oil cybersecurity – Waterfall Security Solutions https://waterfall-security.com Unbreachable OT security, unlimited OT connectivity Thu, 03 Apr 2025 14:02:28 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://waterfall-security.com/wp-content/uploads/2023/09/cropped-favicon2-2-32x32.png oil cybersecurity – Waterfall Security Solutions https://waterfall-security.com 32 32 Enabling The Digital Refinery https://waterfall-security.com/ot-insights-center/oil-gas/enabling-the-digital-refinery/ Thu, 08 Sep 2022 10:59:00 +0000 https://waterfall-security.com/?p=10502 Protecting critical equipment of a highly sensitive petrochemicals processing plant, while improving production performance with real-time, actionable, and predictive analytics.

The post Enabling The Digital Refinery appeared first on Waterfall Security Solutions.

]]>

Enabling The Digital Refinery

Protecting The Refining & Petrochemical Industry From Evolving Cyber Threats
Enabling The Digital Refinery
Customer/ Partner:

North American Petrochemical Refinery.

Customer Requirement:

To protect critical equipment and on-going productivity of a highly sensitive production environment involving the processing of petrochemicals, while at the same time improve the performance of plant production with real-time, actionable and predictive analytics.

Waterfall’s Unidirectional Solution:

Secure the production environment perimeter from external threats and provide real-time enterprise visibility – Unidirectional Security Gateways protect all industrial control systems (DCS, individual controllers and logic controllers) with an impassable physical barrier to external network threats, while enabling enterprise access to real-time production data.

Refining & Petrochemicals Processing Modernization And Containing Remote Cyber Threats

The energy industry has become the second most prone to cyber attacks with nearly three-quarters of U.S. oil & gas companies experiencing at least one cyber incident. Remote cyber attacks on oil and gas refining & production can result in severe consequences to human and environmental safety in the form of ruptures, explosions, fires, releases, and spills. In addition, disruption of service and deliverability can be devastating for key infrastructure end users such as power plants, airports or national defense.

The Challenge icon
The challenge

To secure the safe, reliable and continuous operation of oil & gas processing control and safety networks from threats emanating from less trusted external networks. At the same time provide real-time access to operations data to the enterprise users and applications, as well as provide periodic and on-demand inbound access for anti-virus and other updates to turbine vendors and other third parties.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed between the process control network (PCN) and the enterprise network. Unidirectional Gateway software connectors replicate OSISoft PI, GE OSM and ICCP servers from the PCN to the enterprise network where enterprise clients can interact normally and bi-directionally with the replicas. A file server replication connector was also deployed, to eliminate the routine use of USB drives and other removable media. A Waterfall FLIP, a hardware-enforced Unidirectional Security Gateway whose orientation is reversible, was also installed between the PCN and IT networks. By schedule, or by exception, an independent control mechanism inside the protected OT network triggers the FLIP hardware to change orientation, allowing information to flow back into the protected OT network as needed.

Results and benefits - icon
Results & benefits
  • 100% Security: With the gateways, the PCN is now physically protected from threats emanating from external, less-trusted networks. The FLIP permits disciplined, on-demand and scheduled updates of plant systems, without introducing firewall vulnerabilities.
  • 100% Visibility: The enterprise network continues to operate as if nothing has changed. Instead of accessing servers on the critical operational network, users on the external network now access real-time data from replicated servers for all informational and analytical requirements.
  • 100% Compliance: Unidirectional Gateways are recognized manufacturing cyber security standards as well as by global industrial control system cyber security standards and regulations.
vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks originating on external networks. The Gateways enable vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. As a result, Unidirectional Gateway technology represents a plug-andplay replacement for firewalls, without the vulnerabilities and maintenance issues that always accompany firewall deployments. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected network.

