SCADA security for a Houston oil and gas company mostly means watching the ways into the control network, which are vendor remote access, IT-to-OT traffic, the Windows machines running HMIs and historians, and field cellular gateways. Your MSP watches those doors. Your controls engineers own what’s behind them.
I’ll start with the part IT providers rarely say out loud. An MSP has no business reprogramming your PLCs, and that includes us. Uprite isn’t a SCADA integrator. Never has been. What a managed IT and security provider can do, and should be held to, is watching every path an attacker would use to reach those controllers, from a vendor’s VPN account to a cellular router at a wellsite. It’s the line we draw in our oil and gas IT services in Houston, and it’s the line this post is about.
That line matters more now. Control rooms in Houston office towers talk to RTUs in the Permian over cellular carriers, historians push production data into cloud dashboards, and the vendor who commissioned your compressor controls in 2019 probably still has a way in. The controller isn’t the weak spot. Everything wired to it is.
So we went looking for evidence instead of opinions. Our team pulled every industrial control system advisory CISA published over the past 12 months and counted what they say about energy equipment. Those counts shaped the monitoring list below. One of them surprised me.
CISA published 486 industrial control system advisories in the 12 months to September 24, 2026, and 186 of them listed the Energy sector. Half of those 186 held a flaw someone could exploit over a network with no password and no click. Every known-exploited bug inside them came from IT software, like Windows, Linux, and Chromium. So an MSP earns its place at the boundary, watching 8 specific things, and stays away from controller logic.
What Does SCADA Security Cover in Oil and Gas?
SCADA security is the set of controls that keeps supervisory control and data acquisition systems, meaning the servers, software, and field devices that run pipelines, compressor stations, and wellsites, from being reached, changed, or shut off by someone who shouldn’t. In oil and gas it runs from a Houston control room to a solar-powered box on a lease road.
OT security is wider. It covers every piece of operational technology, from the distributed control system in a refinery to the automatic tank gauge at a truck terminal. Plant floors have their own version of this fight, covered in what Texas manufacturers get wrong about OT security. SCADA is the slice that spans distance. Distance makes it hard.
Who owns what? Answer that first, because it decides what an MSP can watch without getting in anyone’s way. The layers below follow the Purdue levels your controls team already uses.
| Layer | What sits there in a typical Houston midstream company | Who usually owns it | What the MSP watches |
|---|---|---|---|
| Business network (Levels 4 and 5) | ERP, email, Microsoft 365, Active Directory, accounting | IT or the MSP | All of it. Home turf. |
| IT/OT buffer zone (Level 3.5) | Firewalls, jump hosts, a historian replica, a patch staging server | Shared, which is the problem | Every session and every flow that crosses it |
| Site operations (Level 3) | SCADA servers such as Yokogawa FAST/TOOLS, historians such as AVEVA PI, engineering workstations | Controls engineering or an integrator | Logins, new software, USB use, and backups, with vendor-approved agents only |
| Supervisory control (Level 2) | HMIs and operator consoles | Controls engineering | Alerts from a passive sensor, never an active scan |
| Controllers and field devices (Levels 1 and 0) | PLCs, RTUs such as SCADAPack, flow computers, safety systems | Controls engineering and the equipment maker | Nothing directly. Change alerts only. |
| Field communications | Cellular gateways, licensed radios, satellite links | Nobody, more than you’d think | Firmware, internet exposure, and configuration changes |
Check the last row first. A cellular gateway gets bolted inside a cabinet by a communications contractor, gets a default password and a public IP address, and then quietly falls off every asset inventory the company keeps. IT assumes it’s an OT device. The controls team assumes it’s a network device. Nobody patches it.
What Did a Year of CISA Advisories Say About Energy Systems?
Of the 486 industrial control system advisories CISA published between September 25, 2025, and September 24, 2026, 186 listed Energy as an affected sector. 94 of those, or 50.5%, included at least one flaw exploitable over a network with no credentials and no user interaction.
