LockurBlock Digital News & Media Platform

collapse
Home / Daily News Analysis / Marathon Petroleum’s CISO on OT security automation, supply chain risk

Marathon Petroleum’s CISO on OT security automation, supply chain risk

Jul 29, 2026  Twila Rosenbaum 4 views
Marathon Petroleum’s CISO on OT security automation, supply chain risk

Mary Rose Martinez, Chief Information Security Officer at Marathon Petroleum, recently shared insights on the evolving challenges of securing operational technology (OT) as automation expands across refineries, pipelines, and terminals. The discussion covered the shift from air-gapped environments to interconnected digital systems, the pragmatic use of the Purdue model, and the complexities of managing supply chain risk in an industry where vendors and their subcontractors hold critical keys to operations. With state-aligned actors increasingly probing energy infrastructure, Martinez highlighted the importance of cross-skilling the workforce and maintaining strong partnerships with government agencies.

The Dissolution of Air-Gapped OT

Marathon Petroleum operates an extensive network of refineries, pipelines, and storage terminals—assets that have traditionally been isolated from corporate IT networks. However, as automation deepens, the security boundary has moved in unexpected ways. Martinez noted that the traditional concept of air-gapping OT environments is effectively dissipating. Industrial control systems such as programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems are now exposed to broader digital ecosystems. This transition is not unique to energy—manufacturing, transportation, and other critical infrastructure sectors face similar exposure. Security teams must continuously reassess their defensive controls to keep pace with these changes.

Defending Systems That Cannot Be Patched on a Typical Schedule

A key reality in OT security is that critical industrial equipment—like a catalytic cracker in a refinery—cannot be rebooted on Patch Tuesday. Martinez explained that Marathon Petroleum leverages the widely accepted Purdue Enterprise Reference Architecture (PERA) model. This framework divides control system networks into hierarchical levels (from Level 0 for physical processes to Level 4 for enterprise IT). By implementing appropriate security controls at and between these layers, Marathon creates space to synchronize security actions with regular operational cadences without disrupting production. For example, patch management can align with planned maintenance outages, and network segmentation prevents lateral movement from IT to OT.

Supply Chain Risks: Visibility and Control Gaps

Autonomous operations come bundled with vendor platforms, third-party models, and remote support tunnels. Martinez pointed out that the greatest risks in the supply chain lie where companies have the least visibility and control. Marathon has greater control over how its own environment is accessed, but far less over vendors’ products or security practices. These risks extend past third-party vendors to nth-party vendors deeper in the supply chain. To mitigate these, Marathon performs rigorous due diligence and assessments when evaluating new products or services, leveraging contractual language to enforce security requirements. Building partnerships with key vendors is also valuable—whether by providing input on product design or coordinating joint incident response to restore operations quickly.

Cross-Skilling the Workforce for a Digitized OT Environment

As processes run autonomously, the workforce around them changes. Skill gaps can open between those who understand the chemistry of refining and those who understand code. Martinez cited the concept of “Calm Technology” as a goal, where systems are as invisible as possible in support of human tasks. However, this does not eliminate the need for cross-skilling. Technology advancements—especially in artificial intelligence—are lowering the bar to codification, but they change the type of skilling required. Marathon develops different learning pathways to increase digital fluency, addressing the varied needs and interests of employees. For example, operators might learn basic scripting for data analysis, while IT staff gain familiarity with industrial control system protocols.

Adapting to Government Directives and State-Aligned Threats

Critical infrastructure operators face growing pressure from agencies like CISA and transportation security directives from the TSA. The threat environment includes state-aligned actors probing energy systems for vulnerabilities. Martinez emphasized that Marathon understands its role in the nation’s critical infrastructure and continually adjusts strategies based on the evolving threat landscape. Partnerships with government agencies are key—both for leveraging intelligence to allocate resources efficiently and for providing input into regulations that are operative and effective for the industry. The move toward automation changes what Marathon reports, how it defends, and what it assumes an adversary already knows. For example, more automated systems generate additional telemetry that can be shared with information-sharing and analysis centers (ISACs), and defensive architectures must assume that adversaries have mapped the digital layout of control systems.

Marathon Petroleum’s approach illustrates the delicate balance between embracing automation for efficiency and maintaining robust security in a sector where failure can have catastrophic consequences. By using the Purdue model, investing in supply chain visibility, cross-skilling personnel, and collaborating with government, the company works to stay ahead of threats while keeping the nation’s fuel supply flowing.


Source:Help Net Security News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy