M ManySignal

Oil & Gas

Protect pipeline SCADA and upstream operations from Triton-scale threats

Triton/Trisis, Industroyer2, and the Colonial Pipeline ransomware attack demonstrated that oil and gas critical infrastructure faces sophisticated, consequences-maximising attackers. ManySignal monitors OT networks, SCADA access, and IT/OT boundaries — with TSA Security Directive compliance built in.

$4.5M

Colonial Pipeline ransom — and $5B in economic disruption

12 hrs

TSA Security Directive incident notification window to CISA

Triton

First malware targeting safety instrumented systems — petrochemical plant

SD-02E

TSA directive mandating cybersecurity plans for critical pipelines

How ManySignal protects oil and gas operations

Pipeline SCADA and control system monitoring

Oil and gas SCADA systems controlling pipeline compression, valve operations, and custody transfer points are regulated by TSA Security Directives. ManySignal integrates with OT security platforms monitoring DCS, PLC, and RTU communications on Modbus, DNP3, and OPC-UA protocols — correlating control system anomalies with IT identity and network events.

  • Abnormal remote access to pipeline SCADA systems
  • TSA Security Directive SD-02E control monitoring
  • Custody transfer system integrity monitoring

Pipeline SCADA and control system monitoring

Upstream operational data and reservoir model protection

Seismic survey data, reservoir simulation models, and field production data are high-value assets targeted by competitor intelligence operations and nation-state actors. ManySignal monitors access to seismic interpretation platforms (Petrel, Kingdom), reservoir simulation tools (Eclipse, CMG), and production databases — detecting bulk access and exfiltration attempts.

  • Petrel and Kingdom seismic data access baselining
  • Reservoir model bulk export anomaly detection
  • Contractor access to asset-specific exploration data

Upstream operational data and reservoir model protection

Offshore and remote operations monitoring

Offshore platforms and remote production facilities connect to onshore operations via satellite and MPLS links with limited bandwidth and high latency. ManySignal's detection engine operates in edge-deployment mode at remote sites, with event correlation and escalation to the onshore SOC. It detects unauthorised remote access to Distributed Control Systems (DCS) and vessel management systems.

  • Remote site edge deployment with onshore SOC escalation
  • Satellite link anomaly detection — unusual traffic to operational systems
  • Vessel management system access monitoring for offshore assets

Offshore and remote operations monitoring

Standards and regulations supported

TSA Security Directives SD-02D/EIEC 62443NIST SP 800-82 Rev 3API Standard 1164 (Pipeline SCADA)FERC CIPNERC CIP (electric operations)NIS2 (EU operators)UK CAF (NCSC)

Oil and gas security — common questions

How does ManySignal support TSA Security Directive compliance for pipeline operators?

ManySignal addresses TSA SD-02D and SD-02E requirements for critical pipeline and LNG facility operators: network segmentation monitoring (detecting connections across OT/IT boundaries), access control monitoring for OT systems (privileged access to SCADA from IT networks), and incident reporting (the 12-hour notification requirement to CISA for confirmed or potential cyberattacks). Evidence packages are formatted for TSA assessment reviews.

Can ManySignal monitor Honeywell, Emerson, or Yokogawa DCS systems?

ManySignal monitors DCS environments via integration with the OT security platforms that operate passively on DCS networks — Claroty, Nozomi, and Dragos all support Honeywell Experion, Emerson DeltaV, and Yokogawa CENTUM. ManySignal ingests structured telemetry from these platforms and correlates control system events with IT identity events in the entity graph. No agents are deployed on DCS hardware.

How does ManySignal address the Triton/Trisis malware threat against safety systems?

Triton targeted Safety Instrumented Systems (SIS) — specifically Schneider Electric Triconex — by manipulating safety controllers to disable safety shutdowns. ManySignal detects Triton-related indicators: unusual communication between engineering workstations and SIS hardware, Triconex proprietary protocol anomalies, and lateral movement from IT networks toward safety system segments. Detection is based on the TTPs documented in CISA ICS Advisory ICSA-18-240-01.

Does ManySignal integrate with Honeywell Forge or Emerson's operational technology platforms?

ManySignal can ingest security events from Honeywell Forge Security, Emerson's Plantweb Digital Ecosystem, and Yokogawa's OpreX security offerings via their syslog or REST API log outputs. This allows integration with plant-specific security tooling while consolidating alerts in ManySignal for correlation with IT events and centralised SOC response.

How does ManySignal support monitoring for LNG facilities under FERC jurisdiction?

FERC's Critical Infrastructure Protection (CIP) standards for LNG facilities under 18 CFR Part 380 require cybersecurity programmes covering access controls and incident response. ManySignal provides continuous monitoring evidence aligned to FERC's cybersecurity assessment framework, and supports the incident reporting requirements to CISA and FERC applicable to LNG facility operators.

See OT/SCADA monitoring in action

Walk through pipeline SCADA anomaly detection, TSA Security Directive evidence collection, and Triton-pattern hunting — in one session with our OT security team.