IT compliance for Texas oil and gas operators means aligning your information and operational technology to the security rules that govern pipelines, production data, and public reporting. That includes TSA pipeline directives, API 1164, NIST 800-82, SEC incident disclosure, the Texas Data Privacy and Security Act, and the new SB 2610 safe harbor. Most operators are covered by several at once.
TL;DR. Texas oil and gas operators sit under a patchwork of federal and state security rules, and a partner delivering managed IT services for the oil and gas industry pulls them into one program instead of a stack of disconnected checklists. Pipelines answer to TSA. SCADA and OT lean on API 1164 and NIST 800-82. Public companies report incidents to the SEC within 4 business days. Any business holding Texans personal data falls under the TDPSA, and SB 2610 now offers legal protection to operators who adopt a recognized framework.
What IT compliance actually means for a Texas oil and gas operator
IT compliance is the practice of proving that your technology, data handling, and security controls meet the specific rules that apply to your business. For a Texas operator, that proof spans two worlds most other industries keep separate. There is the IT side, meaning email, ERP, land and lease records, and financial systems. Then there is the OT side, meaning the SCADA, PLCs, and control systems that run wells, compressors, and pipelines.
Uprite builds and maintains that program for producers, midstream companies, and service firms across the state. If you want the full picture of how we scope this work, our oil and gas IT services in Houston page walks through the delivery model. This article is about the compliance layer underneath it.
Here is the honest part. No single agency hands you a compliance certificate for oil and gas. Compliance is assembled from overlapping obligations, and the operator carries the burden of showing each one is met. That is the trap. A company can pass its financial audit, keep its RRC permits current, and still run a control network that would fail every security expectation a regulator looks at after an incident.
The regulations Texas operators actually answer to

The rules break into three buckets. Federal security directives that apply to pipeline and critical infrastructure. Federal reporting and data rules that apply because of who you are or what data you hold. And Texas state law. Here is how they map.
| Rule or standard | Who it applies to | What it requires |
|---|---|---|
| TSA Security Directive Pipeline-2021-02 and later revisions | TSA-designated pipeline and LNG owners and operators | Network segmentation between IT and OT, access controls, continuous monitoring, a TSA-approved Cybersecurity Implementation Plan, an incident response plan, and reporting incidents to CISA |
| API Standard 1164, 3rd Edition | Oil and natural gas pipeline OT environments (SCADA, local controls, IIoT) | Risk assessments, network design, incident response, and physical security for control systems. Voluntary, now harmonized with NIST CSF and IEC 62443 |
| NIST SP 800-82 Rev. 3 | Any operator running ICS, SCADA, DCS, or PLCs | The recognized best-practice benchmark for securing operational technology. Not law, but the standard regulators and insurers measure you against |
| IEC 62443 | Operators securing industrial automation and control systems | Lifecycle security for the whole control environment, not just SCADA |
| SEC cybersecurity disclosure rules | Publicly traded operators and their subsidiaries | Disclose a material cybersecurity incident on Form 8-K within 4 business days of the materiality decision, plus annual risk and governance reporting |
| Texas Data Privacy and Security Act (TDPSA) | Almost any company doing business in Texas that handles personal data | Reasonable administrative, technical, and physical safeguards, data protection assessments, and consumer rights responses within 45 days |
| Texas SB 2610 safe harbor | Texas businesses under 250 employees holding sensitive personal data | Adopt a recognized framework (CIS Controls, NIST CSF, ISO 27001) to earn protection from punitive damages after a breach |
A few of these deserve a note. The TSA directives are the ones with teeth for pipeline operators. After the Colonial Pipeline attack, TSA moved from voluntary guidance to mandatory directives, and it now expects 100% of an operator security program to be assessed every 3 years. If you touch a regulated pipeline, this is not optional.
The TSA reissued pipeline requirements and NIST SP 800-82 Rev. 3 together form the backbone of what a mature OT security program looks like. API 1164, in its 3rd Edition, was deliberately harmonized with both so operators are not chasing three conflicting rulebooks.
