
Marathon Petroleum, one of the largest petroleum refining, marketing, and transportation companies in the United States, operates an extensive network of refineries, pipelines, and terminals. As the company pushes automation deeper into these operational technology (OT) environments, its CISO Mary Rose Martinez has had to reassess fundamental security assumptions. In a wide-ranging discussion, she detailed how the security boundary has shifted, the realities of patching industrial controls, the complexities of vendor dependency, and the workforce skill gaps that arise when code and chemistry converge.
The Dissolving Air-Gap and Shifting Security Boundaries
For decades, operational technology security relied on the concept of air-gapping—keeping OT networks physically isolated from IT networks and the internet. Martinez explains that this traditional mindset is becoming obsolete. "We have had to make the mindset shift that the traditional concept of air-gapping OT environments is effectively dissipating," she says. OT environments are increasingly digitized, exposing industrial control systems like programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems to greater risk. This digital transformation is not unique to energy; manufacturing and transportation sectors face similar exposure. As automation permeates deeper, security teams must continuously reassess protective and defensive controls to ensure they remain adequate and effective.
The move toward autonomy—where refineries, pipelines, and terminals run with minimal human intervention—creates new attack surfaces. Martinez’s team discovered that the boundary has moved from the network perimeter to the very devices controlling critical processes. The integration of IT and OT systems means that an initial compromise in corporate IT can now pivot into the operational environment. This requires a shift in defense strategies, including segmentation at the control level, robust monitoring of OT protocols, and strict access controls for remote maintenance tunnels.
Architecting Defenses Around Autonomous Systems: The Purdue Model
One of the most significant operational realities in OT security is the inability to simply reboot or patch industrial equipment on a standard patch Tuesday schedule. A catalytic cracker in a refinery, for instance, runs continuously for months or years. Martinez emphasizes Marathon’s unwavering commitment to safe, reliable, and environmentally sound operations. To balance security with business continuity, the company leverages the Purdue Enterprise Reference Architecture (PERA) model—a widely accepted framework for segmenting industrial control systems into layers from Level 0 (physical process) to Level 4 (enterprise IT).
"When the appropriate security controls are implemented at and between the information and operational technology layers of the model, space is created to synchronize security actions with regular operational cadences while mitigating risk," Martinez explains. This approach allows Marathon to apply patches during planned maintenance windows, implement network segmentation to limit lateral movement, and deploy intrusion detection systems that understand OT protocols. The Purdue model also helps in defining zones of trust. For example, the safety instrumented systems (SIS) can be isolated from the control network, ensuring that even if an attacker gains access to the SCADA layer, they cannot directly manipulate safety-critical functions. Martinez notes that the model’s flexibility is key—security controls at each layer can be adapted without disrupting ongoing production.
Supply Chain Risk: The Vendor Dependency Chain
Automation comes bundled with vendor platforms, third-party models, and remote support tunnels. Martinez identifies the greatest supply chain risks as those where companies have the least visibility and control. Marathon has significant control over how its own environment is accessed, but far less control over its vendors’ products or security practices. These risks extend beyond third-party vendors to nth-party vendors deeper in the supply chain. For instance, a vulnerability in a component from a subcontractor that supplies a major OT vendor could ripple through multiple customers.
To mitigate these risks, Marathon performs thorough due diligence, conducts risk assessments, and uses contractual language to set security requirements when evaluating new products or services, and when material changes occur. "Forming partnerships with key vendors is valuable as well—whether it results in the ability to provide input on products and services or jointly responding to an event and restoring operations as quickly as possible," Martinez adds. This collaborative approach extends to joint tabletop exercises and information sharing. She emphasizes that no single organization can secure the entire supply chain alone; industry-wide cooperation is essential.
The reliance on remote support tunnels is particularly concerning because they can bypass traditional network defenses. Martinez’s team implements multi-factor authentication (MFA) for all remote access, monitors outbound connections from OT to vendor cloud services, and requires vendors to use dedicated jump boxes with session recording. Despite these measures, she acknowledges that supply chain attacks like the 2020 SolarWinds incident demonstrate how deeply an attacker can infiltrate through trusted vendors. The energy sector must remain vigilant, constantly reassessing the trust assumptions placed in third parties.
