tags, and SCADA vendor remote-access ports are the structural risks no enterprise SOC sees.

Cellular RTU/SCADA Gateway
Dragos VOLTZITE Vector
Cellular networks backhauling RTUs (Remote Terminal Units) at pump stations, wellheads, and pipeline valve assemblies historically operated over private cellular APNs with minimal endpoint security. Dragos VOLTZITE tracking documents credential compromise on these cellular gateways as a primary PRC targeting vector. Many TX midstream operators don't even have an inventory of their cellular RTU fleet — leading to OT assets outside CISO scope and outside IR playbook reach.
Source: Dragos VOLTZITE activity cluster 2024–2025; CISA/NSA Joint Advisory AA24-038A.
OT Engineering Workstation
Modbus / DNP3 / OPC-UA / EtherNet-IP
Engineering workstations running Pro/ENGINEER, AutoCAD Plant 3D, or AVEVA E3D provide access to OT configuration + engineering data. Modbus (TCP/502), DNP3 (TCP/20000), OPC-UA (TCP/4840), EtherNet-IP (TCP/44818 + UDP/2222) protocols broadcast across the OT VLAN with limited authentication. A compromised engineering workstation allows attackers to read live process state + write configuration that affects physical operations.
Source: Dragos 2024-2025 ICS Protocol Threat Reports; CISA ICS Advisories 2024-2025.
VPN Credential Reuse
The Colonial Trigger Pattern
Colonial Pipeline's May 2021 attack vector was a single reused VPN credential with no MFA enforcement on OT-adjacent IT systems. The same architectural failure mode is documented across multiple TX midstream operators: shared VPN accounts between IT and OT scopes, password rotation gaps, MFA bypass via SMS/call, and contractors accessing OT via VPN without per-user provisioning. OT-side fallback to manual operation is rarely tested — and billing-system dependency on IT-side means a billing ransomware takes the OT down with it.
Source: Colonial Pipeline post-incident disclosures (June 2021) + Dragos post-Colonial OT IT/IT-disconnect analysis.
PI Historian Exfiltration
OSIsoft PI / AVEVA PI Server
PI historian servers collect every process measurement timestamp from across the operator's OT fleet — flow rates, pressures, temperatures, valve states, tank levels — and store in high-resolution time-series databases that can span 10+ years of operating data. A compromised historian provides an attacker with complete operational visibility + the ability to predict production schedules, plan physical attacks, and impersonate operator telemetry in social-engineering follow-ons.
Source: Dragos 2024 PI Historian Threat Analysis; AVEVA PI Server Security Configuration Best Practices.
Vendor Remote Access
Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix
SCADA vendors (Emerson DeltaV, Honeywell Experion, Rockwell ControlLogix, Schneider Wonderware, AVEVA) provide remote support via dedicated modem banks + secure-access gateways. Many of these remote-access endpoints run on aging modem firmware with documented vulnerabilities — and the credential rotation on these modems is operator-dependent (the vendor uses one shared credential per operator site). Vendor credential compromise cascades across multiple operators (ENGlobal as the documented third-party integrator cascade).
Source: CISA ICS Advisories on Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix 2024-2025 + ENGlobal Corp SEC filings Nov 2024.
What CoreRecon Delivers — TX Oil & Gas SOC

OT-aware SOC. SCADA-aware threat hunts. SD-02F authorship. SEC Item 1.05 disclosure workflow. RRC §3.71 reporting pathway.

CoreRecon is an SDVOSB-certified MSSP purpose-built for TX oil & gas operators. We deliver SCADA-aware SOC coverage in tier — Sentinel covers the IT half of the convergence (VPN hardening, MFA, EDR, credential rotation); Fortress adds OT-VLAN segmentation + cellular-RTU gateway monitoring + pre-authorized SCADA isolation playbook; Command adds SD-02F CIP authorship, SEC Item 1.05 disclosure workflow, RRC §3.71 incident reporting pathway, and the OT-aware threat-hunt cycle that detects Volt Typhoon VOLTZITE pattern.

