A frank look at cybersecurity risk in oil and gas, from the Strait of Hormuz to a filling station in Badagry.
"An OT-driven disruption inside Nigeria's own oil and gas infrastructure sits on the same transmission line as a war on the other side of the world. It does not need to happen at the Strait of Hormuz to reach the same kitchen table."
In December 2025, attackers hit more than 30 renewable energy and combined heat-and-power facilities across Poland in a single coordinated campaign. They got in through exposed, internet-facing edge devices, then deployed wiper malware that damaged remote terminal units, corrupted firmware, and wiped human-machine interfaces. Operators lost the ability to monitor and control affected sites. Production continued only because automated failsafes held. CISA flagged the incident in a February 2026 alert, warning that the same class of exposed OT and ICS equipment sits across the global energy landscape, oil and gas included.
Operational Technology, or OT, refers to the industrial control systems that operate physical assets such as pipelines, compressors, refineries, pumps, valves, and production facilities. It is distinct from IT, which runs the corporate systems, email, and enterprise software most executives are already fluent in. The two used to be separate worlds. They are not anymore, and that is precisely the risk this article is about.
Three months later, on February 28, 2026, Operation Epic Fury, the US and Israeli campaign against Iran, triggered a wave of Iranian-aligned cyber activity against Western critical infrastructure. A survey of 100 US upstream and midstream OT decision-makers conducted for Tosi in April 2026 found that 99 of 100 operators had experienced at least one cyber incident category since that date. Ransomware affecting OT-connected systems and precautionary OT shutdowns triggered by IT-side incidents each hit 48 percent of operators.
The more troubling finding was not the incident count. It was the gap between confidence and capability. Eighty-seven percent of operators rated themselves confident they could detect an OT breach within 24 hours. But 51 percent said that confidence rested on IT security tools they themselves admitted have limited visibility into OT traffic, and 27 percent said detection would depend on a field technician noticing something wrong. Only 16 percent had OT-native monitoring in place. Separately, Dragos's 2026 year-in-review found oil and gas carried the highest rate of malware detection gaps of any sector it tracks, and that poor IT/OT segmentation was the leading architectural weakness driving lateral movement once attackers were inside.
Read together, these findings describe the same underlying problem from three different angles: the walls between IT and OT have come down faster than the controls needed to govern that convergence have gone up.
Why Convergence Changes the Risk Calculus
For most of its history, OT security depended on separation. Control systems ran on isolated networks, proprietary protocols, and physical distance from the corporate IT environment that faced the internet. That separation is now largely gone. Remote monitoring, predictive maintenance, vendor access for diagnostics, and enterprise reporting all require IT and OT systems to exchange data continuously. The efficiency case for convergence is real. So is the exposure it creates.
The consequence is that an attacker no longer needs to breach OT directly. A phishing email that compromises a laptop on the corporate network can become the entry point to a control system, if the segmentation between the two environments is flat rather than deliberately architected. That is precisely the pattern Dragos and Tosi both describe: incidents that start on the IT side and force precautionary OT shutdowns, and detection tools built for IT traffic that cannot see what is happening on the industrial side once an intrusion crosses over.
This is also why ransomware has become the sector's dominant threat. Zscaler's most recent data shows ransomware attacks against oil and gas surging 935 percent year over year, with groups like Akira expanding their reach through affiliates. Ransomware does not need to understand a specific industrial process to be effective. It only needs to reach a system the operator cannot afford to lose, and OT-adjacent IT infrastructure increasingly qualifies.
This Is Not Just a Western Problem
It is tempting to read Poland, Iran, and US pipelines as a story that happens elsewhere. It is not.
Nigeria's oil and gas sector is the primary driver of the country's foreign exchange earnings and a cornerstone of GDP. That scale is exactly what makes it a target rather than a bystander. In 2021, the Nigerian National Petroleum Corporation was hit by a ransomware attack in which hackers encrypted sensitive data and demanded payment, a domestic reminder that the threat was never hypothetical. Legal and industry analysis of the Nigerian energy sector points to the same structural weakness driving global incidents: aging SCADA and distributed control systems that were never built with security in mind, frequently unpatched, and often lacking the network segmentation that would contain an intrusion instead of letting it spread across an entire operation.
Physical threats have historically dominated the conversation around Nigerian pipeline security. That is changing. As operators digitize, remote-monitor, and integrate IT and OT systems to run more efficiently, the same convergence reshaping risk in the US and Europe is reshaping it here, on infrastructure that in many cases already carries legacy vulnerabilities and thinner security budgets than its Western counterparts. A cyber incident at a Nigerian upstream or midstream facility would not stay contained to that facility. Disrupted production or a forced shutdown at scale touches government revenue, fuel supply, and the broader economy that depends on this sector functioning.
The link between global energy disruption and the price of fuel at a Badagry filling station is not theoretical. It played out this year. When the US and Israel launched Operation Epic Fury against Iran on February 28, 2026, the resulting conflict disrupted shipping through the Strait of Hormuz and pushed crude prices above $100 a barrel. Nigeria's deregulated downstream market transmitted that shock directly to consumers: petrol prices rose roughly 39.5 percent between late February and mid-March, the sharpest increase anywhere in Africa, with pump prices in Lagos climbing past ₦1,200 per litre and transport fares doubling on some routes. In parts of Lagos, the price small businesses pay to run a generator through a power cut rose from around ₦800 to ₦1,400 per litre in the space of months. That is what happens to an ordinary household or shop owner in Badagry, Ajah, or Agege when a geopolitical event thousands of kilometres away disrupts the physical flow of oil.
