Cybersecurity for energy and natural resources

In mining, oil and gas, and power generation, computers control physical equipment. When those systems are attacked, production stops, and in the worst case people get hurt. The key question for leadership is simple: can an attack on the office network reach the systems that run the site?

What an incident costs

You already know what an hour of lost production costs. A cyber incident adds investigation, recovery and often a safety review before operations restart. Energy and mineral resources is one of the sectors Indonesia designates as vital information infrastructure. Serious incidents therefore draw attention from the National Cyber and Crypto Agency (BSSN) and the Ministry of Energy and Mineral Resources. Joint-venture partners, lenders and insurers will also want to know what happened and what has changed.

The weak points we look at

Operational technology (OT) is the hardware and software that monitors and controls physical processes, such as SCADA systems and industrial controllers. At most sites it was once isolated. Today it is connected to office IT for reporting, remote support and cloud analytics. That connection is where we focus.

First, we check whether an attacker who breaks into office IT can move into the control network. We then test the VPNs and remote access tools used by vendors and remote operations centers, which are a common way in. We also look at the web portals, mobile apps and APIs used for fleet and logistics, where a simple flaw can expose operational data. Finally, we check whether your backups and recovery plan would get production running again after a ransomware attack (malicious software that locks systems until a ransom is paid).

How we keep testing safe

Rules of engagement are agreed with operations before any work begins. Control systems are assessed with passive, non-intrusive methods, or in a staging environment that mirrors production. Scope is set per site and per OT zone, and no outage is planned.

What you get

You receive a risk-rated report within 10 days of testing. It explains the production and safety impact of each finding in plain language, for the board and for the regulator. Once fixes are in place, we retest. We also help your monitoring team build detection for OT alerts, which IT-focused monitoring often misses.

Standards we work to

Snipeyes is CREST-accredited and ISO/IEC 27001:2022 certified. OT work follows IEC 62443 (the international standard for industrial control system security), NIST SP 800-82 and MITRE ATT&CK for ICS. We work with mining companies, oil and gas operators, power producers and diversified natural resources groups.