OT/IT Security for Texas Energy Companies: Where Convergence Leaves Gaps

Texas energy companies no longer run 2 separate networks. Field gateways, historians, vendor tunnels and shared logins tie the control side to the business side, and attackers now go after that seam on purpose. In the 12 months to August 31, 2026, CISA tagged 177 of its 478 industrial control system advisories as Energy. Here’s where convergence breaks, which Texas rules apply, and what to fix first. For the wider view of how we support operators, start with our oil and gas IT services.

OT/IT security for a Texas energy company means defending the business network and the control systems that run wells, pipelines and power as 1 environment, because they’re already connected. The priorities are removing internet exposure, locking down remote access, segmenting the 2 sides and proving you can run manually.

I’m the CTO at Uprite, and I’ll be blunt about who this is for. It isn’t written for a major utility with a 40-person security operations team. It’s for the operators in between. Mid-sized producers in the Permian, gathering and midstream companies, oilfield service firms in The Woodlands and Midland, and the electric co-ops and municipal utilities that keep the lights on across the ERCOT footprint.

Those companies share one problem. Nobody ever decided to merge IT and OT. It just happened. One useful connection at a time, approved by sensible people, and never drawn on the network diagram that the next engineer or auditor would be handed.

So this post doesn’t repeat the usual advice. It uses a fresh count of every industrial advisory CISA published over the last year, the 2026 threat findings for energy, and the rules that actually reach Texas operators. Then it gets specific about the seams we keep finding.

What does OT/IT convergence mean for a Texas energy company?

OT/IT convergence is the point where operational technology, the SCADA servers, PLCs, RTUs and flow computers that move product and power, starts exchanging data and credentials with information technology, the email, ERP and accounting systems that run the business. Once that happens, an intrusion on either side can reach the other.

In Texas energy, the connections are rarely dramatic. Production volumes flow from a historian into accounting so royalty, revenue and land teams can close the month without anyone driving out to read a meter or retyping numbers from a field report. Measurement data feeds gas marketing. A compressor station sends alarms to a cloud dashboard that a field supervisor checks from a phone. An OEM keeps a remote support path open on a skid in Reeves County because driving out costs a day.

Every one of those links is reasonable. Every one saves money. Together, they make the old picture of an isolated control network fiction.

If you run a plant rather than a pipeline, the failure patterns look a little different, and we covered them in what Texas manufacturers get wrong about OT/IT security. Energy adds distance. Lots of it. Your control assets are spread across hundreds of miles of lease roads, and most of them talk over cellular or radio.

What did a year of CISA advisories show about energy OT?

We wanted a number nobody else had published. So we counted. All of it.

On September 17, 2026, we pulled every industrial control system advisory in CISA’s public CSAF repository with an initial release date between September 1, 2025 and August 31, 2026. That’s 478 ICSA advisories, medical device advisories excluded. We read the critical infrastructure sector field on each one, then scored the vulnerabilities inside the ones marked Energy.

What we measuredAdvisoriesShare
ICS advisories CISA released in the 12 months478100%
Advisories that list the Energy sector17737.0% of all advisories
Energy advisories with a CVSS base score of 9.0 or higher5631.6% of Energy advisories
Energy advisories with an authentication or credential weakness4123.2% of Energy advisories
Energy advisories where the vendor had no fix available or planned for at least 1 product105.6% of Energy advisories

Energy was the second most common sector tag, behind Critical Manufacturing at 331. Those 177 advisories carried 592 individual vulnerabilities. Siemens and Schneider Electric led with 28 advisories each, followed by Hitachi Energy at 16 and ABB at 15.

The weakness list is the part I’d show a board. Improper input validation topped it at 54 vulnerabilities. Second was CWE-306, missing authentication for a critical function, at 35. That’s a device that performs an important action, such as changing a setpoint, uploading new logic or restarting a process, without first checking who asked or whether they should be allowed to ask at all. You can’t configure your way out of that. Not really. You can only keep strangers from reaching it.

A caveat on method. An advisory can list several sectors, scores mix CVSS versions 3 and 4, and CISA’s tags describe where a product is deployed, not whether it’s in your field. Still, nearly 1 in 3 energy advisories rated critical. That’s a lot. It’s a patching workload most operators can’t absorb during production, especially when each fix needs vendor approval, a tested backup and a maintenance window that operations has already promised to someone else.

How are attackers actually getting into Texas energy networks?

Mostly through the IT side. And the remote paths. Rarely through exotic control system malware.

Dragos’s 2026 oil and gas findings put numbers on the gaps its teams found in the field. Poor IT/OT segmentation showed up in 29% of oil and gas findings, the highest share of any sector. Default or weak credentials appeared in 26%. Malware protection and detection gaps appeared in 37%. The same report describes VOLTZITE compromising cellular gateways across U.S. midstream operations, then pivoting to engineering workstations to take configuration files and alarm data.

That’s the Volt Typhoon ecosystem, and it isn’t alone. In its February 2026 year in review, Dragos described a new group, SYLVANITE, that exploited Ivanti vulnerabilities at U.S. electric and water utilities, pulled Active Directory credentials and handed footholds to VOLTZITE. Notice the target. A VPN appliance. The corporate directory. Pure IT.

The less sophisticated crowd uses even simpler tools. In May 2025, CISA, the FBI, EPA and DOE warned that unsophisticated actors were targeting ICS and SCADA systems in oil and natural gas, using basic intrusion techniques against exposed assets. Then in April 2026, joint advisory AA26-097A described Iranian-affiliated actors exploiting internet-exposed Rockwell Automation PLCs across Energy and other sectors. The July 22 update added Schneider Electric and Siemens devices to the list. The advisory also describes altered HMI and SCADA displays and logic changes that disabled shutdown and alarm functions, which means an operator’s screen can look normal while the process isn’t.

Closer to home, the pattern holds. Newpark Resources, based in The Woodlands, reported a ransomware incident detected on October 29, 2024 that disrupted financial and operating reporting systems. Its manufacturing and field operations kept going, in the company’s words, by utilizing established downtime procedures. Hold that phrase. It matters. We’ll come back to it.

Pipeline control room operator pointing at SCADA trend screens that could be altered in an OT attack

Which Texas rules shape OT/IT security, and for whom?

It depends on which part of energy you’re in. That’s my first question. Always.

Where you operateWhat sets the barWhat it pushes on the OT/IT seam
TSA-designated pipelines and LNG facilitiesTSA Security Directives Pipeline-2021-01G and 2021-02G, the 02 series reissued May 1, 2026Segmentation, access control, continuous monitoring, and tested incident response and contingency plans
Generation and transmission on the bulk electric systemNERC CIP standards, including CIP-015-1 for internal network security monitoringWatching traffic inside the trusted zone, not just at the perimeter
Transmission and distribution utilities, municipal utilities and co-ops in ERCOTThe Texas Cybersecurity Monitor Program created by SB 936 in 2019Self-assessments reviewed by the PUCT’s cybersecurity monitor, plus outreach on emerging threats
Producers and oilfield service companiesMostly customer, insurer and investor expectations, plus SEC disclosure rules for public companiesEvidence that remote access, backups and incident response actually work
Texas businesses under 250 employeesThe SB 2610 safe harbor, effective September 1, 2025A recognized framework, adopted and documented, before a breach

A few notes on that table. TSA lists every pipeline directive revision, and the 02 series, first issued in 2021, is now on revision G. FERC approved CIP-015-1 in a final rule effective September 2, 2025, with a phased implementation plan. And ERCOT describes the monitor program as a PUCT and ERCOT contract under Section 39.1516 of the Utilities Code, open by election to utilities outside ERCOT too.

