Oil and gas operators have long assumed that the operational technology (OT) networks running their wells, pipelines and refineries were isolated from corporate information technology (IT) systems.
And in many cases, they were right; OT and IT traditionally ran separately, a church and state-like governance model. Yet as with many tech modernisation trends, the two are converging.
The growing digitalisation of energy operations is eradicating the wall between IT and OT.
The systems that manage everything from drilling schedules and accounting to procurement, logistics and regulatory reporting now sit at the centre of this converged environment.
Yet paradoxically, this convergence remains largely outside the scope of industrial cybersecurity programs for many energy organisations.
This is a major gap at a time when 94 per cent of the top 400 oil and gas firms worldwide have experienced at least one data breach.
Targeting of energy infrastructure by both state-supported and individual perpetrators and growing reliance on third-party remote access – a byproduct of today’s API-fueled hunger for ubiquitous connectivity – are increasing the risk.
And SAP environments, which power the bulk of business operations for oil and gas entities, sit squarely in the crosshairs.

When your business applications become an attack vector
As most IT leaders will tell you, SAP comprises the financial and operational nervous system of most major energy companies.
When an SAP environment is compromised, adversaries gain considerable leverage over the organisation.
Intruders may manipulate maintenance scheduling data and delay critical equipment inspections or crash supply chains by corrupting procurement records.
Perpetrators might even redirect vendor payments to the tune of millions of dollars or traverse SAP middleware interfaces toward connected operational technology systems.
That last scenario is the one that scares energy sector CISOs the most.
Because it underscores how SAP is no longer just an accounting platform; it is a data bridge between the business and the plant floor.
As such, an attacker with access to SAP may gain a path to penetrate the SCADA environment.

ANATOMY OF AN SAP ATTACK
Adversaries targeting SAP in oil and gas environments typically sneak in through third-party connectivity, say joint venture partners, drilling contractors and oilfield services vendors who have been granted SAP access for a project and never offboarded.
Once inside, attackers exploit over-provisioning in SAP authorisation models.
Think years of mergers, acquisitions and project-based access grants that leave accounts with greater system access than they need.
From there, attackers use native SAP transaction codes, batch jobs and built-in remote function call (RFC) modules to move through the environment. This type of exploit is called “living off the land”.
The gotcha moment? Because the activity often uses legitimate SAP processes, it generates no malware signatures and triggers no endpoint detection rules.
Standard security tools guarding the network and endpoint layer will miss it completely. These tools don’t see what is happening inside an SAP application.
The truly scary detail is that these attacks don’t yet involve AI, which is quickly emerging as a favourite weapon in adversaries’ arsenals.
Google in May discovered that a criminal hacking group tried to launch a cyberattack that relied on AI to detect a previously unknown bug.
This begs the question: How soon before AI accelerates the number of zero-day attacks for which there is no defence? It’s a question that CISOs hope to never answer.
For now, given that the IT-OT convergence increases the attack footprint for adversaries, it’s critical that organisations leverage a zero-trust cybersecurity model all the way to their ERP and its surrounding ecosystem.

SAP-native security offers organisations another hedge
Even with zero trust fully exercised, organisations would do well to close this gap with security capabilities that are native to SAP itself and detect threats in real time.
Continuously analysing SAP users, roles, code, logs, configurations and system behaviour, unifying cybersecurity, access control, compliance and monitoring is critical.
This approach will help detect anomalous behaviour, such as changes to master records, a “privileged user” accessing drilling data when they have no reason to, RFC calls at odd hours and unfamiliar code executions.
All with no external virtual machines, no separate connectors and no additional attack surface to patch.
Such protection is table stakes for large oil and gas operators tasked with managing complex, geographically dispersed SAP landscapes.
It’s a security architecture that travels with the SAP system, not working in parallel where it may fall out of sync.
THE BOTTOM LINE
As valuable as oil and gas infrastructure is for the companies that work the wells, cyber adversaries seek riches by targeting the data pipeline that serves and stores information across the converged digital ecosystem centralised in SAP.
This environment spans financial operations, supply chain, contractor networks and, increasingly, operational technology.
Accordingly, oil and gas entities would do well to incorporate SAP into their critical infrastructure asset inventory.
Other steps include conducting an honest assessment of their SAP authorisation and patch posture and demanding visibility in their SOC at the SAP level.
Ultimately, deploying security that is native to the SAP environment is the best bet for comprehensive protection.
Because just as you can’t manage what you can’t measure, it’s hard to protect what you can’t see happening inside the application environment.