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightSafe, continuous monitoring of critical systems

arrow red rightProtects product quality, safety of personnel, property and the environment

arrow red rightProtects safety and preventative maintenance systems of physical assets from remote Internet-based threats

arrow red rightSimplifies audits, change reviews, and security system documentation

arrow red right
Disciplined, on-demand and scheduled updates of plant systems, without introducing firewall vulnerabilities

arrow red rightReplaces at least one layer of firewalls in a defense-in-depth architecture thereby breaking the chain of infection and pivoting attacks

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader in Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by many leading industry standards bodies such as NIST, ANSSI, NERC, the IEC, the US DHS, ENISA and may more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Enabling The Digital Refinery appeared first on Waterfall Security Solutions.

]]>
Protecting the GIPL pipeline https://waterfall-security.com/ot-insights-center/oil-gas/protecting-the-gipl-pipeline/ Thu, 08 Sep 2022 08:36:00 +0000 https://waterfall-security.com/?p=4860 Protecting operational data within the gas transmission SCADA system, while enabling safe visibility and exchange of operational data for both pipeline partners.

The post Protecting the GIPL pipeline appeared first on Waterfall Security Solutions.

]]>

Protecting the GIPL pipeline

Waterfall teams with ELSIS TS to reinforce cybersecurity at gas interconnection Poland and Lithuania facilities
Customer/ Partner:

Lithuanian-based ICT and OT company ELSIS TS at GIPL sites

Customer Requirement:

Protecting operational data exchange within the gas transmission SCADA system, while enabling safe visibility and exchange of operational data for both pipeline partners.

Waterfall’s Unidirectional Solution:

Secures control system network perimeters from external threats with Unidirectional Security Gateways, enabling enterprise-wide visibility for operations status and key performance indicators as well as safe ICS network monitoring from a central enterprise SIEM.

Cross border pipeline infrastructure is facing real cyber threats

The Colonial Pipeline incident, Russian actions in the Ukraine, targeted ransomware actors and other threats have raised serious concerns about the cybersecurity of critical national infrastructures. This deployment of Unidirectional Gateways provides the world’s strongest protection from online attacks to this important natural gas interconnection.

The Challenge icon
The challenge

Secure the automation processes of the GIPL pipeline for the safe exchange of operational data between the gas transmission systems of the two countries, without posing risk to reliable, uninterrupted and efficient operation of the complex, transnational pipeline infrastructure. In addition, enable a central dispatch centre to remotely monitor and control process operations.

Waterfall solution - icon
Waterfall solution

Waterfall integrated Unidirectional Security Gateways to unidirectionally replicate gas metering and pressure reduction data between Polish and Lithuanian sites, without posing risk to process control networks. Unidirectional Gateways replicate industrial data to a central dispatch center to enable the safe exchange of data between geographically dispersed sites.

Results and benefits - icon
Results & benefits

Security: Unidirectional Gateways enabled the secure exchange of multisite operational data between countries. OT data replication provides strong assurance that no attack from the IT network can enter the operational network.

Simplicity: Unidirectional server replication makes the gateways easy to use. The unidirectional replicas are realtime participants in both source and destination networks.

Performance: Safe industrial data exchange for international pipeline infrastructure, not only optimizes business efficiencies, but ensures the security of critical resources.

vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and industrial control networks from attacks originating from external less-trusted networks. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected industrial network.

This deployment used two Unidirectional Security Gateways to enable safe control-system data exchange, external monitoring, and visibility into operations for the GIPL sites. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments.

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightSafe operational data exchange between geographically disparate facilities

arrow red rightSecure monitoring of operational data from less-secure, Internet-based networks

arrow red rightStrongest industrial security for automation processes and systems

arrow red rightSafe replication of critical data to enhance operational efficiencies

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, the ISA, the US DHS, ENISA and many more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Protecting the GIPL pipeline appeared first on Waterfall Security Solutions.

]]>
Waterfall And W-Industries Secure Offshore Platforms https://waterfall-security.com/ot-insights-center/oil-gas/waterfall-and-w-industries-secure-offshore-platforms/ Tue, 23 May 2017 08:29:00 +0000 https://waterfall-security.com/?p=10249 Secure, safe, and continuous operation of offshore platforms, protected against remote cyber attacks, while enabling reliable real-time monitoring and reporting of production data and the statuses of essential platform systems.

