Unmonitored Access Paths Put Pipeline Integrity at Risk
A Singapore-based oil and gas pipeline maintenance firm faced a critical cybersecurity exposure when routine monitoring revealed unauthorised access attempts originating from within its corporate network and targeting operational technology (OT) systems. These systems, responsible for monitoring pressure thresholds, valve positions, and leak detection across active pipeline segments, were found to be directly accessible from office workstations. With regulatory oversight from the Energy Market Authority (EMA) and strict PDPC compliance requirements for data handling, the firm was operating under urgent pressure. A single breach or malfunction triggered by network-based interference could lead to environmental incidents, regulatory penalties, or operational shutdowns. The company had no immediate visibility into lateral movement between departments, and third-party contractors routinely connected to internal systems without enforced access controls. The risk was not hypothetical — anomalous traffic patterns indicated prior probing of control interfaces, and the window for corrective action was narrowing.
Flat network architecture left OT systems exposed to corporate-side threats
When our team conducted an initial network topology assessment, we discovered that the client’s IT and OT environments shared the same Layer 3 switching infrastructure, with no firewall enforcement or VLAN segregation between corporate workstations and SCADA-connected devices. Traffic from the finance department’s workstations could reach Modbus TCP ports on programmable logic controllers (PLCs) managing pipeline flow control. The root cause was a legacy network design predicated on convenience rather than security — remote maintenance access was enabled through unauthenticated VPN tunnels, and Active Directory policies applied uniformly across both domains. Worse, the client had no asset inventory of OT devices, meaning they could not track what was connected, let alone secure it. This lack of network segmentation meant a phishing incident in the corporate email system could potentially cascade into unauthorised manipulation of pressure sensors or valve actuators. The firm was unaware of the extent of exposure because monitoring tools were limited to IT endpoints, and OT systems were excluded from SIEM coverage.
Deployed Palo Alto firewalls with zone-based policies and established micro-segmentation for OT devices
We implemented a zero-trust segmentation strategy by inserting Palo Alto Networks next-generation firewalls at key network boundaries — specifically between the corporate LAN and the OT control network. These firewalls were configured with strict zone-based policies, allowing only necessary protocols such as OPC UA and SNMP on predefined ports, with deep packet inspection enabled to detect protocol anomalies. We isolated the OT subnet into dedicated VLANs and applied role-based access control using TACACS+ integration for engineers, ensuring that only authenticated personnel could initiate supervisory commands. A centralized logging pipeline was established using the client’s existing Splunk deployment, now extended to ingest firewall, switch, and PLC event logs. We deployed Veeam-based backup for configuration snapshots of all network and control devices, ensuring rapid recovery in case of tampering. All third-party remote access was routed through a jump server with multi-factor authentication and time-limited sessions, replacing the previous open SSH tunnels. The entire re-architecture was completed in phases over six weeks without interrupting scheduled pipeline inspections or maintenance cycles.
Zero unauthorised access incidents since segmentation, with full audit readiness
Post-implementation, the client achieved complete visibility into north-south and east-west traffic flows. The number of blocked unauthorised connection attempts — primarily from legacy applications attempting to scan OT subnets — averaged 18 per day initially, tapering off as misconfigured systems were corrected. There have been zero confirmed incidents of unauthorised access to control systems in the 14 months since deployment. The firm passed its most recent EMA audit with no non-conformance findings related to network security, a marked improvement from the prior year’s report, which cited inadequate segregation as a high-risk item. Engineers now operate within defined privilege tiers, and all access to PLCs is logged and correlated in Splunk for real-time alerting. The client has since adopted this architecture as the standard for all regional maintenance hubs, with replication underway across three additional sites.
Assume breach pathways exist wherever operational and corporate networks intersect
For Singapore-based industrial firms, especially those managing critical infrastructure, the assumption that IT and OT can coexist on shared infrastructure without consequence is a dangerous oversight. The convergence of digital operations increases efficiency but multiplies risk when segmentation is neglected. Proactive network zoning, continuous monitoring, and strict access controls are not optional enhancements — they are operational necessities, particularly when regulatory scrutiny and public safety are at stake.
When pressure sensors and email servers share the same network, a single misconfigured device can compromise far more than data — it can endanger physical systems. Learn how to separate your control environments with purpose-built segmentation at TYPENT’s industrial cybersecurity framework.