APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

DarkMatter LLC

Eric Eifert, SVP

Cyber Threats in Energy Companies

Eric Eifert

Eric Eifert

Cyber security for energy companies within the Middle East is extremely important. For example, the security breach incident at Aramco and RasGas highlighted the fact that oil and gas companies are a target of cyber attacks, which if successful can have a significant negative impact on organisations. The energy sector has the added challenge of needing to provide cyber security across a more diversified environment, which includes industrial control systems, communications systems with remote facilities, sub-contractors/suppliers and its own corporate network.

Previously, the biggest threat energy companies used to face was the loss of sensitive and proprietary information to competitors. This information could be as simple as a list of customers, to more complex data such as the chemical formula for a gasoline additive or the organisation’s mineral exploration investment strategy. While different areas are of interest to different types of threat actors they generally share a single characteristic; the information is held on corporate servers in headquarters and regional offices. Information loss could be significant, having far-reaching implications for the profitability and reputation of the firms attacked.

However, such attacks rarely affected the day-to-day operations of the targeted firms; commercial damage is real, but it would unfold over months and years as executives realised their rivals had stolen a competitive advantage on them. It rarely caused processes to be shut down and certainly didn’t involve disruption to supply and production. Threats were best countered by robust information protection measures including encryption of data in transit and at rest, and access controls to ensure that information was only disseminated to those who genuinely needed it.

While traditional threat actors; rivals, criminals and environmental activists persist, today we’re seeing a dangerous trend of energy companies being targeted by state actors with far more ambitious and dangerous intentions. As more systems go online and become interconnected, they can be targeted by a hostile state looking to attack the underpinning infrastructure of the nations in which they operate.

The malware programme nicknamed Stuxnet (discovered in 2010), for example, targeted computers that controlled centrifuges in a nuclear enrichment programme in country in the Middle East, altering their rotation speeds, causing the centrifuges to tear themselves apart and producing a cascade of second order effects. More recently, Ukraine suffered a multi-tiered attack on its energy facilities. The Ukrainian computer emergency response team (CERT) reported that in total eight facilities were attacked, ultimately leading to a loss of power for hundreds of thousands of people in the middle of winter. Although most recovered their power within three hours, after-shocks continued for days with Power Company employees having to travel along ice-covered roads to remote sub-stations to manually close breakers the hackers had opened remotely. Most sinisterly, the attack was multi-pronged; opening of breakers was accompanied by spoofing of monitoring systems, a distributed telephonic denial of service attack on help lines, and destructive attacks against corporate systems, all designed to systematically prevent the Ukrainian authorities from resuming control.

The Middle East is rapidly increasing its cyber security capabilities; however, it takes time to build mature processes and procedures, upgrade technology, collaborate on threat intelligence, and develop a workforce that can tackle the current and future cyber threats. We are starting to see cyber security policy, information sharing laws, education programmes, and cyber security technology companies focus on the region. There is an increased understanding of the cyber risks that face the region and investments to mitigate those risks.

We believe that energy companies and governments need to adopt an outlook on cyber security in which they assume breach, and establish the necessary protocols and defences to such.

We also believe that underpinning this outlook should be a commitment to a cyber security life-cycle, which is a four-stage approach encompassing planning, detection, protection, and recovery. 

Energy companies need to focus on:

How and why cyber security is at the forefront of national security
Why having additional connectivity / IoT / smart cities exposes additional threat vectors
How the current geo-political turmoil is intertwined with cyber

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    ISS Facility Services Australia & New Zealand

    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO

  • Willis Towers Watson

    BPAY Group

    Building BPAY Group's New Digital Foundation

    Angela Donohoe, Chief Information Officer

  • Willis Towers Watson

    Bvn Architecture

    How Have Recent Advancements in Big Data Been Impacting Businesses?

    Marc Solomon, CIO

  • Willis Towers Watson

    Tassal Operations

    BI & Analytics in Aquaculture

    Matthew Leary, CIO

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.apacciooutlook.com/leadership-perspective/cyber-threats-in-energy-companies-nwid-2870.html