Oil and Gas
March 15, 2024
22 minutes read
Oil and gas innovation rarely fails because the technology does not work. It fails because the site was not ready for it.
Every digital oilfield deployment needs five things present before the technology delivers anything: power at the location, connectivity, data infrastructure, operational technology security, and people who can run it. Most programmes are approved on the strength of the technology and stall on one of the five.
The fifth failure mode is the one nobody writes about. Connecting production equipment to a network creates an attack surface on systems whose failure mode is physical rather than financial, and there is an international standard that governs exactly that.
This guide covers what each major technology actually requires, what ISA/IEC 62443 demands once you connect anything, and how to test a vendor claim before you fund it.
The technologies described in oil and gas innovation content are real and they work. The gap is between a vendor demonstration and a producing site.
A wellpad that has no electrical service cannot host a sensor network. A remote location with intermittent satellite connectivity cannot support real-time analytics. A facility with no data historian has nothing to train a model on. A control system with no network segmentation cannot safely accept a new connected device. And a site with no one trained to interpret the output will not act on it.
Each of those is an infrastructure problem, not a technology problem, and each has a longer lead time than the software.
For a broader survey of the technologies themselves, see our rundown of the top technological advancements in the oil and gas industry. This guide addresses what it takes to deploy them.
Assess these five before funding any digital or automation programme, because each has a lead time longer than the technology it supports.
A conventional wellpad needs no electrical supply beyond small solar panels for telemetry. Adding a sensor network, edge computing or actuation creates a continuous load at a site with no service. Multiplied across a pad count, a digital programme becomes a power infrastructure programme.
For the site power decision including grid, self-generation and hybrid options, see our guide to oil and gas in the age of renewable energy.
Assess site readiness first, then close the infrastructure gaps, then deploy. A programme sequenced the other way stalls after the software contract is signed and the invoices have started.
A connected asset needs someone who can interpret what it reports and authority to act. That is a role, not a dashboard licence, and in remote operations it frequently means a rotation rather than a hire.
The digital oilfield is an integrated system combining instrumentation, connectivity, data infrastructure and analytics to monitor and optimise production, and the analytics layer is the last part to install rather than the first.
Industrial Internet of Things, or IIoT, describes networked sensors and devices embedded in industrial equipment that report condition and process data continuously.
A data historian is the time-series database that records process and equipment data with timestamps, and it is the foundation everything else sits on. Without consistent tag naming and sufficient history, analytics has nothing to learn from.
Edge computing processes data at or near the source rather than sending everything to a central system, which matters where bandwidth is limited or latency requirements are tight.
A digital twin is a continuously updated virtual model of a physical asset, fed by live data, used to predict behaviour or test changes before making them. It requires a validated engineering model plus a reliable data feed, and it is the most prerequisite-heavy technology in the category.
A consistent tag naming convention across sites. Sufficient historical data to establish a baseline, which for most applications means one to two years rather than weeks. Documented instrument calibration. And a defined data quality standard, because a model trained on drifting instrumentation produces confident wrong answers.
Establish in the contract that the operator owns all process, equipment and condition data in an exportable format, with no restriction on using it with a different vendor later. A platform provider holding your operating history controls your position at renewal.
For the maintenance strategy that connected condition data should feed, see our comparison of predictive versus preventive maintenance and our rotating equipment field guide.
Connecting industrial equipment to a network is a security decision before it is a technology decision, and ISA/IEC 62443 is the international standard that governs it.
Operational technology, or OT, is the hardware and software that monitors and controls physical processes: distributed control systems, programmable logic controllers, SCADA and safety instrumented systems. It differs from IT in what it prioritises. IT security prioritises data confidentiality. OT security prioritises the safe and continuous operation of a physical process.
That difference has a hard consequence. In OT, control actions must occur within a defined timing window or the physical process fails. If a logging function causes a safety controller to pause even momentarily, the result can be a physical incident rather than a data loss.
You cannot transplant IT security practice into OT. That is the single most common and most dangerous assumption in a digital oilfield programme.
ISA/IEC 62443 is the series of standards for Industrial Automation and Control Systems security, developed jointly by the International Society of Automation and the International Electrotechnical Commission.