The method was simple. CISA publishes every ICS advisory in a machine-readable format called CSAF, in its public GitHub repository. We read all 486 files, kept the ones whose critical infrastructure sector field named Energy, and checked each flaw’s CVSS vector for 3 conditions at once, which were a network attack vector, no privileges required, and no user interaction. Then we matched every CVE against CISA’s Known Exploited Vulnerabilities catalog as of September 27, 2026. Nothing fancy.
| What we counted | Energy advisories | Share |
|---|---|---|
| Advisories that listed the Energy sector, out of 486 | 186 | 38.3% of all ICS advisories |
| At least 1 flaw exploitable over a network with no credentials and no click | 94 | 50.5% of the 186 |
| Rated CVSS 9.0 or higher | 59 | 31.7% |
| Missing authentication or hard-coded credentials among the weaknesses | 45 | 24.2% |
| Vendor listed no fix planned or none available for at least 1 flaw | 10 | 5.4% |
| Carried a CVE already on CISA’s known-exploited list | 7 | 3.8% |
Half. That’s the number to remember.
The product names read like the equipment list at a Gulf Coast midstream company. Schneider Electric’s SCADAPack RTUs and RemoteConnect software landed in the remote, no-credential group. Yokogawa’s FAST/TOOLS SCADA platform did too, twice, in February and June, along with Schneider’s Saitel DP RTU. A Veeder-Root TLS4B automatic tank gauge advisory carried a 9.9 score, plus a second flaw the vendor hadn’t fixed yet when it was published. Recognize any of those?
Some fixes aren’t patches. For a set of denial-of-service flaws in the ControlLogix 1756-RM2 redundancy module, every firmware version was affected and Rockwell Automation’s answer was to move to the newer 1756-RM3 hardware module at the next planned outage. That’s a purchase order and an outage window, not a Tuesday night update. Until the swap happens, monitoring is the only control you actually have.
The Known-Exploited Bugs Were IT Bugs
I expected controller flaws. There weren’t any. 7 of the 186 energy advisories carried a CVE that CISA had already listed as exploited in the wild, and every one of those CVEs came from IT software buried inside an industrial product.
- Schneider Electric’s EcoStruxure Foxboro DCS Advisor was affected by CVE-2025-59287, the Windows Server Update Services flaw.
- CVE-2025-32433, an Erlang/OTP SSH bug, turned up in Siemens SINEC OS.
- Fortinet’s CVE-2026-24858 came along with the Siemens RUGGEDCOM APE1808, which runs Fortinet software.
- ABB Ability Zenon? A MongoDB flaw, CVE-2025-14847.
- 2 Chromium V8 bugs in Siemens CADRA.
- One Linux kernel flaw, CVE-2026-31431, hit both ABB Ability Edgenius and a batch of Siemens SIPLUS and SIMATIC products.
Windows update infrastructure. A Linux kernel. A browser engine. A firewall. Every one of those is a name an IT security team already tracks for office servers, and that’s the strongest argument I know for putting an MSP at the OT boundary, as long as it stays there. The skill that catches CVE-2025-59287 on a file server catches it on a DCS workstation. What happens next is different. On the file server you patch tonight. In the control zone you wait for the vendor to qualify the update, and you watch hard until it does.
The catalog tells the same story from the other side. CISA added 308 vulnerabilities to its known-exploited list in those 12 months, and only 2 came from industrial vendors. One was CVE-2018-4063 in Sierra Wireless AirLink ALEOS, the software on a line of rugged cellular routers built for remote industrial sites, added December 12, 2025, more than 6 years after CISA’s first advisory on it. The other was CVE-2021-22681 in Rockwell Automation’s Logix controllers, added March 5, 2026.
The AirLink entry isn’t abstract. Dragos reported that VOLTZITE, the group it associates with Volt Typhoon, compromised Sierra Wireless AirLink cellular gateways to reach US midstream pipeline operations and then pivoted to engineering workstations. A router on a pole. Then the machines that program the controllers.
Old bugs don’t retire. They wait for someone to find the box.
One caveat on method. CISA’s sector tags are broad, so Energy includes electric utility gear alongside oil and gas equipment, and a single advisory can cover dozens of product versions and hardware models at once. Read these counts as a measure of how much your vendors publish, not a risk score for your site. CVSS itself is shaky here, too. The same Dragos report found that 25% of ICS vulnerabilities in 2025 carried incorrect CVSS scores, so treat any count built on those scores, ours included, as directional. We ran a similar count over a slightly earlier window for our OT/IT security guide for Texas energy companies, and the energy share barely moved, from 37.0% in that count to 38.3% in this one. It’s not a spike. It’s the baseline.
What Is the Biggest Cyber Threat to SCADA Systems Right Now?
Someone logging in the way your vendor does. Half of all incidents reported in the SANS 2025 State of ICS/OT Security report began with unauthorized external access, and fewer than 15% of organizations had implemented advanced ICS-aware controls such as session recording or real-time approvals.
Ransomware is the loud version. Dragos tracked 119 ransomware groups going after industrial organizations in 2025, up from 80 the year before, collectively hitting about 3,300 organizations, according to its 2026 OT Cybersecurity Year in Review. The office side of that fight is in our ransomware protection playbook for Houston businesses. The quiet version worries me more. In a May 2025 alert, CISA said it was increasingly aware of unsophisticated actors going after ICS and SCADA systems in oil and natural gas, and that poor cyber hygiene and exposed assets could turn basic intrusion techniques into configuration changes, operational disruption, and in severe cases physical damage.
2 more Dragos findings belong on every MSP’s wall. OT ransomware sat in environments for 42 days on average, against 5 days at organizations with full OT visibility. And Dragos kept seeing OT incidents written off as IT only, because engineering workstations and HMIs run Windows and get filed as IT assets. Think about that for a second. Your RMM console sees an HMI as one more Windows box.
It isn’t.
Houston has already paid for a version of this lesson. Halliburton disclosed in its third-quarter 2024 10-Q that an unauthorized third party got into its systems in August 2024, took information, and disrupted business applications supporting parts of its operations. The company booked a $35 million pre-tax charge for the incident. No controller had to be touched for operations to feel it.
Why Is SCADA Security Different in Houston?
The control rooms are here. Harris County alone had 144 private pipeline transportation establishments and 11,546 pipeline jobs in 2025, 20.6% of the US total, according to the BLS Quarterly Census of Employment and Wages.
Add the other Houston metro counties whose figures BLS discloses and the count climbs to 15,164 jobs, 27.0% of every private pipeline job in the country. Harris County holds 28.7% of US crude oil pipeline jobs and 20.1% of natural gas pipeline jobs. Chambers County, home to the Mont Belvieu storage and fractionation hub, has 1,246 pipeline jobs spread across just 20 establishments. Montgomery County, which takes in The Woodlands, has 1,892 across 12. The Railroad Commission of Texas counts 479,096 miles of pipeline in the state, and the Greater Houston Partnership says Houston companies operate 56% of the country’s natural gas pipelines.
Why does that matter? A control room login in a Houston office can reach a pump station more than 400 miles away. The attack path runs between them over a carrier network or a private circuit, through a firewall someone in Houston manages. The pipe is out west. The credentials live here.

Houston also stacks regulators. A terminal on the Ship Channel can answer to the Coast Guard, a pipeline to TSA, and a cogeneration unit to NERC, sometimes all under one parent company with one shared IT department. Terminal operators on the channel can start with our IT support for Houston maritime and logistics companies, which covers the Coast Guard side. And if you’ve heard that energy is the top ransomware target, we checked that separately in how often ransomware actually hits Houston energy companies. It isn’t. Not by FBI complaint counts.
What Should Your MSP Actually Be Monitoring?
8 things, none of them inside the controllers. Each one is either a way in or a record you’d need after something goes wrong.
- Every remote access session into the control network, vendor tunnels included
- Traffic from the business network into OT, and anything leaving OT for the internet
- Logins, new software, and USB use on HMIs, historians, and engineering workstations
- Firmware and exposure on each cellular gateway and field router
- Accounts, specifically the shared, default, and dormant ones that can reach OT
- Program downloads and mode changes on controllers, as seen by a passive sensor
- New CISA advisories that name equipment you own, checked every week
- Backups of PLC programs, HMI projects, and historian configs, with a restore test on the calendar
Remote Access Into the Control Network
Start here. CISA and 3 partner agencies put secure remote access on their short May 2025 list of primary OT mitigations, and nothing in our own work argues with them. Vendors need access. They get it through a VPN account, a jump host, or a remote desktop tool somebody installed on an HMI during commissioning and never removed. Some still work.
What should page someone? A session outside an approved window. A login from a new country or a residential IP address. TeamViewer, AnyDesk, or ScreenConnect showing up on a control-zone machine for the first time. One vendor account used from 2 places at once. No PLC-aware tool required. That work needs firewall, VPN, and endpoint logs that a person actually reads.
TSA’s pipeline directive is specific here. It requires multifactor authentication or equivalent controls, and an operator that skips MFA on control room workstations regulated under 49 CFR parts 192 or 195 has to spell out its compensating controls in writing.