The post Waterfall And W-Industries Secure Offshore Platforms appeared first on Waterfall Security Solutions.

]]>

Waterfall And W-Industries Secure Offshore Platforms

Partnering With Global Systems Integrator To Secure Critical Production Processes
Customer/ Partner:

Offshore Oil & Gas Producer.

Customer Requirement:

Secure safe and continuous operation of offshore platforms from remote cyber attacks, while enabling reliable real-time monitoring and reporting of production data and the status of essential platform systems.

Waterfall’s Unidirectional Solution:

Secures the platform control system network perimeter from external threats with Unidirectional Security Gateways, enabling real-time enterprise monitoring and third-party monitoring and diagnostics, while creating fully operational Wonderware PCS, OPCDA, power turbine monitoring and file server replicas.

Offshore Production Modernisation And Containing Remote Cyber Threats

The energy industry is the second most prone critical infrastructure to cyber attacks with nearly threequarters of U.S. oil & gas companies experiencing at least one industrial cyber incident annually. Remote cyber attacks targeting offshore oil platforms can result in severe consequences to human and environmental safety. Waterfall partnered with W-Industries, a leading global systems integrator for the offshore industry, to secure a fleet of offshore platforms and operational processes from cyber attacks.

The Challenge icon
The challenge

Waterfall Unidirectional Gateways were deployed, both on the platform and in onshore facilities. Each gateway is the only point of connection between IT and OT networks, replicating information from control networks to the enterprise network. A central OSIsoft PI enterprise server served as a repository for analyzing operations data, company-wide. An OPC-DA server in each control network pulls realtime data from industrial servers. The Waterfall Gateway replicates OPC-DA servers to platform and onshore IT networks. The enterprise PI server pulls data from the Waterfall OPC-DA replicas and makes it available enterprise-wide for reporting, analysis and optimization planning.

Waterfall solution - icon
Waterfall solution

W-Industries replaced the IT/OT firewall with a Unidirectional Security Gateway. The gateways replicate an OSIsoft PI historian from the OT network to the IT network. The IT PI replica provides enterprise users and applications with real-time access to all operations data authorized to be shared with the enterprise. The enterprise hydraulic analysis application draws real-time reservoir levels, pressures and pump indications from the replica historian. A secure web portal accesses equipment status information, billing information and other readings from the replica as well. This data IS available to utility management, end users and field personnel.

Results and benefits - icon
Results & benefits

Security: Absolute protection from online attacks originating on the IT network, and from Internet-based attacks which might breech the enterprise network.

Visibility: Online access to real-time operations data, with no change in end-user or business application integration procedures.

Cost: Reduced training, admin, audit, testing, and monitoring costs when compared to a conventional firewall-based solution.

vertical red line
Theory of Operation
Click to enlarge

“Using the Waterfall Gateways gave our customer the assurance of true unidirectional server replication from the control network to the business network.”

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and industrial control networks from attacks emanating from external less-trusted networks. Waterfall Gateways contain both hardware and software components. The hardware is physically able to send information in only one direction. The software replicates servers and emulates devices. The gateway software produces an accurate, timely replica of a production OPC server. Enterprise applications and users interact normally with the replica server.

Unidirectional Gateways enable control system intrusion detection, vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. The gateways replicates servers, emulate industrial devices, and translate industrial data to cloud formats. Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments. Replacing at least one layer of firewalls in a defense-in-depth architecture breaks the attack path from the Internet to critical systems

vertical red line
Unidirectional Security Gateways Benefits:

arrow red rightSafe, continuous monitoring of critical systems

arrow red rightProtects product quality and the safety of personnel, equipment and the environment

arrow red rightSimplifies audits, change reviews, and system documentation

arrow red rightDisciplined, on-demand and scheduled updates of plant systems, without introducing firewall vulnerabilities

arrow red rightReplaces at least one layer of firewalls in a defense-in-depth architecture, breaking the chain of infection and preventing pivoting attacks

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Waterfall And W-Industries Secure Offshore Platforms appeared first on Waterfall Security Solutions.