One rule that quietly changed the landscape is Texas SB 2610, effective September 1, 2025. It does not force you to do anything. It rewards you. Adopt a recognized cybersecurity framework and you get a legal shield against punitive damages if you are sued after a breach. For a mid-sized Texas operator, that is a compliance investment that pays for itself the first time a plaintiff attorney looks at your program. We break down the mechanics in our Texas SB 2610 compliance guide.
Worth knowing too. The Chemical Facility Anti-Terrorism Standards program, which once governed security at facilities holding certain chemicals, lapsed in July 2023 and CISA can no longer enforce it. Some operators read that as one less thing to worry about. The smarter read is that the security expectations did not disappear, they just lost their enforcement wrapper, and insurers and courts still expect those controls.
Why oil and gas gets hit harder than almost any other sector

Oil and gas is a target because disruption is expensive and visible. A ransomware crew that locks up a hospital gets paid because lives are at risk. One that locks up a pipeline gets paid because fuel stops moving and the whole country notices within a day.
The numbers back this up. Ransomware attacks on the oil and gas industry jumped 935% between April 2024 and April 2025, according to Zscaler. The Colonial Pipeline attack in 2021 shut the largest refined-products pipeline in the country for 6 days, triggered panic buying across 17 states, and cost the company a $4.4 million ransom plus a proposed federal penalty near $1 million. The entry point was almost insultingly simple, a single VPN password with no multi-factor authentication behind it. In August 2024, a RansomHub breach of Halliburton cost the company roughly $35 million after it had to shut down IT systems.
What ties these together is the same lesson every time. The attackers rarely break the OT directly. They walk in through IT, an unpatched VPN, a phished credential, a flat network, and then move sideways into the systems that actually run the physical operation. That is why layered cybersecurity and IT and OT segmentation are not buzzwords for this industry. They are the difference between a contained incident and a national headline.
Where IT and OT compliance overlap, and where operators slip

Most compliance failures in oil and gas happen in the seam between IT and OT. The IT team owns the corporate network and knows security. The OT team owns the control systems and knows they cannot take a well offline to install a patch. Neither owns the space in between, and that is where attackers live.
The TSA directives spell this out plainly. They require network segmentation so OT keeps running safely even if IT is compromised, and the reverse. NIST 800-82 says the same. The recurring mistakes we see when we take over an operator environment look like this.
- Flat networks where a laptop in accounting can reach a compressor controller with no barrier in between
- Remote access into SCADA with shared passwords and no multi-factor authentication
- No inventory of what OT devices even exist, which makes assessing 100% of security measures impossible to prove
- Incident response plans written for IT that go silent the moment a control system is involved
- Backups of business data with nothing protecting the control system configurations
None of these are exotic. They are the boring gaps that pass a surface audit and fail an incident. Closing them is the actual work of compliance, and it needs someone who speaks both languages.
How a managed IT service provider closes the oil and gas compliance gap

This is where a managed IT service partner built for the oil and gas industry earns its place. A generalist IT company can secure your email and laptops. It usually cannot touch your SCADA, and it will not know that a TSA directive expects a specific implementation plan on file. The gap is domain knowledge, and it is the whole game.
A capable partner does a handful of things that map directly to the rules above.
- Builds and documents the IT and OT segmentation that TSA and NIST 800-82 require, so a compromise on one side cannot cross to the other
- Maintains the asset inventory and continuous monitoring that let you prove your security posture, not just claim it
- Writes the incident response plan that covers both IT and control systems, then tests it before an attacker does
- Aligns your controls to a recognized framework so you qualify for the SB 2610 safe harbor and satisfy the TDPSA reasonable-safeguards standard
- Handles the fast-clock obligations, like the SEC 4-day disclosure window, so a material incident does not turn into a securities problem on top of a security problem
Uprite runs this for operators through a combination of managed IT services for oil and gas and dedicated security operations. For companies that need round-the-clock threat monitoring on the OT environment, our managed security services team carries that load so your operations staff can stay focused on production. If you want to see the broader industry approach first, the oil and gas solutions overview lays out the verticals we support.