One Texas law gets cited on this topic more than it should. The Lone Star Infrastructure Protection Act, SB 2116 from 2021, bars agreements that let companies tied to China, Iran, North Korea, or Russia access or control critical infrastructure. But its definition covers communications, cybersecurity systems, the electric grid, hazardous waste treatment, and water treatment. Pipelines aren’t on the list. Vet your vendors anyway.
Traffic Crossing the IT and OT Boundary
Your buffer zone firewall is the best sensor you already own. Use it. Tuning it is ordinary network security work, not an OT specialty. Rules between business and control networks should be short, specific, and boring. Boring is good. It keeps the alerts simple. Any new flow from an office subnet straight into Level 2 or below. Remote desktop or file sharing traffic headed into the control zone. An HMI trying to resolve internet domain names. Historian data moving the wrong way. That last one gets more common as producers feed historian data into AI tools, which our look at managed AI for Houston oil and gas covers.
Volt Typhoon is why this matters beyond ransomware. In advisory AA24-038A, US agencies said with high confidence that the Chinese state-sponsored group was pre-positioning on IT networks to enable lateral movement to OT assets, with Energy among the sectors hit, and that it had tested access to domain-joined OT assets using default vendor credentials. It lived off the land, using ordinary admin tools. Antivirus rarely flags that. A flow that has never happened before stands out.
The Windows Machines in the Control Zone
HMIs, historians, OPC servers, engineering workstations, and jump hosts mostly run Windows. They’re where attackers tend to land first, and they’re where an MSP’s normal tooling fits, with one hard condition. Use only endpoint agents your SCADA vendor has qualified for that software version. An unapproved agent that quarantines a file on a running HMI isn’t a security win. It’s an incident.
Watch for new local admin accounts, interactive logins at 3 a.m., new services or executables, USB storage, and antivirus that suddenly stops reporting. Patch on the vendor’s schedule, not Patch Tuesday. Every time. The WSUS flaw above sat on CISA’s known-exploited list from October 24, 2025, and a control-zone server running that software can’t always take Microsoft’s fix the same week. Monitoring carries the risk until the vendor signs off. That’s the job.

Field Gateways and Internet Exposure
Cellular gateways and field routers are the most exposed devices in a typical oil and gas network, and the least watched. Bad combination. Track each one’s firmware against CISA advisories and the known-exploited list. Alert on configuration changes. Know which public IP address each one answers on, if any. Write it down.
Then look at yourself from outside, the way an attacker would. Check your public address ranges for industrial protocol ports that should never answer from the internet, like Modbus on 502, DNP3 on 20000, EtherNet/IP on 44818, and Siemens S7 on 102. Nothing inside gets touched.
Exposure is how the CyberAv3ngers campaign worked. Starting November 22, 2023, IRGC-affiliated actors logged in to internet-connected Unitronics PLCs on the default TCP port 20256, where the devices had a default password or none, and compromised at least 75 of them, according to CISA advisory AA23-335A. At least 34 of them sat at water and wastewater utilities. The playbook travels. In December 2025, AA25-343A described pro-Russia hacktivists going after HMIs exposed through VNC remote access, at targets ranging from water treatment plants to oil well systems.

Accounts and Credentials
24.2% of the energy advisories we counted involved missing authentication or hard-coded credentials. You can’t fix a password baked into firmware. You can fence it in. Make sure nobody reaches that device without first passing through an account you do control.
So watch the accounts. Shared operator logins that 3 shifts use. Vendor accounts that should have died when the project closed. Business-domain Active Directory accounts that can log in to OT systems at all. And multifactor authentication on every remote path, with no exception for the one integrator who finds it annoying.
Controller Changes, Seen Passively
Passive OT sensors cover this. Products such as Microsoft Defender for IoT, Claroty, Nozomi Networks, Dragos, and Tenable OT sit on a mirrored switch port and listen. They decode Modbus, DNP3, EtherNet/IP, and S7 traffic, then flag program downloads, controller mode changes, firmware updates, and write commands from a device that’s never sent one before in all the months the sensor has been listening.
The MSP’s job is narrow. On purpose. It takes the platform’s alerts into the same SOC queue as everything else, lines them up against remote access and Windows logs, and routes anything touching a controller to the engineer who knows whether the change was planned. It never touches the controller.