Its core architectural concepts are zones and conduits. Zones group assets with similar security requirements. Conduits are the controlled communication pathways between zones. Traffic between zones is regulated rather than open, which is what stops a compromise in one area reaching another.
As Dragos explains, ISA/IEC 62443 uses the Purdue Reference Model, derived from the Purdue Enterprise Reference Architecture, to describe how data flows through industrial networks, breaking systems into hierarchical levels based on response time and function. Many organisations mirror the Purdue levels in their network architecture, and Dragos notes specifically that care is needed when considering wireless, cloud, remote access and Industrial Internet of Things solutions, because each of those crosses levels the model was designed to separate.
That caution is the point. Every technology in an innovation programme is one of the four things the model warns about.
Security levels, SL1 through SL4, define the required protection strength. A security level is a measure of confidence that a system, zone or conduit is free from vulnerabilities and functions as intended. SL4 addresses high-resource and nation-state attacks against critical infrastructure.
IEC 62443 addresses the security of industrial automation and control systems including the legacy equipment common in the sector. Older controllers frequently cannot be patched or authenticated, which is precisely why the standard's answer is architectural segmentation rather than device hardening alone.
An architecture diagram showing which zone the new device sits in and which conduit carries its traffic. The security level the solution is designed to. Evidence of segmentation between the new system and any safety function. A patching and vulnerability management commitment. And whether remote access is required, by whom, and through what control.
In 2017, malware known as TRITON, also called TRISIS or HatMan, targeted the safety instrumented system of a petrochemical plant. It was the first known malware built specifically to defeat a safety system.
A safety instrumented system is the independent protective layer designed to bring a process to a safe state and prevent explosions and toxic releases. It exists precisely so that a control system failure does not become a physical catastrophe. Its functional safety requirements are governed by IEC 61511 for the process industries.
The attackers reached the safety controller through the plant network. The incident triggered a process shutdown and was jointly analysed by CISA, the FBI, the NSA and the US Department of Energy.
The incident changed how the industry understands OT risk. The objective was not to halt production or steal data. It was to disable the systems designed to protect human life.
Every connected device added to a facility is a potential path toward the safety layer, and OT compromise frequently begins in less-guarded systems rather than at the target. The Colonial Pipeline incident followed the same pattern, with lateral movement from corporate IT networks through inadequate DMZ controls into OT segments.
Ask of any innovation proposal: can this device, or anything that can reach it, reach a safety instrumented system? If the answer is not a documented no, the proposal is incomplete.
Yes. Where a safety instrumented function is credited in a hazard analysis, a cyber path to that function undermines the credit. Treat the connection as a change requiring management of change review and a revised hazard assessment, not as an IT project.
Operators depend on drilling contractors, equipment vendors, software providers and logistics partners, so a compromise at any of them can reach the operator without a direct breach. Vendor security posture is part of the operator's exposure, which is why it belongs in prequalification rather than in a separate security review.
High-resolution 3D seismic imaging combined with machine learning improves subsurface interpretation, and its commercial value is in reducing exploration risk rather than in eliminating it.
3D seismic imaging uses reflected acoustic energy recorded across a grid to construct a three-dimensional model of subsurface structure. Machine learning applied to that data accelerates interpretation, identifies features that manual review may miss, and improves consistency across interpreters.
What it does not do is remove geological uncertainty. Interpretation quality improves; the subsurface does not become deterministic.
Seismic acquisition, processing and interpretation is oilfield services and specialist geoscience scope, delivered by companies such as SLB and dedicated seismic contractors. It is not surface engineering or power infrastructure work.
For which provider category handles which kind of work, see our guide to E&P and oilfield services.
Whether the model was trained on data from an analogous basin. What the demonstrated improvement in interpretation accuracy is, measured against what baseline. And whether the vendor will accept a validation exercise against wells you already have results for, which is the only genuine test.
Enhanced oil recovery covers techniques that mobilise hydrocarbons remaining after primary and secondary production, and it is reservoir engineering rather than surface technology.