The state is also building capacity of its own. The Texas Cyber Command, created by HB 150 in 2025 and headquartered in San Antonio, lists critical infrastructure in its mandate. On August 31, 2026, GovTech reported that TIPRO president Ed Longanecker said Texas energy companies now operate on the assumption that hostile actors may already have undetected access. I think that’s the right posture. It’s also a humbling one.

For the full rulebook on the oil and gas side, including API 1164 and NIST SP 800-82, see our guide to IT compliance for Texas oil and gas operators. The small-business shield is covered in our Texas SB 2610 guide.

Where does convergence usually break in an energy operation?

In the same 5 places. Over and over. Here they are in the order we check them.

  1. Cellular gateways and field modems. Many were installed by a vendor, kept default settings and never landed on anyone’s asset list.
  2. Shared identity. A domain account that works on the office network and on the SCADA servers turns 1 phished password into control system access.
  3. Data paths out of OT. Historians, measurement systems and cloud dashboards often have inbound connections nobody meant to allow.
  4. Vendor and OEM remote access. Standing tunnels with shared logins, no multifactor authentication and no session record.
  5. Flat networks at remote sites. The camera, the PLC, the gate controller and the field laptop sit on one segment because it was quicker.

The SANS State of ICS/OT Security 2025 report backs up the ranking. Half of the ICS/OT incidents its respondents reported started with external connectivity or remote access, and 31% of organizations had no formal inventory of their remote access points. Only 23% required jump-host session brokering. You can’t lock down a path you haven’t listed. Start the list.

Here’s my honest take on number 2. Shared identity is the one operators resist fixing, because a separate OT domain feels like overhead for a small team that already covers help desk tickets, field laptops, phone systems and the occasional midnight call from a pumper who can’t log in. I understand that. Fully. But when a directory credential is the prize, as it was in the SYLVANITE intrusions, a shared domain is the bridge. Split it, or at least require separate privileged accounts with their own MFA for anything in the control zone.

Engineer patching network cables in a field enclosure to separate business and control networks at a Texas energy site

What should a Texas energy company fix first?

Start with the cheap, boring controls that close the doors attackers actually use. CISA’s primary mitigations for OT point the same way.

  1. Remove control devices from the public internet. Scan your own address space from the outside and put anything that answers behind a gateway.
  2. Change every default password and put multifactor authentication on each remote path, including the vendor ones.
  3. Build a real boundary between business and control networks, with a DMZ for historians and data transfers.
  4. Keep offline copies of PLC and RTU logic, and compare them against running code on a schedule.
  5. Write and rehearse manual operating procedures for the day the network isn’t trustworthy.
  6. Add passive, protocol-aware monitoring so you can see traffic without probing fragile devices.

None of that requires a shutdown. Not one item. Most of it needs a decision, a diagram and a few weeks. The network work is what our network security services team does every day, and it’s the part general IT providers most often skip because they can’t see the field side.

What can wait? Replacing every legacy controller. Seriously. It’s expensive, it needs outages and it rarely beats the return on segmentation and access control. Plan hardware refreshes around your capital cycle, use compensating controls such as tighter firewall rules and brokered access in between, and write down each exception so the next auditor, insurer or new hire can see why it exists.

Why does manual operation matter so much?

Because it’s the control that still works when every other control has failed.

Go back to Newpark. Its information systems were disrupted, yet field work continued on established downtime procedures. Now look at a public utility example from the Panhandle. According to the same GovTech report, attackers manipulated a tank level control at Muleshoe’s water utility in January 2024, causing an overflow that lasted 30 to 45 minutes until city officials disconnected the system and switched to manual operation. Different sector. Same lesson. The people who could run it by hand limited the damage.

So test it. This month. Pick 1 compressor station or 1 substation and ask 3 questions. Who decides to isolate it? How do operators run it without SCADA? And how long can they keep that up before safety or contracts force a stop? If the answers live only in someone’s head, that’s your first finding. Write them down. It’s also the backbone of a sound disaster recovery plan for Texas businesses, because the same runbook covers a hurricane, a fiber cut and a ransomware event.