Why go to the trouble? Because attackers aim straight at this layer. FrostyGoop, the ninth known ICS-specific malware by Dragos‘s count, talked to controllers directly over Modbus TCP on port 502 to disrupt a district heating company in Lviv, Ukraine, in January 2024. Closer to home, CISA advisory AA26-097A, updated in July 2026, describes Iranian-affiliated actors tampering with PLC project files and manipulating HMI and SCADA displays across US critical infrastructure, Energy included, and in some cases disabling shutdown and alarm logic so systems drifted into unsafe conditions without operators being told. A passive sensor sees those writes. Antivirus doesn’t.
Advisories Matched to Your Asset List
CISA put out roughly 9 ICS advisories a week over the last year. Nobody reads them all, and nobody should have to. Match them against an asset inventory instead. CISA’s August 2025 asset inventory guidance for OT owners and operators even includes a taxonomy written for oil and gas organizations, from wellheads and compressors to RTUs and data historians. The CSAF feed makes the matching a scripting job. Without the inventory it’s guesswork.
Backups You’d Rebuild From
PLC program files, HMI projects, historian configurations, firewall configs, and the directory that controls access to all of it. Keep an offline copy. Restore one on a schedule and write down what happened. Then do it again.
Colonial Pipeline is the case everyone cites, and for good reason. Ransomware encrypted IT systems, and on May 7, 2021, the company proactively shut down its pipeline system to keep the attack from spreading into OT. Restart began the evening of May 12. In between, employees collected key pipeline readings by hand because the OT network wasn’t visible, CEO Joseph Blount told the Senate.
That’s why CISA’s primary mitigations include practicing manual operation. On the Gulf Coast, the same drill doubles as hurricane prep. Same muscle.
What Should Wake Someone Up at 2 a.m.?
Not every alert deserves a phone call. These do.
| Signal | Why it matters | Who acts first |
|---|---|---|
| Remote session into OT outside an approved window | It’s the path federal OT guidance puts near the top of the list | MSP SOC confirms with the site, then disables the account |
| New flow from the office network into Level 2 or below | Segmentation just failed or got bypassed | MSP blocks it at the buffer zone firewall |
| Controller program download or mode change nobody scheduled | Someone may have changed what the process does | Control room first, controls engineer second, MSP supports |
| New remote desktop tool on an HMI | A backdoor, even when a vendor installed it | MSP flags it, operations decides on isolation |
| Gateway configuration change or firmware downgrade | Field devices rarely change on their own | MSP, with the communications contractor |
| Admin login on a historian or engineering workstation at an odd hour | Attackers stage on Level 3 before they touch control | MSP SOC |
Everything else belongs in a weekly change report. New devices, new remote sessions, new flows, controller changes, and which of them were planned. Expect the first month to be noisy while baselines settle, and be suspicious of any provider that promises otherwise. Quiet dashboards on day 1 usually mean nobody tuned anything.
What Should an MSP Never Do on a SCADA Network?
Never run active scans inside it, never patch it on the office schedule, never install agents the SCADA vendor hasn’t approved, and never change anything on a controller, not even a clock setting. Almost everything else is negotiable.
NIST’s OT guide, SP 800-82 Revision 3, tells owners to exercise extreme caution with active scanning on an operational network, because scans can destabilize devices or interfere with the process, and to schedule them during planned outages whenever possible. Its own list of accidental incidents includes a natural gas utility whose IT penetration test locked up the SCADA system. The same CISA primary mitigations fact sheet cited above adds that misconfigurations can come from a system integrator or a managed service provider. That sentence is about firms like ours, and it’s fair.
- Active scans inside the control network. Use passive monitoring, or scan a lab copy.
- Patch Tuesday for HMIs? No. The SCADA vendor qualifies the patch, then operations picks the window.
- Endpoint agents nobody approved, which is why you ask the vendor for its qualified list in writing.
- Anything on a PLC, RTU, or safety system, whether that’s logic, firmware, setpoints, or even a reboot.
- Joining OT servers to the corporate Active Directory domain because it’s convenient.
I’d rather lose a deal than send a technician to run a discovery scan on a live pipeline SCADA network. It’s also the quickest test of whether a provider understands OT at all. Ask how they’d inventory your control network. If the answer starts with a scanner, keep interviewing.
Which Rules Apply to Houston Pipeline and Plant Operators?
