Skip to main content

Third Party Risk Management

Every industrial control system running in a refinery, compressor station or offshore platform today was, in almost every case, never designed to be connected to the internet. SCADA and distributed control systems built in the 1990s and 2000s were engineered around an assumption of physical and network isolation - a closed environment, monitored locally, with no meaningful external attack surface to defend. That assumption no longer holds anywhere in the sector.

The convergence of Operational Technology (OT) and Information Technology (IT) - driven by remote monitoring, predictive maintenance platforms, cloud-connected SCADA dashboards and vendor-managed remote access - has quietly rebuilt the risk profile of the entire industry.

The consequence is a form of third-party risk that has no real precedent in other critical sectors: a compromise that begins in a vendor's IT environment can now propagate directly into a live industrial control system, with consequences that are physical and operational rather than purely informational.

This is not a hypothetical concern. NCSC's Cyber Assessment Framework version 4.0, published as the current authoritative UK standard for essential function operators, explicitly requires organisations to understand the extent of their supply chain that supports network and information systems underpinning essential functions - including subcontractors - and to ensure contracts include appropriate security obligations across that chain. Ofgem's Adapted CAF Profile goes further, requiring granular mapping of supplier access and privileges across both OT and IT environments specifically, and mandating zero-trust architectures and identity-based authentication for all third-party access into these systems.

The structural reason this matters so acutely in oil and gas is straightforward: the vendors with legitimate, contracted access to OT environments are numerous, specialised and often small. Field device manufacturers, SCADA software providers, remote diagnostics contractors, firmware update services and instrumentation calibration specialists all require some form of connectivity into control environments to do their job.

Each one represents a discrete point of third-party access into infrastructure where an intrusion is not measured only in data loss, but potentially in process safety, environmental release or physical damage. The industry does have a maturing standard to assess against. ISA/IEC 62443 remains the only globally recognised, consensus-based cybersecurity standard purpose-built for industrial automation and control systems, offering three tiers of independently verifiable certification: Component Security Assurance for individual OT devices, System Security Assurance for integrated control architectures, and Security Development Lifecycle Assurance for the vendor's own software development process.

In practice, however, the overwhelming majority of vendors operating in oil and gas supply chains today have not pursued formal IEC 62443 certification, which means most third-party risk programmes are still assessing OT-adjacent vendors using generic IT security questionnaires never designed for the environment they are actually meant to protect.

That gap - between the assurance framework the sector has and the assurance framework most supply chains actually apply - is likely to close over the next several years, not because vendors will suddenly seek certification voluntarily, but because procurement requirements are starting to demand it. The direction is already visible in Ofgem's own guidance, which treats supply chain cyber requirements as non-negotiable criteria to be embedded into procurement and onboarding from the outset, not bolted on after contract award. Organisations that begin building OT-specific vendor assessment capability now - distinct from, and more technically rigorous than, standard IT vendor due diligence - will be the ones equipped to meet that requirement as it becomes formalised across the sector.