
OT Security Automation and the Fading Air-Gap
In a recent interview with industry media, Mary Rose Martinez, CISO at Marathon Petroleum, offered an in-depth look at how operational technology (OT) security is transforming as automation spreads deeper into refineries, pipelines, and terminals. Marathon Petroleum operates one of the largest refining and midstream footprints in the United States, with a network that includes multiple refineries, thousands of miles of pipelines, and hundreds of terminals. This sprawling infrastructure relies heavily on industrial control systems (ICS) such as programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems.
Martinez emphasized that the traditional concept of air-gapping OT environments is rapidly becoming obsolete. As digital transformation accelerates across energy, manufacturing, and transportation sectors, the boundaries that once isolated industrial control networks from enterprise IT and external connectivity are dissolving. This shift introduces significant exposure for critical control systems that were never designed to be connected to broader networks. “We have had to make the mindset shift that the traditional concept of air-gapping operational technology environments is effectively dissipating,” Martinez explained. The digitization of OT creates new attack surfaces that security teams must continuously reassess.
Historically, air-gapping relied on physical separation to protect ICS from remote threats. However, the drive for operational efficiency, real-time monitoring, and predictive maintenance has pushed organizations to connect OT systems to IT networks and even cloud platforms. This convergence, while beneficial for operations, introduces risks that must be managed with layered defenses. Martinez noted that the energy industry is not unique in facing this transition; manufacturing, transportation, and other critical infrastructure sectors are undergoing similar changes. The key challenge is to apply commensurate protective controls without disrupting production.
Architecting Defenses Around Autonomous Systems
One of the most fundamental differences between IT and OT environments is the inability to simply patch and reboot systems on demand. In a refinery, a catalytic cracker or distillation column cannot be taken offline during a typical Patch Tuesday cycle. Downtime for such equipment can result in millions of dollars in lost production and potentially create safety hazards. Martinez addressed this operational reality by highlighting how Marathon leverages the widely accepted Purdue Enterprise Reference Architecture (PERA) model. The Purdue model divides ICS networks into hierarchical levels, from Level 0 (physical processes) to Level 4 (enterprise IT), with clear security zones and conduits between them.
“When appropriate security controls are implemented at and between the information and operational technology layers of the model, space is created to synchronize security actions with regular operational cadences while mitigating risk,” Martinez said. For example, security patches and updates can be tested in a simulated environment and then deployed during planned maintenance windows that coincide with turnaround schedules. Network segmentation, access controls, and monitoring at each level help contain any potential compromise without requiring an emergency shutdown. The goal is to achieve a balance where security enhances reliability rather than hinders it.
Martinez also highlighted the importance of understanding the specific operational tolerances of each asset. Some systems have real-time constraints that cannot tolerate latency introduced by security scans or agent-based monitoring. Therefore, passive monitoring techniques, such as network traffic analysis using anomaly detection, are often preferred over active scanning. The security architecture must be designed to be transparent to the control systems while still providing visibility into anomalous behavior.
Supply Chain Risk and Vendor Dependencies
As autonomy expands, it is increasingly bundled with vendor platforms, third-party models, and remote support tunnels. These dependencies create a complex supply chain that extends far beyond the immediate vendor. Martinez identified the greatest risks as lying where companies have the least visibility and control. “We have greater control over how our environment is accessed and least control over our vendors’ products or security practices,” she stated. These risks extend to nth-party vendors—companies that supply components or services to the primary vendor.
To mitigate these risks, Marathon employs a rigorous due diligence process that includes contractual language, security assessments, and ongoing monitoring. When evaluating a new product or service, the security team reviews the vendor’s security posture, incident response capabilities, and history of vulnerabilities. Material changes to existing products also trigger reassessments. Martinez emphasized the value of forming strategic partnerships with key vendors. Such partnerships can enable joint incident response, product improvement feedback, and even influence over the vendor’s security roadmap. “Whether it results in the ability to provide input on products and services or jointly responding to an event and restoring operations as quickly as possible, these partnerships are valuable,” she added.
The supply chain challenge is particularly acute for OT because many legacy devices have fixed software and hardware that cannot be easily updated. Vendors may discontinue support or go out of business, leaving operators with unsupported components. Martinez recommended that organizations maintain an inventory of all OT assets, monitor for vendor security advisories, and develop contingency plans for end-of-life devices. In some cases, network segmentation can isolate high-risk devices from the rest of the network until they can be replaced.
