Which identities touched SCADA last night?
Your posture stack keeps growing, yet each tool still sees only its own slice. None of them can tell you whether an identity's behavior was normal. That is where real risk lives in a contractor-run operation.
AI for security is what every tool claims.
Security for the AI in your operations is the part most skip.
Your operations now run copilots, service accounts, and autonomous agents that reason and expand scope at runtime. The first question is simple: can you even see them, and what they can reach? CINQUE makes them visible as personas with observed behavior, measured against what is normal for each.
| Persona | Entitled, per RBAC | Observed, per CINQUE | Variance |
|---|---|---|---|
| OEM remote engineer | Vendor jump host only | Control network reached | BOUNDARY CROSSED |
| Field telemetry account | Well-pad data, batch window | New scopes, off-window | SCOPE DRIFT |
| Turnaround contractor | Read unit drawings | Read and bulk export | NEW EXPORT PATH |
| Reliability AI agent | Recommend work orders | Recommend and create | FOUR-EYES BREAK |
| Historian replication feed | Process data, continuous | Process data, continuous | RECONCILED |
Detection tells you what happened. Context tells you whether it was supposed to happen.
Four places pipeline operators point it first.
The IT/OT boundary
Who, or what, is crossing from corporate toward control rooms, compressor stations, and SCADA.
Contractors and vendor remote access
What contracted identities actually touched, from the jump host to the control network and beyond it.
Non-human identities
Service accounts, Shadow AI, and the agents entering operational workflows, each baselined as a persona of its own.
Assessment evidence
Dozens of scattered signals become a short list of correlated, business-contextualized risk stories you can attest to each year.
The TSA directives ask for inventory, segmentation, and proof.
CINQUE produces all three from behavior.
Based on TSA Security Directive Pipeline-2021-01 and -02 series requirements for TSA-designated critical pipeline owners and operators, and API Standard 1164, 3rd Edition. Directives are renewed annually and requirements may change, but the direction toward asset inventory, IT/OT segmentation, and continuous verification is clear.
CINQUE for Oil & Gas security leaders
Which identities touched SCADA last night? For contractor-run operations: every persona, human, non-human, and AI, measured against its own normal, mapped to the TSA pipeline directives.
- Inventory of critical cyber systems, discovered from observed behavior
- IT/OT segmentation evidenced by where control access actually concentrates
- Contractors, vendor remote access, and autonomous agents as first-class personas
- Assessment evidence you can stand behind each year (TSA SD Pipeline-2021-01/-02, API 1164)
Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.