It depends on what you operate. Only one rule set in this table spells out continuous monitoring for pipelines in so many words, and it’s TSA’s.
| If you’re | What applies | What it expects from monitoring |
|---|---|---|
| Owner or operator of a pipeline or LNG facility that TSA has notified is critical | Security Directive Pipeline-2021-02G, effective May 3, 2026, through May 2, 2027 | Continuous monitoring and detection, an audit of any OT communication with an external system that strays from your documented baseline, continuous log collection, and a way to isolate control systems during an IT incident |
| Terminal or facility on the Ship Channel regulated under the Maritime Transportation Security Act | The Coast Guard’s 2025 maritime cybersecurity rule, on top of facility security rules that have covered computer systems since 2003 | A cybersecurity officer, a cybersecurity plan, and incident reporting |
| Company with generation or transmission assets registered with NERC, such as a cogeneration unit | NERC CIP, including CIP-003-9 | For low-impact assets, a way to determine, disable, and detect vendor remote access, enforceable since April 1, 2026 |
| Any pipeline operator, designated or not | API Standard 1164, 3rd edition, published August 2021 | The pipeline industry’s own control systems cybersecurity standard, voluntary unless a contract or regulator adopts it |
| Everyone | NIST SP 800-82 and ISA/IEC 62443 | Zones, conduits, and monitoring at the conduits, with NIST’s Revision 4 draft now out for comment |
| Energy or chemical facility in Texas | Texas Cyber Command, created by HB 150 effective September 1, 2025 | No monitoring mandate. It’s a state body in San Antonio built to prevent and respond to incidents affecting critical infrastructure, and the law’s definition includes energy and chemical facilities |
2 lines in 02G matter to anyone hiring an MSP. Section III.E.2.b tells covered operators to prioritize every patch on CISA’s known-exploited list, which is exactly why the IT bugs above belong on an OT team’s radar. Section III.E.3 then admits that some OT systems can’t take a patch without a severe hit to operations, and requires written mitigations and a timeline instead. In most of those write-ups, monitoring is the mitigation. Plan for that.
NIST is moving too. It released the initial public draft of SP 800-82 Revision 4, its guide to OT security, on September 21, 2026, with expanded guidance on asset management and on network monitoring and detection, and comments run through November 30, 2026. Our breakdown of IT compliance for Texas oil and gas operators covers the full rulebook, and the Coast Guard maritime cyber rules and NERC CIP for oil and gas IT teams each get their own guide.
Should an MSP Run Your SCADA Security at All?
Sometimes. It depends on who owns your controllers and how big your OT team is, and for some Houston operators the honest answer is no.
| Your situation | Best fit | Why |
|---|---|---|
| Small E&P operator, a few dozen wellsites on cellular, no OT staff | MSP at the boundary, an integrator on call for controllers | The exposure is remote access and gateways, which is IT work |
| Midstream company with its own control room and a TSA designation | Co-managed, with your OT team owning the sensors | Your people know the process, and the MSP’s SOC covers nights and the IT side |
| Refinery or chemical plant with a dedicated OT security team | Keep OT in-house, use an MSP for corporate IT | A second party in the control zone adds confusion, not coverage |
| Oilfield service company with remote access into customers’ SCADA | MSP secures your laptops, remote tools, and accounts | You’re the vendor on someone else’s risk list |
| Office-only energy company whose only OT is building automation | Standard managed security | There’s no SCADA to watch |
For the second row, our co-managed IT in Houston model is built for exactly that split. Whatever the setup, write down who owns each job before anything goes wrong. Before, not after.
| Job | MSP | Controls engineering or integrator | Operations |
|---|---|---|---|
| Remote access accounts, MFA, and session logs | Runs them | Approves vendor access | Sets the allowed windows |
| Buffer zone firewall rules | Manages and monitors | Approves every OT-side change | Kept informed |
| HMI and engineering workstation patches | Tracks them against CISA’s known-exploited list | Qualifies with the vendor and installs | Picks the outage window |
| PLC and RTU logic, firmware, and setpoints | Never touches | Owns | Approves changes |
| Passive sensor alerts | Triages around the clock | Confirms whether a change was planned | Decides on manual operation |
| Cutting OT off from IT during an incident | Executes it at the firewall | Advises | Makes the call |
| Backups of PLC programs and HMI projects | Stores copies and tests restores | Exports current versions | Kept informed |
Section II.A.3 of TSA’s directive is blunt on one point. If a covered operator hands security work to a managed security service provider, the operator keeps sole responsibility for compliance. Write the split down anyway. Then, whoever you talk to, ask these before you sign anything.