]]>
Enabling the Digital Oil Field (Offshore) https://waterfall-security.com/ot-insights-center/oil-gas/enabling-the-digital-oil-field-global-offshore-oil-and-gas-company/ Sat, 08 Apr 2017 09:24:00 +0000 https://waterfall-security.com/?p=10465 Securing safe and continuous operation of offshore platforms from remote cyber attacks, while enabling reliable real-time monitoring of essential platform systems.

The post Enabling the Digital Oil Field (Offshore) appeared first on Waterfall Security Solutions.

]]>

Enabling the Digital Oil Field (Offshore)

Protecting Offshore Exploration And Production From Evolving Cyber Threats
Enabling The Digital Oil Field (Offshore)
Customer/ Partner:

Global Offshore Oil and Gas Company.

Customer Requirement:

To secure the safe and continuous operation of offshore platforms from remote cyber attacks, while enabling reliable real-time monitoring of costs, production and the status of essential platform systems.

Waterfall’s Unidirectional Solution:

Secures the platform control system network perimeter from external threats with Unidirectional Security Gateways, enabling Real-Time Enterprise Connectivity and Third Party Monitoring and creating fully operational Wonderware PCS, OPC-DA, power turbine monitoring and file server replicas.

Offshore Production Modernization And Containing Modern Cyber Threats

The energy industry has become the second most prone to cyber attacks with nearly three-quarters of U.S. oil & gas companies experiencing at least one cyber incident annually. Remote cyber attacks on offshore oil and gas platforms can result in severe consequences to human and environmental safety in the form of ruptures, explosions, fires, releases, and spills.

The Challenge icon
The challenge

To secure the safe, reliable and continuous operation of platform control and safety networks from threats emanating from less trusted external networks. In parallel, provide safe, real-time reporting of operations data to business, vendor, regulatory and cloud systems: including predictive maintenance applications, scheduling optimizers, and outsourced network and security monitoring.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed connecting platform control system networks to the on-platform extension of the enterprise IT network. Unidirectional Gateway software connectors replicate OPCDA servers from the control network to the enterprise network where OSIsoft PI servers query and otherwise interact normally and bi-directionally with the OPC replicas.

In addition, Waterfall’s Unidirectional CloudConnect provided visibility into natural gas turbine operating parameters for cloud-based turbine monitoring and predictive maintenance applications. A file server replication connector was also deployed, to eliminate the routine use of USB drives and other removable media.

Waterfall’s Unidirectional Gateway and CloudConnect hardware physically prevent cyber threats from reaching sensitive industrial control networks by transmitting data in only one direction to external networks.

Results and benefits - icon
Results & benefits

100% Security: The offshore network is now physically protected from threats emanating from external, less-trusted, Internet-exposed and cloud-based networks.

100% Visibility: The enterprise network continues to operate as if nothing has changed. Instead of accessing servers on the critical operational network, users and applications on external networks access real-time data from real-time replica servers for all informational and analytical requirements.

100% Compliance: Unidirectional Gateways simplify compliance with global industrial-control-system cybersecurity standards and regulations.

vertical red line
Theory of Operation
Click to enlrage

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks originating on external networks. The Gateways enable vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. As a result, Unidirectional Gateway technology represents a plug-andplay replacement for firewalls, without the vulnerabilities and maintenance issues that always accompany firewall deployments. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected network.

vertical red line
Unidirectional Security Gateways Benefits:

arrow red rightSafe, continuous monitoring of critical systems

arrow red rightSafe cloud vendor/services supply chain integration

arrow red rightProtect product quality and the safety of personnel, property and the environment from remote internet-based attacks

arrow red rightSimplify audits, change reviews, and security system documentation

arrow red rightReplace at least one layer of firewalls in a defense-in-depth architecture, breaking the attack path from the internet to important control systems

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, the ISA, the US DHS, and ENISA. Waterfall’s solution also facilitates safe real-time data monitoring for compliance with the requirements of the US Department of the Interior’s BSEE Well Control Rule.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Enabling the Digital Oil Field (Offshore) appeared first on Waterfall Security Solutions.