Primary recovery uses natural reservoir pressure. Secondary recovery typically injects water or gas to maintain pressure. EOR, sometimes called tertiary recovery, changes the physical or chemical properties of the oil or the reservoir to mobilise what the first two stages left behind.
EOR is capital-intensive and its uplift is reservoir-specific. Steam injection in particular consumes large quantities of energy to generate steam, which creates a substantial power and fuel demand, and that demand is a surface infrastructure question.
The commercial test is cost per incremental barrel against the oil price you can rely on, not against the price today. Projects sanctioned at a high price and operated through a low one are how EOR programmes become stranded.
Require a pilot with defined success criteria and a decision gate before field-wide deployment. Reservoir response is the variable no vendor controls, and a pilot that does not meet its criteria is information rather than failure.
EOR is delivered by oilfield services and specialist reservoir engineering firms. Where Prismecs contributes is the surface side: the power, steam generation infrastructure, controls and maintenance that an EOR programme depends on.
Robotic and autonomous inspection reduces exposure of people to hazardous environments, and its business case is usually safety and access rather than cost.
Unmanned aerial systems inspect flare stacks, tanks, offshore structures and elevated equipment without scaffolding or rope access. Crawler and magnetic-wheeled robots inspect vessel and tank internals. In-line inspection tools, commonly called smart pigs, survey pipeline integrity from inside.
Autonomous drilling systems adjust drilling parameters in real time to optimise rate of penetration and reduce downhole risk. That is drilling contractor and oilfield services scope.
Robotic inspection rarely beats manned inspection on unit cost. It wins on three other grounds: removing people from confined spaces, working at height and over water; accessing locations that would otherwise require a shutdown; and producing a repeatable digital record that supports trending across inspections.
Where an inspection would otherwise require scaffolding, a shutdown or confined space entry, the comparison changes decisively.
Regulatory approval for the airspace or environment. Certification of any equipment entering a classified hazardous area. Data format and ownership. And an inspection standard the output will be assessed against, because an image is not an inspection unless someone qualified interprets it to a defined criterion.
Assess technology maturity explicitly, because the distance between a working demonstration and a deployable system is where most innovation budgets are lost.
Technology readiness level, or TRL, is a scale describing maturity from basic principles observed through to a system proven in an operational environment. API and DNV both publish recommended practice for technology qualification in the oil and gas sector, providing a structured method for assessing whether a novel technology is ready for a given application.
Require the TRL, and require the environment in which it was demonstrated. A technology proven in a laboratory and a technology proven on a producing asset in your environment are different propositions carrying different risk.
Where has this been deployed, on a producing asset, and can I speak to that operator? Reference customers who will take a call are the strongest evidence available.
What were the prerequisites at that site, and how do they compare to mine? A deployment that worked on a facility with fibre connectivity and a mature historian proves little about a remote pad.
What is the measured result against what baseline? An improvement claim without a stated baseline and measurement method is unverifiable.
What does the solution require from my control system, and which zone does it sit in? This is the IEC 62443 question, and a vendor who cannot answer it has not designed for an industrial environment.
Who owns the data, in what format, and what happens at contract end?
What does year three cost? Licence, support, connectivity, replacement sensors and the people to run it. First-year pricing is rarely the operating cost.
Define success criteria, the measurement method and the decision gate before the pilot starts. A pilot without defined criteria always produces a positive-sounding result and never produces a decision.
For procuring the equipment inside these programmes and the sector compliance attached to it, see our guides to the industrial procurement process and oil and gas procurement.
Connecting industrial systems brings reporting and compliance obligations that did not exist when the systems were isolated.
The 72-hour and 24-hour reporting windows are worth putting in front of whoever would have to meet them. A reporting obligation that fast requires a detection and escalation capability already in place.
Cyber and property insurers increasingly assess OT security posture, network segmentation and incident response capability when pricing industrial risk. A connected asset with no segmentation is a different underwriting proposition from an isolated one, and the change should be disclosed rather than discovered.
Establish notification obligations, evidence preservation requirements and liability allocation in the contract. Supply chain compromise reaches the operator without a direct breach, and a contract silent on vendor incidents leaves the operator with no entitlement to know.
The prerequisites are constant. Which one binds changes with the asset.
Power and connectivity bind first, because pads are numerous, remote and individually small. Solutions must scale across hundreds of locations or they are pilots forever.
TSA Security Directives apply directly to pipeline owner-operators, and SCADA exposure across a distributed asset is the dominant risk. Remote terminal units at unattended sites are a documented attack surface.
Connectivity is expensive and constrained, which favours edge processing. Every device must be certified for the hazardous area classification, and the cost of getting anything wrong is far higher.
The most mature OT environments, the most extensive safety instrumented systems, and the sector where TRITON occurred. Segmentation and safety system protection outrank every other consideration.
The prerequisite gap is widest and the value of remote monitoring is highest, which makes these sites both the best case and the hardest to deliver. Power and connectivity are the whole project.
Full digital programmes are uneconomic below a certain asset base. Apply the prerequisites selectively and deploy on the highest-consequence assets only, rather than attempting a field-wide rollout.
The standards are international and unchanged: ISA/IEC 62443, IEC 61511 and ISO/IEC 27001 apply everywhere. The reporting obligations differ. In the EU, the NIS2 Directive imposes its own incident reporting and security requirements on essential and important entities. Confirm the national regime before designing the incident response process.
Prismecs is an engineering and power services company. It works on the surface infrastructure that innovation programmes depend on, and it does not perform wellbore or reservoir operations.
Prismecs does not perform seismic acquisition or interpretation, drill wells, design or execute enhanced oil recovery programmes, or provide drilling automation. Those are oilfield services and specialist geoscience scope.
Prismecs does deliver the instrumentation, controls and power infrastructure that connected operations require: I&C services covering control systems, SCADA and DCS support; EPCM services for project delivery; O&M services for operating the resulting assets; distributed energy solutions for site power; and technology and consulting for assessment.
Stating the boundary matters here specifically, because innovation content routinely implies capability across the whole value chain. A provider who tells you what they do not do has given you a reason to believe what they say they do.
Apply this article's questions to any vendor, including us. Ask where it has been deployed on a producing asset. Ask which IEC 62443 zone the solution sits in. Ask what the prerequisites were at the reference site. Ask what year three costs.
To request a site readiness and deployment assessment, send your site location and power position, current control system and connectivity, existing historian and data history, and the application you are considering to sales@prismecs.com or call +1 (888) 774-7632. We return a prerequisite gap list, a sequencing recommendation and the questions to put to your shortlisted vendors.
It is an integrated system combining instrumentation, connectivity, data infrastructure and analytics to monitor and optimise production. The analytics layer is the last part to install, not the first. It requires site power, adequate connectivity, a data historian with consistent tag naming and sufficient history, network segmentation appropriate to the risk, and people who can interpret and act on the output. Most programmes fail on one of those five.
Usually on prerequisites rather than technology. A wellpad with no electrical service cannot host a sensor network. A remote site with intermittent connectivity cannot support real-time analytics. A facility with no historian has nothing to train a model on. A flat control network cannot safely accept new connected devices. Each is an infrastructure problem with a longer lead time than the software it supports.
It is the series of standards for Industrial Automation and Control Systems security, developed jointly by the International Society of Automation and the International Electrotechnical Commission. Its core architectural concepts are zones, which group assets with similar security requirements, and conduits, which are the controlled communication pathways between them. Security levels SL1 through SL4 define required protection strength, with SL4 addressing nation-state-capable attacks.
IT security prioritises data confidentiality. OT security prioritises safe and continuous operation of a physical process. The consequence is timing: in OT, control actions must occur within a defined window or the physical process fails, so a logging function that pauses a safety controller can cause a physical incident rather than a data loss. IT security practice cannot be transplanted into OT without redesign.
The Purdue Reference Model, derived from the Purdue Enterprise Reference Architecture, describes how data flows through industrial networks by breaking systems into hierarchical levels based on response time and function. ISA/IEC 62443 uses it as its architectural reference. Care is required with wireless, cloud, remote access and Industrial Internet of Things solutions, because each crosses levels the model was designed to separate.
TRITON, also called TRISIS or HatMan, was 2017 malware that targeted the safety instrumented system of a petrochemical plant, the protective layer designed to prevent explosions and toxic releases. It was the first known malware built specifically to defeat a safety system. The attackers reached the safety controller through the plant network, and the incident was jointly analysed by CISA, the FBI, the NSA and the US Department of Energy.
It is the independent protective layer that brings a process to a safe state when defined conditions occur, existing so that a control system failure does not become a physical catastrophe. Its functional safety requirements are governed by IEC 61511 for the process industries. Where a safety instrumented function is credited in a hazard analysis, a cyber path to that function undermines the credit and requires reassessment.
EOR, sometimes called tertiary recovery, covers techniques that mobilise hydrocarbons remaining after primary and secondary production by changing the physical or chemical properties of the oil or reservoir. Methods include polymer flooding to improve sweep efficiency, steam injection to reduce viscosity in heavy oil, CO2 injection, and microbial techniques. It is reservoir engineering delivered by oilfield services and specialist firms.
It depends entirely on the reservoir and on the oil price you can rely on rather than today's price. EOR is capital-intensive, and steam injection in particular consumes large quantities of energy to generate steam, which creates a substantial surface power and fuel demand. The commercial test is cost per incremental barrel across the price range you expect, and a pilot with defined success criteria should precede field-wide deployment.
Usually not on unit cost. The case rests on three other grounds: removing people from confined spaces, work at height and work over water; accessing locations that would otherwise require a shutdown; and producing a repeatable digital record supporting trending across inspections. Where inspection would otherwise need scaffolding, a shutdown or confined space entry, the comparison changes decisively.
Require the technology readiness level and the environment it was demonstrated in. API and DNV both publish recommended practice for technology qualification in the sector. Then ask six questions: where it has been deployed on a producing asset, what the prerequisites were at that site, what the measured result was against what baseline, which IEC 62443 zone it occupies, who owns the data, and what year three costs.
In the United States, the Cyber Incident Reporting for Critical Infrastructure Act requires covered operators to report significant incidents to CISA within 72 hours and ransom payments within 24 hours. TSA Security Directives impose network segmentation, access controls, continuous OT monitoring and vulnerability management on pipeline owner-operators. Those windows require detection and escalation capability already in place before an incident occurs.
Increasingly yes. Cyber and property insurers assess OT security posture, network segmentation and incident response capability when pricing industrial risk. A connected asset on a flat network is a materially different underwriting proposition from an isolated one. Disclose the change at renewal rather than allowing it to be discovered during a claim investigation.
Oilfield services companies and specialist geoscience firms. Seismic acquisition, processing and interpretation, drilling, well completion and enhanced oil recovery programme design all sit in that category. Engineering and power services companies work on surface infrastructure: power, electrical systems, instrumentation, controls and maintenance. Sending an enquiry to the wrong category costs time on a schedule-driven project.
Tags: Digital Oilfield IEC 62443 OT Security Technology Readiness Enhanced Oil Recovery Industrial Control Systems
Power Utilities
20 minutes read
Fast-Track Power Plants Deployment: How to Reach Speed to Power in Under 12 Months
Fast-track power plant deployment can hit first power in weeks. See real TM2500 timelines from permitting to COD, proven in Oman and Taiwan. Plan your...
O&M Services
11 minutes read
Gas Turbine Outage Planning: Schedule, Scope Rules, and Checklist
Gas turbine outage planning starts 18 months out. Get the T-minus schedule, scope freeze rules, parts readiness gates and checklist. Talk to a Prismec...
O&M Services
15 minutes read
Predictive vs Preventive Maintenance: How to Choose Per Asset
Most plants apply predictive vs preventive maintenance facility wide and overspend. Match each asset by failure mode, criticality and P-F interval. Ta...
Data Centers
59 minutes read
Data Center Power Redundancy: N, N+1, 2N and 2N+1- What Each Level Takes to Build and Prove
Most data center power redundancy claims fail under test. See what N+1, 2N and 2N+1 truly require, how Level 5 testing proves them, and what to demand...