Refinery, pipeline,city gate. One record.

Oil and gas is where the consequence of a control failure is measured in fire. The refinery's distributed control and safety systems, the pipeline's RTUs strung across hundreds of kilometres, the pressure regulation in a city gas network — each has its own vendors, its own protocols and its own control room. ASTRICS gives them one operational understanding, ranked by what an operator would lose.

India's refining capacity is about 257 million tonnes a year with a stated path to 310 by 2030, and 307 geographical areas have been authorised for city gas distribution. Pipelines and refineries can be notified as protected systems under the IT Act.

Sources: Invest India; Ministry of Petroleum and Natural Gas CGD network page; NCIIPC sector list

The oil and gas estate,as ASTRICS reads it.

Refinery, terminal, pipeline and distribution assets land in one register, each with its process, its owner and its consequence attached — so the safety system and the tank gauge are ranked by what they protect, not by their vendor.

DCS and safety instrumented systems

Process control and the independent layer that stops it safely. Their separation is a control, and ASTRICS tests it against observed traffic.

Tank farm and terminal automation

Tank gauging, loading racks, custody transfer metering. Where product becomes money, and where a wrong reading becomes a spill.

Pipeline SCADA and RTUs

Remote terminal units at valve stations and pump stations, reached over cellular, satellite or fibre. Long, thin and mostly unattended.

City gas distribution

Pressure regulation, odorisation and district metering across a geographical area. Consumer-facing OT with a public-safety consequence.

Utilities and power

Captive power, steam and cooling. A captive plant at 50 MW or more is in scope of the CEA regulation in its own right.

Contractor and OEM access

Licensor engineers, control-system OEMs, instrument contractors. Every session observed, attributed and checked against its window.

Why the consequenceis the point.

In this sector the adversary does not need to reach the process to stop it. The IT incident that halts billing halts the pipeline; the safety system is a target precisely because it is the last line.

Safety is the target

TRITON was written to disable a safety instrumented system so that a process upset could do physical damage. The boundary between control and safety has to be proven, continuously.

Long, thin and remote

A pipeline is a chain of RTUs in fenced compounds with a cellular modem each. Firmware ages, credentials persist, and nobody visits until something breaks.

The IT side stops the plant

Colonial Pipeline shut its operations to protect OT from an IT ransomware event. Oil India's 2022 incident hit the headquarters network. The operational decision is made under uncertainty — unless the record already shows what is connected to what.

On the record

  • 2022

    Oil India Limited reported a ransomware attack on its systems at Duliajan, Assam, with a reported demand of US$7.5 million. The company said drilling and production were unaffected.

    Oil India Limited statement, April 2022 — as reported

  • 2021

    Colonial Pipeline halted the largest fuel pipeline in the United States for six days after ransomware hit its IT systems, to keep the incident away from operations.

    Colonial Pipeline; US Senate testimony, June 2021

  • 2017

    TRITON reprogrammed Triconex safety controllers at a petrochemical facility. The plant tripped safely only because the attackers made a mistake.

    FireEye Mandiant; Idaho National Laboratory CyOTE case study

What the rules askof an oil and gas operator.

Summaries of the notified text as we read it in September 2026. Orientation, not legal advice — check the Gazette before you rely on a clause.

CERT-In, six hours

IT Act s.70B(6) Directions

The CERT-In Directions of 28 April 2022 bind every body corporate: covered incidents reported within six hours of noticing, 180 days of ICT logs kept in India, clocks synchronised to NIC or NPL time.

Protected systems

IT Act ss.70, 70A

Refineries and pipelines fall within the power and energy sector NCIIPC covers. Where an asset is identified as critical information infrastructure, it can be notified as a protected system under section 70 of the IT Act, with access restricted and penalties raised.

The regulator's baseline is coming

PNGRB Action Plan 2026–27

The Petroleum and Natural Gas Regulatory Board's action plan for 2026–27 commits to a baseline cyber security framework for the entities it regulates.

Captive power in scope

CEA Regulations 2026, Reg 2(1)

A captive generating plant at 50 MW or more comes under the CEA (Cyber Security in Power Sector) Regulations, 2026 from 1 April 2027, whatever the parent business.

IEC 62443 as the Indian standard

BIS / IEC 62443

The Bureau of Indian Standards has adopted the IEC 62443 series as Indian Standards. Zones, conduits and security levels are the vocabulary a refinery's audit will use.

to report a covered cyber incident to CERT-In after noticing it — for every body corporate, whatever the sector.

of ICT system logs to be kept, inside India, and produced to CERT-In on request.

How ASTRICS mapsto oil and gas.

One platform, one language, one source of truth. Understand, Govern, Protect, Orchestrate and Assure travel together, so every capability below reads the same record.

Control and safety, kept apart

Zones & Conduits declares the boundary between the DCS and the safety instrumented system and tests it continuously. A flow across it is a dated finding with the evidence attached.

Risk ranked by what burns

The Risk Queue orders vulnerability data by what failure would cost this operator: the RTU at a mainline valve station outranks the highest CVSS score in the office.

Every RTU, every modem, every session

Asset Inventory holds each remote unit with its firmware, its communications path and its vendor access. Remote sessions are attributed and checked against the window they were approved for.

Events that already know the asset

Native syslog and event analytics correlate on the asset model, not on hostnames matching across log sources — so six events at a pump station become one incident with a consequence attached.

Understand & Assure

Zones & Conduits

Chapter IV asks an operator to prove trust-level segmentation, not describe it. Declared zones and permitted conduits are continuously tested against observed traffic, and every mismatch becomes a dated finding.

Zones & Conduits — concept view
Concept product view — not a production screenshot
Protect & Orchestrate

Risk Queue

The same vulnerability data everyone has, ordered by what it would cost this operator. The two highest CVSS scores in the estate rank 18th and 27th here — because consequence, not severity, decides the work.

Risk Queue — concept view
Concept product view — not a production screenshot
Protect & Orchestrate

Events & Syslog

Native collection, retention and correlation — no second logging product, and no dependency on another vendor's asset data being right first. Correlation runs on the asset model, not on hostnames matching across log sources.

Events & Syslog — concept view
Concept product view — not a production screenshot
Questions

What operators askbefore they buy.

Straight answers, in the terms the regulation and the plant already use. Bring the rest to a walkthrough.

Is there an oil and gas equivalent of the CEA cyber security regulation?

Not yet in force as of September 2026. PNGRB's action plan for 2026–27 commits to a baseline cyber security framework for regulated entities. Today the binding instruments are the CERT-In Directions of 2022, the protected-system provisions of the IT Act where NCIIPC has identified an asset, and the CEA regulation for any captive power at 50 MW or more.

Our safety system is air-gapped. Why model it?

Because the claim has to be evidenced. ASTRICS declares the control-to-safety boundary as a conduit rule and tests it against observed traffic. If the gap holds, the verdict says so with the evidence attached; if a flow appears, it becomes a finding the same day.

Can ASTRICS reach RTUs on cellular links?

ASTRICS builds the record from the traffic and sources the operator already has — SCADA front ends, historians, syslog and passive observation at the control centre and the sites where it is deployed. Deployment models, including distributed multi-site and air-gapped options, are on the deployment page.

Which standard should a refinery audit against?

IEC 62443 is the series BIS has adopted as Indian Standards for industrial automation and control system security, and its zones, conduits and security levels are the vocabulary ASTRICS uses in Zones & Conduits. ISO/IEC 27001 covers the management system around it.

See ASTRICS against your own environment.

Book a walkthrough with the ASTRICS team and bring one site's worth of questions.