]]>
Enabling The Digital Oil Field https://waterfall-security.com/ot-insights-center/oil-gas/enabling-the-digital-oil-field/ Sat, 08 Apr 2017 09:10:00 +0000 https://waterfall-security.com/?p=10437 Securing safe and continuous operation of diesel engines, compressors, and pumps as well as enabling reliable real-time monitoring of the natural gas and oil pipeline network.

The post Enabling The Digital Oil Field appeared first on Waterfall Security Solutions.

]]>

Enabling The Digital Oil Field

Protecting Pipeline Networks From Evolving Cyber Threats
Picture of Waterfall team

Waterfall team

Enabling The Digital Oil Field
Customer/ Partner:

North American petrochemicals pipeline company.

Customer Requirement:

To secure the safe and continuous operation of diesel engines, compressors and pumps as well as enable reliable real-time monitoring of the natural gas and oil pipeline network.

Waterfall’s Unidirectional Solution:

Protects the critical physical assets and pipelines from remote cyber attacks while ensuring safe IT/OT integration that allows real-time, continuous, and actionable network monitoring.

Oil & Gas Pipeline Industry Modernization And Containing Modern Cyber Threats

The energy industry has become the second most prone to cyber attacks with nearly three-quarters of U.S. oil & gas companies experiencing at least one cyber incident. A remote cyber attack on oil and gas pipelines can result in severe consequences to human and environmental safety in the form of ruptures, explosions, fires, releases, and spills. In addition, disruption of service and deliverability can be devastating for key infrastructure end users such as power plants, airports or national defense.

The Challenge icon
The challenge

To secure the safe, reliable and continuous operation of pipeline control and safety networks from threats emanating from less trusted external networks, yet still provide safe, real-time reporting of operations data to vendor and cloud systems, including predictive maintenance applications, scheduling optimizers, and outsourced network and security monitoring. However efficient, all of these modern applications introduce unacceptable vulnerabilities to critical systems.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed between the pipeline control system network and the enterprise network. Unidirectional Gateway software connectors replicate OSISoft PI, servers from the control network to the enterprise network where enterprise clients can interact normally and bidirectionally with the replicas. A file server replication connector was also deployed, to eliminate the routine use of USB drives and other removable media. Waterfall’s Unidirectional CloudConnect enabled diesel engine oil monitoring and predictive maintenance cloud based applications to provide visibility into pipeline ICS networks. The CloudConnect hardware physically prevents cyber threats from reaching sensitive industrial control networks and transmits data in only one direction to cloud monitoring networks.

Results and benefits - icon
Results & benefits

100% Security: The pipeline network is now physically protected from threats emanating from external, less-trusted Internet and cloud-based networks.

100% Visibility: The enterprise network continues to operate as if nothing has changed. Instead of accessing servers on the critical operational network, users on the external network now access real-time data from replicated servers for all informational and analytical requirements.

100% Compliance: Unidirectional Gateways simplify compliance with US TSA Pipeline Security Guidelines and are recommended by IEC 62443 as well as other North American and global industrial cyber security standards and regulations.

vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks originating on external networks. The Gateways enable vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. Unidirectional Gateways replicate servers, emulate industrial devices, and translate industrial data to cloud formats. As a result, Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that always accompany firewall deployments.

Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected network.

vertical red line
Unidirectional Security Gateways Benefits:

arrow red rightSafe integration of pipeline safety, control, storage, transportation and delivery systems with external networks

arrow red rightSafe, continuous monitoring of critical systems • Safe cloud vendor/services supply chain integration

arrow red rightProtects product quality, the safety of personnel, property, and the environment 

arrow red rightReplace at least one layer of firewalls in a defense-in-depth architecture, breaking the attack path from the Internet to important control systems

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader in Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by many leading industry standards bodies such as NIST, ANSSI, the IEC, the US DHS/TSA, ENISA and many more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Enabling The Digital Oil Field appeared first on Waterfall Security Solutions.

]]>