- Which OT platforms has your team actually worked on, by name?
- Will you ever run an active scan inside our control network? The right answer is no.
- Which endpoint agents are qualified for our SCADA and HMI versions, and who confirmed it?
- How do CISA advisories get matched to our equipment, and how fast?
- When your SOC sees a program download at 2 a.m., who do you call?
- What do you refer out, and to whom?
Still comparing providers? Our ranking of the best IT services for oil and gas in Houston is a good place to start the shortlist.
The last question is the telling one. A provider that claims to handle everything in OT is telling you something. Just not what it thinks.
How Does Uprite Handle SCADA-Adjacent Security?
Uprite Services is a managed IT and cybersecurity provider headquartered in Houston, serving Texas businesses, including E&P operators, oilfield service firms, and midstream companies with 20 to 300 users. We secure and monitor the IT layer around control systems, which means the business network, the buffer zone, remote access, control-zone Windows hosts running vendor-approved agents, identity, advisory matching, and backups.
We don’t build ICS environments. We don’t program controllers. When a finding needs protocol-level OT work, we say so and bring in a specialist, and our cybersecurity services in Houston are scoped that way from the very first conversation with a new client. Our average first response is 5.06 minutes. Every engagement carries a 120-day satisfaction guarantee.
Want to see how that plays out? Our oil and gas IT modernization case study follows a Texas operator whose specialized operational platform stayed untouched while the infrastructure around it got stabilized, monitored, and secured over the course of the engagement. For companies that keep their own IT staff, managed security services in Houston starts with the MSSP Security Focus plan on our published pricing at $40 per user per month, which covers firewall management, SIEM, and SOC monitoring. Statewide work sits under our oil and gas IT for Texas operators.
What Houston Operators Ask About SCADA Monitoring
Can an MSP monitor SCADA without touching the control network?
Mostly, yes. A passive sensor on a mirrored switch port listens without sending a single packet, and firewall, VPN, and Windows logs cover the rest. The controllers never notice. The one job that needs hands inside the zone is installing the sensor, and your controls team should pick that window.
Should we put EDR on our HMIs and engineering workstations?
Only agents your SCADA vendor has qualified for that exact software version. Get that list in writing. Where no agent is approved, application allowlisting and log forwarding usually are, and they cover a lot of the same ground.
How often should someone check CISA’s ICS advisories against our equipment?
Weekly. CISA published 486 of them in the 12 months to September 24, 2026, about 9 a week, and 186 named the Energy sector. Once an asset inventory exists, matching them is a scripting job.
Our wellsites run on cellular. Doesn’t that keep our SCADA off the internet?
Not by itself. A cellular gateway with a public IP address is on the internet, and some carrier plans assign one unless you ask for private addressing. Ask your carrier for a private APN, lock down each gateway’s management interface, and check your address ranges from outside.
Does TSA’s pipeline cybersecurity directive apply to us?
It binds owners and operators of hazardous liquid and natural gas pipelines, or LNG facilities, that TSA has notified are critical, and nobody else. Without that notice, Security Directive Pipeline-2021-02G doesn’t apply to you directly. Customers and insurers may still borrow its monitoring and patching expectations, so it’s a sensible benchmark anyway.
What does SCADA monitoring cost for a mid-size operator?
$40 per user per month is where Uprite’s MSSP Security Focus plan starts for the IT side. A passive OT sensor platform is priced separately by its maker, per site or per asset depending on the product, so get that quote before you set a budget for the year. Site count moves that number more than headcount does. Our breakdown of cybersecurity cost in Houston covers the rest of the budget.
Who should we call first if an HMI shows something strange?
Your control room. Safety and the process come first, so operators decide whether to go to manual, and the controls engineer decides whether a change was planned. Your MSP comes third, pulling remote access, firewall, and login records to answer the question everyone asks next, which is how someone got in.
Do we need an OT-specific SOC?
At 20 to 300 users, usually not a separate one. You need one SOC that receives both your IT alerts and your OT sensor alerts, plus a written rule for who touches what. Operators running dozens of control rooms are a different story.
Running pipeline, gathering, or terminal systems anywhere from the Ship Channel to The Woodlands? Get an assessment. We’ll map every path into your control network, check your remote access and field gateways against CISA’s advisories, and tell you plainly which findings belong to us and which belong to an OT specialist.
Get an Assessment








