Solutions · Oil & Gas

Which identities touched SCADA last night?

Your posture stack keeps growing, yet each tool still sees only its own slice. None of them can tell you whether an identity's behavior was normal. That is where real risk lives in a contractor-run operation.

Book a Discovery WorkshopGet the datasheet
AI security means two things

AI for security is what every tool claims.
Security for the AI in your operations is the part most skip.

Your operations now run copilots, service accounts, and autonomous agents that reason and expand scope at runtime. The first question is simple: can you even see them, and what they can reach? CINQUE makes them visible as personas with observed behavior, measured against what is normal for each.

PersonaEntitled, per RBACObserved, per CINQUEVariance
OEM remote engineerVendor jump host onlyControl network reachedBOUNDARY CROSSED
Field telemetry accountWell-pad data, batch windowNew scopes, off-windowSCOPE DRIFT
Turnaround contractorRead unit drawingsRead and bulk exportNEW EXPORT PATH
Reliability AI agentRecommend work ordersRecommend and createFOUR-EYES BREAK
Historian replication feedProcess data, continuousProcess data, continuousRECONCILED
Illustrative. Each variance sits below the triage threshold of the console that owns it. It exists only once all five control points are read together.

Detection tells you what happened. Context tells you whether it was supposed to happen.

Where pipeline operators point it first

Four places pipeline operators point it first.

The IT/OT boundary

Who, or what, is crossing from corporate toward control rooms, compressor stations, and SCADA.

Contractors and vendor remote access

What contracted identities actually touched, from the jump host to the control network and beyond it.

Non-human identities

Service accounts, Shadow AI, and the agents entering operational workflows, each baselined as a persona of its own.

Assessment evidence

Dozens of scattered signals become a short list of correlated, business-contextualized risk stories you can attest to each year.

Mapped to where pipeline security is heading

The TSA directives ask for inventory, segmentation, and proof.
CINQUE produces all three from behavior.

The expectation
Who is asking
What CINQUE gives you
Maintain an inventory of critical cyber systems, refreshed on a set cycle
TSA SD Pipeline-2021-01 / -02
Personas actually active in your environment, human, non-human, and AI, from observed behavior rather than stale directory data.
Segment IT and OT so a compromise on one side cannot reach the other
TSA SD Pipeline-2021-02 ยท API 1164
Activity correlated into one journey per persona, so you can see where control access concentrates.
Account for contractors, vendors, and AI that can reach control systems
TSA SD Pipeline-2021-02
Contractor accounts, vendor remote access, and autonomous agents surface as first-class personas, not blind spots between tools.
Produce assessment evidence you can stand behind each year
Your TSA-approved plan's annual assessment
A short list of correlated, business-contextualized risk stories you can attest to.

Based on TSA Security Directive Pipeline-2021-01 and -02 series requirements for TSA-designated critical pipeline owners and operators, and API Standard 1164, 3rd Edition. Directives are renewed annually and requirements may change, but the direction toward asset inventory, IT/OT segmentation, and continuous verification is clear.

Datasheet

CINQUE for Oil & Gas security leaders

Which identities touched SCADA last night? For contractor-run operations: every persona, human, non-human, and AI, measured against its own normal, mapped to the TSA pipeline directives.

What it covers
  • Inventory of critical cyber systems, discovered from observed behavior
  • IT/OT segmentation evidenced by where control access actually concentrates
  • Contractors, vendor remote access, and autonomous agents as first-class personas
  • Assessment evidence you can stand behind each year (TSA SD Pipeline-2021-01/-02, API 1164)

Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.

The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your correlated risk picture.