🛢️
24/7 SCADA-Aware SOC
24/7/365 SOC staffed by Texas-based analysts. SCADA-aware monitoring — we recognize Modbus/DNP3/OPC-UA/EtherNet-IP protocol broadcasts, PI historian tag exfil, cellular RTU gateway anomalies, vendor remote-access modems, Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix configuration events, and SCADA HMI access patterns. Not a generic EDR queue. Real TX analysts who know what oil & gas OT cybersecurity looks like at 3 AM.
Pre-Authorized SCADA Isolation Playbook
The Colonial lesson is pre-authorize the SCADA-isolation decision before the incident. Most midstream operators don't have a pre-authorized OT-IT disconnect playbook — and the resulting panic (Colonial's "we can't bill") causes unsafe shutdowns. CoreRecon's playbook defines the IT-OT logical segmentation, the hardware fail-safe modal hold, the instrumented RTU state-machine restore procedure, and the 4-hour OT-side manual fallback enabling pipeline operation without IT-side billing.
🌐
OT-Aware Threat Hunts (Dragos VOLTZITE)
Quarterly OT-aware threat hunts using the Dragos adversary-TTP feed — including the Volt Typhoon VOLTZITE activity cluster (cellular-RTU/SCADA-gateway credential compromise + IT-network-adjacent-to-OT-VLAN persistence). Hunts are run alongside CoreRecon's 24/7 SOC monitoring; findings produce a documented vulnerability-disclosure deck for the operator's IT + OT leadership.
📑
SD-02F CIP Authorship
TSA SD-02F Cybersecurity Implementation Plan (effective May 3, 2025) authorship + annual review. CIP-as-drafted-not-template-fiction. Includes network segmentation validation evidence, OT/IT access-control matrix, ITA test results, incident response clock-ready narrative templates (12-hr to TSA + CISA), and SD-02F audit-ready format. CoreRecon FAB-tested SD-02F CIP deliverables are in production at multiple TX midstream operators.
📋
SEC Item 1.05 4-Business-Day Disclosure
SEC Form 8-K Item 1.05 (effective December 18, 2023) specifies a 4-business-day cyber-incident disclosure clock from materiality determination for SEC-registered issuers. CoreRecon Command-tier includes the materiality determination framework pre-loaded, the Form 8-K Item 1.05 drafting template, the parallel CIRCIA narrative (72-hr CISA), the RRC §3.71 narrative (TX Railroad Commission), and the 90-day forensic image preservation routine.
⛓️
RRC §3.71 Incident Reporting Pathway
16 TAC §3.71 (TX Railroad Commission pipeline damage-prevention + incident notification) reporting workflow for TX operators. Pipeline-incident classification matrix; RRC online RRC-3000 portal submission template; parallel 4-business-day SEC Item 1.05 narrative + PAD system operator notice + TSA SD-02F evidence preservation. Cyber-induced release reporting path explicitly authorized under HB 1208 (2023) + SB 3 / SB 1928 (2025).
Controls — CoreRecon Coverage

8 controls. Specifically built for the TX oil & gas OT/IT surface.

Sentinel ($89), Fortress ($109–$129), and Command ($2,500+) tiers cover different control families. The 8 controls below are the ones that distinguish an OT-aware SOC from a generic enterprise MDR. Each maps to a specific regulatory surface.

Control 1 — Cellular RTU Gateway Inventory + Hardening
Dragos VOLTZITE mitigation. Fleet-wide inventory of every cellular RTU + SCADA gateway in TX operating territory; vendor-default credential scan; firmware update validation; private cellular APN with strong per-device authentication; quarterly re-validation. The structural mitigation against the most-attacked TX midstream OT surface.
Control 2 — Pre-Authorized SCADA Isolation Playbook
TSA SD-02F + Colonial-pattern mitigation. Documented + tabletested IT-OT logical segmentation; hardware fail-safe modal hold on every RTU + PLC; instrumented state-machine restore + 4-hr OT-side manual fallback enabling pipeline operation without IT-side billing; tested full isolation in under 30 minutes; replay test quarterly. Pre-authorizes the disconnect decision before the incident (vs. the Colonial panic pattern).
Control 3 — PI Historian Exfil Defense
Operational-telemetry confidentiality. DLP-class enforcement on PI historian outbound traffic; alert on bulk-tag export; outbound whitelist enforcement; quarterly review of historian access log; 7-year retention with cryptographic integrity (per FERC + PHMSA recordkeeping requirements where applicable). Defends operating-data confidentiality against advanced persistent threat exfiltration of production-schedule data.
Control 4 — SCADA Vendor Remote-Access Inventory
ENGlobal-style third-party-integrator mitigation. Inventory every Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix / Schneider Wonderware / AVEVA remote-access endpoint; per-vendor credential rotation; jump-host mediation; recorded session capture; quarterly vendor-security review. The structural mitigation against SCADA-vendor cascade compromise.
Control 5 — VPN Phishing-Resistant MFA
Colonial trigger-pattern mitigation. Phishing-resistant FIDO2/WebAuthn MFA on every VPN credential — no SMS, no calls, no push-only. Conditional access policies tied to device posture. Mandatory MFA enforcement with no legacy-auth bypass. PAM for administrative distributed engineering accounts. Quarterly MFA fatigue-test training for IT + OT staff.
Control 6 — SEC Item 1.05 Materiality Framework
Public-issuer disclosure readiness. Documented materiality determination framework pre-loaded for SEC-registered issuers; Form 8-K Item 1.05 drafting template; parallel CIRCIA narrative template; parallel RRC §3.71 narrative template; 90-day forensic image preservation; 10-K cost-accounting categories pre-staged for Halliburton-pattern disclosure (incident response, recovery, restoration, lost revenue).
Control 7 — RRC §3.71 Incident Reporting Workflow
TX-only regulator coverage. Pipeline-incident classification matrix (per 16 TAC §3.71 + HB 1208/SB 1928 cyber-induced-release language); RRC online RRC-3000 portal submission template pre-loaded; PAD system operator notice template; paralel SEC Item 1.05 + CIRCIA narrative; tested by full table-top exercise annually.
Control 8 — Cyber Insurance Posture Alignment
Insurance renewal readiness. Documentation of every insurer-acceptable control (MFA on every VPN + remote-access, EDR with 24/7 SOC monitoring, immutable backups w/ quarterly restore-test, tested IR plan against the actual incident timeline, OT/SCADA segmentation w/ evidence, SEC Item 1.05 / CIRCIA / TSA SD-02F reporting workflow). Maps directly to re-opening full-capacity cyber-insurance tower at renewal.
SDVOSB + 30-Min IR SLA — Two Wedges No Texas MSSP Can Match

Service-Disabled Veteran-Owned. Plus Contractual 30-Min SLA. Two structural advantages.

SDVOSB certification counts toward DFARS 252.219-7003 small-business subcontracting goals on every DoD prime contract. When a DLA Energy prime or Defense Logistics prime bundles CoreRecon SCADA-aware SOC into their subcontract stack, it simultaneously hardens their defense fuel supply chain's CMMC posture (reducing their flow-down liability) AND counts toward their SDVOSB utilization goal. Texas oil & gas operators who serve the defense fuel supply chain can claim both.