Is a quiet year proof your OT security works?

No. Usually it’s proof nobody was looking.

Dragos measured average ransomware dwell time in OT environments at 42 days in its 2026 report, and in 13% of its 2025 incident response cases the malware ran silently without triggering a single alert, which means someone was inside for weeks while every dashboard stayed green. SANS found that 22% of organizations had an ICS/OT incident in the prior 12 months. You only count an incident you can see. A field network with no sensors reports nothing, and nothing looks a lot like safe.

The fix isn’t a bigger alert queue. Nobody reads those. It’s a small amount of visibility at the right choke points, such as the IT/OT boundary, the remote access broker and the historian DMZ, watched by people who can tell a normal Modbus poll from a strange one at 2 in the morning.

Oilfield operations manager and IT engineer reviewing manual operating procedures with storage tanks outside the window

How does Uprite handle OT/IT security for energy clients?

We own the IT side and the boundary. We don’t write PLC logic, and we don’t pretend to be your controls integrator.

That split is deliberate. Your integrator knows the process. We know identity, networks, endpoints, backups and monitoring, and we’ve learned that most of the risk in a Texas energy environment sits in exactly those unglamorous places rather than inside the controller. Both matter. The trouble always sits between those 2 scopes, so our job is to make the seam somebody’s documented responsibility, with the controls engineer keeping a veto over anything that touches production.

Uprite has served Texas businesses since 1999, and our team of 42 works from Houston, Dallas and San Antonio. One Texas oil and gas client came to us with aging servers, weak backups and a specialized operational platform it couldn’t replace. We stabilized the environment around that platform instead of forcing a migration, and the oil and gas IT modernization case study walks through the order we did it in.

If your operations center is on the Gulf Coast, our Houston oil and gas IT team is the closest fit. The broader security stack, from managed detection to incident response, sits on our cybersecurity solutions page. And the stakes keep growing. The state produced about 42% of U.S. crude oil in 2025, according to EIA production data, so the target isn’t getting smaller either.

Questions Texas energy operators ask about OT/IT security

Do TSA pipeline security directives apply to my company?

Only if TSA has designated your pipeline or LNG facility as critical, and TSA notifies those owners directly. If you haven’t been notified, the directives don’t bind you, but midstream customers and insurers increasingly expect the same segmentation, access control and incident response the directives require.

Is an air gap still realistic for SCADA in Texas oil and gas?

Rarely. Production accounting, measurement, vendor support and mobile alarms all need data to leave the control network, so most operators have connections they don’t fully track. A documented, monitored boundary with a DMZ is more honest and easier to defend than an air gap on paper.

What should we do about cellular gateways at remote sites?

Inventory them first, then change default credentials, restrict which addresses can reach them and put their management behind multifactor authentication. Dragos reported in 2026 that VOLTZITE compromised cellular gateways across U.S. midstream operations, so these devices deserve the same attention as a firewall.

Can an IT managed service provider secure OT safely?

Yes, if it respects the boundary. A good provider secures identity, remote access, the IT/OT perimeter, backups and passive monitoring, and it leaves controller logic and process changes to your controls engineers. Ask any provider to put that division of responsibility in writing before work starts.

How often do energy OT vulnerabilities come out?

Often. In the 12 months to August 31, 2026, CISA published 177 industrial control system advisories that list the Energy sector, about 3 or 4 a week, and 56 of them carried a CVSS score of 9.0 or higher.

Where should a small co-op or producer start with a limited budget?

Start with remote access. Put multifactor authentication on every path into the control network, remove anything exposed to the internet and write down how operators run key sites by hand. Those steps cost little and close the routes CISA and SANS see most. Then build the IT/OT boundary.

Not sure how many paths lead into your control network? Uprite maps your remote access, the IT/OT boundary and your manual fallback, then tells you plainly what to fix now and what can wait for the next planned outage.

Speak to an IT Expert

About Author

Learn More