Topic
Cyber Security
Protection of digital or operational technology from malicious access and interference.
Documents
- 202221 Mar
Check your Cybersecurity Readiness
BSEE urges Outer Continental Shelf operators and contractors to strengthen cyber defences amid potential increased infrastructure threats associated with Ukraine. Recommendations include monitoring CISA guidance, addressing known vulnerabilities, preparing staff to detect network abnormalities, testing manual backup controls and reporting suspicious activity or compromised safety and environmental systems.
- 20212 Dec
Cyber-security – malicious spoofing and phishing
This safety flash discusses malicious email spoofing and a member report of messages impersonating senior management. It explains phishing through email, telephone and messaging services, and suggests checking unexpected communications, resisting pressure to act, and reporting suspicious messages to company IT departments while blocking the number.
- 202119 Mar
Cyber Security for Industrial Automation and Control Systems (IACS)
Inspection guidance sets out three categories for assessing industrial automation and control system cyber security under NIS and non-NIS arrangements. It combines self-assessment, validation and improvement planning with installation-level assurance. An accompanying assessment pack examines governance, access restrictions, network protection, recovery, staff competence and incident response against OG86.
- 202025 Sep
Recently Discovered Cybersecurity Vulnerabilities May Impact Energy Company Industrial Control Systems
BSEE warns that Treck TCP/IP vulnerabilities could enable a highly skilled remote attacker to control energy-sector industrial systems. It recommends monitoring CISA advisories, assessing exposure, updating software, restricting network access and using secure remote connections. Operators and contractors are also advised to assess defensive measures before deployment.
- 201624 Feb
False or scam emails – warning
This safety flash describes two email fraud attempts in 2015: unsuccessful impersonation of a chief executive seeking confidential information, and a successful payment diversion using subtly altered email addresses. It recommends vigilance over message wording, personal addresses, domains and changed banking details, alongside liaison with IT departments.
- Undated
Cyber Security for Industrial Automation and Control Systems (IACS) Operational Guidance
Operational guidance helps inspectors assess cyber security for industrial automation and control systems affecting major accidents or essential services. It covers management systems, asset identification, zones and conduits, threat-based assessment and defence in depth. Technical measures address access, segregation, hardening, patching, monitoring and recovery, with cautions about testing operational systems.