SDVOSB
Service-Disabled Veteran-Owned Small Business. Certified by the VA's SBA Veteran Small Business Certification (VetCert) program. CVE-verified. USMC veteran-led team. When DoD primes bundle CoreRecon managed SOC into their defense fuel-supply-chain subcontract stack, the spend counts toward their DFARS 252.219-7003 SDVOSB utilization goal — independently billable, fully documented, and federal-contract compliant.
🎖️
SDVOSB Status — VetCert Verified
CoreRecon is verified through the VA's VetCert program. Active and current. Directly billable under prime contractor small-business subcontracting plans. CVE-database lookup confirms status. CAGE code, NAICS codes (541512, 541511, 561621), and prior performance data provided to your contracting officer on request.
📋
DFARS Defense Fuel Supply Chain Coverage
Where your TX oil & gas operation serves DLA Energy contracts (jet fuel, marine fuel, MILSPEC lubricants), DFARS 252.204-7021 makes CMMC certification a condition of award. DFARS 252.204-7012 72-hour DIBNet disclosure clock applies. CoreRecon Command-tier publishes the SSP, the POA&M, and the 72-hour DIBNet disclosure workflow authorized by a vCISO accountable for the SPRS score in PIEE.
⏱️
30-Min SD-02F SLA
Contractual 30-min IR SLA — detection-to-containment within 30 minutes of confirmed alert. TSA SD-02F specifies a 12-hour CISA cyber-incident reporting window. A 30-min SLA gives your SD-02F/CIRCIA/SEC Item 1.05 disclosure team 11.5 hours to draft the four parallel narratives, preserve the 90-day forensic image, file the SEC Item 1.05 8-K, and notify the Railway Commission. Industry MSSP average: 1–4 hours. CoreRecon: 30 minutes or less.
30/60/90 Roadmap — TX Oil & Gas / SD-02F Prep

Three months from baseline to SD-02F-ready for most TX midstream operators.

This roadmap assumes a typical 50–250 endpoint TX midstream operator with existing IT SOC coverage but partial OT-side segmentation + no documented SD-02F CIP. Adjust for your actuals — but the sequencing (identity → OT segmentation → SD-02F authorship → pre-authorized SCADA isolation) is the pattern most TX operators follow.

Phase Focus Key Deliverables
Day 1–30 Identity & Access Hardening Phishing-resistant FIDO2/WebAuthn MFA on every VPN — Colonial pattern mitigated; admin account inventory; vendor-default credential scan on cellular RTUs + SCADA gateways + DeltaV/Experion/ControlLogix modems (Dragos VOLTZITE mitigation); TSA SD-02F baseline scoping against pipeline + LNG operator scope; CMMC L2 baseline scoping (where defense-adjacent); quarterly SPRS submission to PIEE (if defense fuel supply chain).
Day 31–60 Detection & Segmentation OT-IT VLAN segmentation with hardware fail-safe modal hold; cellular RTU/SCADA gateway behavioral EDR coverage; PI historian outbound-traffic DLP enforcement; tabletested pre-authorized SCADA isolation playbook; quarterly OT-aware threat-hunt cycle (Dragos VOLTZITE-aware); SEC Item 1.05 4-business-day disclosure workflow authorship; RRC §3.71 incident reporting workflow authorship.
Day 61–90 SD-02F & CMMC Readiness SD-02F Cybersecurity Implementation Plan authored + tabletested; CIP-as-drafted-not-template-fiction; 90-day forensic-image-preservation routine documented; SEC Item 1.05 materiality determination framework pre-loaded; RRC §3.71 RRC-3000 submission portal template pre-loaded; tabletop exercise with PUCT docket contact + ERCOT QSE contact + CISA CIRCIA POC + RRC; TSP SD-02F audit-ready format validation.
Transparent Pricing — Oil & Gas Edition

Published Rates. Month-to-Month. SDVOSB-Set-Aside Eligible.

Three tiers. Per-endpoint. All include 24/7 SOC coverage, 30-min IR SLA, and OT-aware threat-hunt cycle. Command tier is the SD-02F + SEC Item 1.05 + RRC §3.71 + CMMC-ready path — the playbook + document authoring by vCISO.

Sentinel
$89/endpoint/mo
Min. 10 endpoints • Month-to-month
  • 24/7 SOC monitoring — TX-resident, OT-aware analysts
  • EDR with phishing-resistant MFA on IT-side admin plane
  • VPN credential-rotation playbook + admin-baseline
  • TSA SD-02F scoping (in-scope pipeline + LNG operator scope)
  • Annual security awareness training with completion records
SLA Proof — What 30-Min Really Means

The 30-min SLA isn't marketing. It's a number on the clock.