Cross-Skilling the Workforce for Digital Fluency
As processes become more automated, the workforce around them changes. Operators who traditionally understood the chemistry and physics of refining may now need to interact with complex software systems. Conversely, cybersecurity professionals must understand the operational context of the systems they protect. Martinez described the concept of “Calm Technology” as a guiding principle, where systems remain as invisible as possible while supporting human tasks. Achieving this requires a two-way exchange of knowledge.
“It is incumbent upon the people developing, securing, and providing digital systems to understand business processes and operations to achieve this,” Martinez said. At the same time, some democratization of digital know-how must occur. Artificial intelligence and low-code platforms are helping to lower the barrier to codification, allowing non-programmers to create scripts and automations. However, this does not eliminate the need for cross-skilling; it changes the type of skilling required. Marathon has developed various learning pathways to increase digital fluency across the company, tailor-made for different roles and interests.
For control engineers, these pathways might include cybersecurity fundamentals and threat awareness. For IT security professionals, they might include hands-on training with PLCs and SCADA simulators. The goal is to build a workforce that can serve as a human backstop, capable of recognizing anomalies and taking appropriate action even when automation fails or is compromised. Martinez also stressed the importance of continuous education as technology evolves, with regular drills and tabletop exercises that simulate real-world OT incidents.
Navigating Regulatory Pressures and State-Aligned Threats
Critical infrastructure operators like Marathon face growing pressure from regulatory bodies such as the Cybersecurity and Infrastructure Security Agency (CISA) and the Transportation Security Administration (TSA), which has issued directives specifically for pipeline security. Meanwhile, the threat environment now includes state-aligned actors actively probing energy systems. Martinez acknowledged the reality of these threats and described how the move toward autonomy changes what her team reports, defends, and assumes adversaries already know.
“We understand our role and place in the nation’s critical infrastructure, and continually adjust our strategies and controls based on the threat landscape,” she said. The company re-evaluates the efficacy of its protective and defensive controls in proportion with technology advancements. Partnerships with government agencies are crucial for both defense and regulatory compliance. Martinez highlighted that intelligence sharing from CISA and other agencies helps Marathon allocate resources most efficiently, focusing on the most relevant threats.
Furthermore, Marathon actively provides input into the development of security regulations to ensure they are operative and effective for the industry. This two-way collaboration helps create standards that protect critical infrastructure without imposing impractical operational burdens. Martinez noted that the assumption must be that adversaries are persistent and well-informed. Therefore, rather than relying on secrecy, security should be built on strong fundamentals: segmentation, monitoring, access controls, and incident response readiness. The move toward autonomy actually amplifies the need for these fundamentals, as automated systems can be exploited faster than manual ones.
Background and Additional Context
The conversation with Martinez comes at a time when the energy sector is experiencing a wave of digital transformation. The adoption of Industrial Internet of Things (IIoT) sensors, cloud-based analytics, and artificial intelligence is enabling predictive maintenance and optimization of refinery operations. However, these same technologies introduce new vectors for cyber attacks. The 2021 Colonial Pipeline ransomware attack demonstrated how a single compromised IT system could halt fuel delivery across the Eastern United States. That incident prompted a series of TSA directives requiring pipeline operators to implement specific cybersecurity measures, including network segmentation, multifactor authentication, and incident response plans.
Marathon Petroleum has been proactive in this environment. Under Martinez's leadership, the company has invested in building a dedicated OT security team that works closely with refinery operations and engineering groups. The team employs a risk-based approach, prioritizing assets that have the greatest potential impact on safety, environment, and production. Regular threat hunting and red-teaming exercises help validate defenses and identify gaps before adversaries can exploit them.
Another area of focus is the integration of threat intelligence into operational workflows. By automating the correlation of indicators of compromise (IOCs) with OT network data, the team can quickly detect and respond to suspicious activity. Machine learning models are being trained on normal process behavior to identify deviations that may indicate a cyber incident, such as an unauthorized change to a PLC logic or an unusual command sent to an actuator.
Martinez also addressed the challenge of retaining skilled cybersecurity professionals in a competitive market. The company offers cross-training opportunities, certifications, and career paths that allow technical staff to move between IT and OT roles. This approach not only builds depth but also fosters a culture of shared responsibility for security across the organization.
In conclusion, the interview with Mary Rose Martinez provides valuable insights into the practical realities of securing a large-scale OT environment. The key takeaways are the need to abandon outdated assumptions about air-gapping, adopt architectural models like Purdue that allow for both security and operational continuity, manage supply chain risk through diligence and partnerships, invest in workforce cross-skilling, and maintain close collaboration with government agencies to stay ahead of evolving threats. As automation continues to advance, these principles will only become more critical for protecting the nation’s energy infrastructure.
Source:Help Net Security News