An OT-driven disruption inside Nigeria's own oil and gas infrastructure, whether from ransomware, a wiper attack, or a poorly segmented SCADA network exploited by an intruder, sits on the same transmission line. It does not need to happen at the Strait of Hormuz to reach the same kitchen table. A forced shutdown or a data-integrity incident at a domestic facility can move through supply, pricing, and production the same way a war on the other side of the world already has. That is the stake behind the security posture question for Nigerian operators: it is not only a corporate risk, but also a live input into what every day Nigerians pay to cook, commute, and keep the lights on.
The regulatory environment has also caught up. The Nigeria Data Protection Act 2023 applies fully to operational and personal data handled across the oil and gas value chain, from employee and contractor records to community and stakeholder data. The NDPC has shown it is prepared to act on non-compliance, including a landmark ₦555.8 million fine issued in 2024. For an oil and gas operator, a cyber incident is no longer only a production or safety event. It is a regulatory exposure with a specific enforcement body behind it.
Convergence raises the stakes everywhere it happens, whether the control room is in Texas or Port Harcourt. Nigerian operators are not exempt from that math. If anything, legacy infrastructure and thinner security budgets mean the margin for error is smaller.
Five Things to Check This Week
Waiting for a full governance overhaul before acting on any of this is itself a risk. Some of the highest-value fixes do not require new budget or a board cycle. They require someone to check, this week, whether they are already true.
- List every third party with remote access to an OT system. If you cannot produce that list today, in full, that is the gap to close first. Unknown access is unmanaged access.
- Confirm multi-factor authentication is active on every remote engineering and vendor connection into OT, not just on corporate email. This single control blocks the entry vector CISA and Dragos cite most consistently.
- Ask whether your OT network is segmented from IT, or whether that diagram is aspirational. A quick technical review will tell you whether a compromised laptop today could reach a control system.
- Pull your last incident response plan and check who is on it. If operations, safety, and engineering are not named alongside IT and security, the plan has not been tested against how an OT incident unfolds.
- Check your Nigeria Data Protection Act compliance status, specifically whether a Data Protection Officer is appointed and breach notification procedures are documented for both personal and operational data across your value chain.
None of these five require a consultant to start. They require ten honest minutes and someone willing to ask the question before an incident asks it for them.
What This Means at Board Level
For boards and C-suite leaders, the practical question is not whether to invest in OT security. Ninety-five percent of operators in the Tosi survey already expect their OT security budgets to grow over the next year, and a quarter expect growth above 20 percent. The real question is where that spending goes, because the wrong allocation reinforces tools that were never designed for OT in the first place. A defensible governance framework should give the board four things it can act on.
Visibility as a standing agenda item, not an incident-response afterthought. Boards should ask a direct question at every risk review: can we currently see what is happening on our OT network, independent of IT tooling, and how do we know? "We would detect it within 24 hours" is not evidence. Confirmed OT-native monitoring coverage is.
Segmentation treated as a control, not a project that finished years ago. Flat network architecture is not a one-time build; it degrades as vendors, remote access points, and new integrations get added. The board should expect a current segmentation posture, not the diagram from the last audit.
Incident response built for OT's actual constraints. Dragos's findings point to a specific weakness: oil and gas incident response plans often fail to account for geographically distributed assets, the organizational boundary between IT and OT teams, and the reality that an operational anomaly may be the only signal an attack is under way. A generic IT incident response plan does not close this gap. Tabletop exercises that include operations, safety, and engineering, not just security and IT, are what test whether it works.
Third-party and remote access as a named risk category. Vendor connections into OT environments are a recurring entry vector across nearly every recent finding. The board should know how many third parties have standing access to OT systems, whether that access requires multi-factor authentication, and whether it can be revoked on demand.
None of these require the board to become technical. They require the board to insist on evidence over confidence, and to treat OT risk as an operational and financial exposure with the same rigor applied to any other material risk category, because at this point, that is precisely what it is.
The Shift Already Under Way
The oil and gas sector's posture is changing, and the direction is right: emergency funding approved, budgets rising, continuous monitoring named as the top capability priority by decision-makers themselves. What the current data suggests is that many organizations are still early in translating that spending into OT-native visibility rather than an extension of IT tools that were never built to see industrial traffic. Boards that ask sharper questions now, before the next Epic Fury-scale event rather than after it, are the ones that will close that gap on their own terms.
The Question Worth Asking Now
If a control system at your operation went dark tomorrow, how would you know, how fast, and who would be responsible for the response?
If that answer is not immediate and specific, that gap is worth closing now, not after an incident forces the question.
Every board knows its financial exposure. Every board should know its operational cyber exposure with the same confidence. The question is no longer whether IT and OT have converged. They already have. The question is whether your governance has caught up.
GRCK works with oil and gas operators to answer exactly that question: a clear-eyed assessment of your OT security posture, segmentation, incident response readiness, and NDPA compliance, delivered with the same rigor we bring to fintechs and financial institutions across Nigeria and North America.
About GRCK
GRCK is a Governance, Risk and Compliance advisory firm specialising in cybersecurity, data privacy, and AI readiness. We work with energy operators, fintechs, and corporates across Nigeria and North America to assess cybersecurity maturity, meet regulatory requirements under the NDPA, and build resilient, audit-ready frameworks that protect operations and the people who depend on them.
Cybersecurity is not just protection. It is continuity.