Industry-average MSSP IR response: 1–4 hours. Volt Typhoon kill-chain window: per CISA Joint Advisory AA24-038A, the actor lives off the land with built-in admin tools — meaning the attacker dwell time at pre-positioning is months, but the active exploitation window (Halliburton Aug 2024 pattern) is minutes. TSA SD-02F specifies a 12-hour CISA cyber-incident reporting window. SEC Form 8-K Item 1.05 specifies a 4-business-day disclosure clock from materiality determination. CIRCIA specifies 72-hours. RRC §3.71 has its own internal deadlines. A 30-min containment SLA gives the four parallel-narrative disclosure teams 11.5 hours to draft, preserve forensic evidence, file the SEC Item 1.05 8-K, and notify the Railroad Commission.

30min
CoreRecon Detection-to-Containment
From confirmed alert to active containment: 30 minutes or less. Contractual. Measured monthly. Reported to your operations + IT leadership in your service review.
FAQ — Texas Oil & Gas Operators Ask

Answers before your next security review.

Which Texas oil and gas operators fall within TSA SD-Pipeline and SD-02F scope?
TSA Security Directives apply to the operator categories and lists designated by TSA, including covered hazardous-liquid and natural-gas pipeline and LNG operators; scope is not determined by endpoint count alone. Operators outside a directive can still face 49 CFR Parts 192 or 195, RRC obligations, customer requirements, and insurer expectations. Confirm the current TSA designation, document the boundary, and maintain the required Cybersecurity Implementation Plan where applicable.
How should an SEC registrant prepare for the Item 1.05 clock?
SEC Item 1.05 requires a Form 8-K disclosure within four business days after determining that a cyber incident is material, not simply four days after detection. Define the materiality decision path, preserve forensic facts, pre-stage disclosure ownership and counsel review, and keep the SEC analysis coordinated with TSA, CIRCIA, RRC, and insurer reporting clocks.
How should oil and gas operators segment SCADA and remote access?
Separate enterprise IT, OT control networks, safety systems, historians, cellular RTUs, and vendor remote-access paths according to operational need. Use tightly governed jump hosts, phishing-resistant MFA, least privilege, allowlists, session logging, and a pre-authorized isolation procedure that keeps safe operations available. Test the procedure so a compromise in billing or VPN access does not force an avoidable shutdown.
Why CoreRecon
24/7 Texas-based SOC
Attacker-minded posture
Experience in Oil & Gas
Contractual 30-minute response promise
Research Brief — August 2026
TX Oil & Gas Threat Brief 2026: OT/ICS Ransomware, Pipeline SCADA & TX Railroad Commission Reporting
5 named TX oil & gas anchors. Halliburton $35M (SEC 8-K Item 1.05). Colonial Pipeline shutdown. Dragos VOLTZITE cellular-RTU vector. TSA SD-02F (May 3, 2025) + SEC Item 1.05 4-business-day + CIRCIA 72-hr + RRC 16 TAC §3.71 + TDPSA §541. 60+ verified sources. Source-tagged PDF emailed to your work address.
Download Brief →
Free SCADA / OT Posture Review — $2,500 Value

Five regulators. Four parallel-narrative clocks. SD-02F effective May 3, 2025. Get your SCADA / OT posture baseline before the next material incident forces disclosure.

We deliver an OT-aware posture review across all five regulator surfaces (TSA SD-02F + SEC Item 1.05 + CIRCIA + RRC 16 TAC §3.71 + TDPSA §541), identify the OT/IT segmentation gaps most likely to force disclosure, and deliver a prioritized remediation plan aligned to SD-02F CIP authorship + pre-authorized SCADA isolation playbook + 30-min IR SLA. No credit card. SDVOSB-certified. TX-resident analysts. 14-day delivery from contract start.

Free SCADA / OT Posture Review — $2,500 Value →

Delivered within 14 days  •  SDVOSB-certified  •  SCADA-aware SOC  •  TX-resident analysts