What compliance costs versus what a breach costs
Operators push back on compliance spend until they price the alternative. Here is the comparison that usually ends the debate.
| Line item | Ongoing compliance program | A single serious breach |
|---|---|---|
| Direct cost | Predictable monthly managed services fee | $1.85 million average ransomware cost, before recovery |
| Downtime | Planned maintenance windows | Over half of energy sector victims take more than a month to recover |
| Regulatory exposure | Documented, defensible program | Federal penalties, plus SEC scrutiny for public filers |
| Legal exposure | SB 2610 safe harbor protection | Full punitive damages exposure with no shield |
| Reputation | Quiet, boring, uneventful | Your company name attached to a supply disruption |
The Colonial ransom was $4.4 million. The Halliburton hit was roughly $35 million. A managed compliance program is a rounding error against either number, and it is the version of the story where your name never appears in a headline.
A practical compliance roadmap for a Texas operator
If you are starting from an honest we are not sure where we stand, this is the order that works. It moves fastest through the highest-risk gaps first.
- Inventory every IT and OT asset, because you cannot secure or report on what you cannot see
- Segment the networks so IT and OT cannot freely reach each other, which is the single highest-leverage control
- Lock down remote access with multi-factor authentication everywhere, especially into SCADA and VPNs
- Pick a recognized framework, NIST CSF or CIS Controls, and align to it so SB 2610 and the TDPSA are both covered
- Write and test an incident response plan that includes the control environment and the SEC clock if you are a public filer
- Set up continuous monitoring and a reporting trail so you can prove compliance on demand
- Review and reassess on a schedule, since TSA expects a full assessment cycle every 3 years and threats do not stand still
You do not have to do this in-house. Most Texas operators should not try to. The people who understand your control systems are busy keeping oil moving, and the people who understand SEC disclosure rules usually do not understand a compressor station. Bridging that is exactly what a specialized partner is for.
Build a compliance program that holds up under scrutiny
Uprite secures the IT and OT environments Texas operators depend on, from Houston production offices to Permian Basin field sites. We build the segmentation, monitoring, documentation, and incident response that turn scattered obligations into one program you can defend. Call (866) 570-3065 or request an assessment.
Common questions from Texas operators
Do TSA pipeline directives apply to my company if I only run production wells?
Not directly. The TSA directives target designated pipeline and LNG operators. If you are strictly upstream, you are likely outside their scope, but you still fall under NIST 800-82 expectations, the TDPSA, and SB 2610, and any midstream connection can pull you into a partner requirements.
Is NIST 800-82 a law I can be fined for breaking?
No. NIST SP 800-82 is a guideline, not a statute. What makes it matter is that regulators, insurers, and courts treat it as the definition of reasonable OT security. After an incident, being able to show you followed it is often what separates a defensible position from a negligent one.
How does SB 2610 actually protect an oil and gas operator?
SB 2610 shields qualifying Texas businesses from punitive damages in a data breach lawsuit if they have adopted a recognized cybersecurity framework. It does not stop the lawsuit or cover actual damages, but it removes the exemplary-damages multiplier that turns a manageable claim into a company-threatening one.
We are a public company. What is the SEC deadline if we get breached?
Four business days. Once you determine a cybersecurity incident is material, the SEC requires you to file a Form 8-K describing the nature, scope, and likely impact within 4 business days. The clock starts at the materiality decision, not the breach itself, which makes fast, documented incident response essential.
Can our regular IT company handle oil and gas compliance?
Usually not fully. A standard IT provider can cover email, endpoints, and the corporate network. Oil and gas compliance also requires OT and SCADA expertise, familiarity with TSA and API 1164, and the reporting discipline the SEC and Texas law demand. That combination is what a specialized partner brings.
Where should a Texas operator start if the budget is tight?
Start with network segmentation and multi-factor authentication on remote access. Those two controls block the exact path used in Colonial Pipeline and most oil and gas ransomware cases, and they cost a fraction of a full program. From there, align to a framework so SB 2610 protection kicks in.