Closing the Human Skill Gap Between Chemistry and Code
As process automation increases, the workforce around it changes. There is a growing risk of skill gaps between engineers who understand the chemistry and physics of refining and those who understand the code that controls autonomous systems. Martinez points to the concept of Calm Technology, where systems are designed to be as invisible as possible in support of human tasks. Achieving this requires that the people developing, securing, and providing digital systems thoroughly understand business processes and operations. At the same time, democratization of digital know-how is necessary.
Technology advancements, especially in artificial intelligence (AI), are helping to lower the barrier to codification. For example, AI-assisted programming tools can help operational personnel write simple scripts without deep coding expertise. However, Martinez cautions that this does not eliminate the need for cross-skilling personnel—it changes the nature of the skills required. Marathon has developed different learning pathways to increase digital fluency across the company, tailored to various roles and interests. These include hands-on workshops, online modules, and cross-departmental rotations. Some engineers from refining backgrounds have taken cybersecurity certification tracks, while IT security staff have participated in plant simulator exercises to understand the operational impact of their decisions.
The goal is to maintain a meaningful human backstop: people who can intervene when automated systems behave unpredictably or when an attack bypasses digital defenses. Martinez stresses that the human element remains the most adaptive part of the security posture. "We need to make sure that the people who understand the chemistry also understand the code, and vice versa," she says. This fusion of knowledge is critical for detecting anomalies that automated tools might miss.
Responding to Government Pressure and State-Aligned Threats
Critical infrastructure operators face growing pressure from agencies like the Cybersecurity and Infrastructure Security Agency (CISA), the Transportation Security Administration (TSA) directives, and state-aligned adversaries probing energy systems. Martinez acknowledges that Marathon understands its role in the nation’s critical infrastructure. The move toward autonomy changes what the company reports, what it defends, and what it assumes an adversary already knows.
Reporting obligations have expanded under TSA security directives, requiring immediate notification of certain incidents. Automation generates vast amounts of data, which must be parsed and prioritized. Martinez’s team uses automated logging and security information and event management (SIEM) systems to correlate OT events, but human analysis is still needed to identify true threats from false positives. Defensively, Marathon re-evaluates the efficacy of protective and defensive controls proportionately with technology advancements. The assumption that advanced persistent threat (APT) groups already have some knowledge of the OT environment drives a zero-trust mindset within the operational network. "We assume an adversary may already have a foothold somewhere, so we design controls accordingly," she explains.
Partnerships with government agencies remain key. Marathon leverages threat intelligence from CISA and other partners to prioritize resources efficiently. Additionally, the company provides input to regulatory bodies to ensure that security regulations are operative and effective for the industry at large. Martinez believes that collaboration between the private sector and government is essential to stay ahead of threats, especially as state-aligned actors continue to probe weaknesses in energy systems. She cites examples such as the 2021 Colonial Pipeline ransomware attack, which shut down a major fuel pipeline, as a wake-up call for the entire sector. Since then, Marathon has increased its focus on ransomware resilience, including offline backups for OT systems and fast restoration procedures.
The integration of advanced security controls does not stop at the corporate level. Martinez’s team works closely with the Distributed Energy Resources (DER) ecosystem, as renewable energy assets like solar farms and battery storage are increasingly connected to the grid. These decentralized systems introduce new attack vectors that must be secured through a combination of hardware security modules and continuous monitoring.
Automation and the Changing Threat Landscape
As automation deepens, the attack surface expands exponentially. Martinez points out that adversaries are also using automation to scan for vulnerabilities and launch attacks at machine speed. Defenders must respond with similar velocity. Marathon employs automated threat hunting tools that analyze network traffic patterns in real time, searching for malicious behavior in ICS protocols like Modbus and DNP3. The company also uses deception technologies—honeypots and decoys—within the OT environment to lure and detect attackers early.
In addition, the rise of the Industrial Internet of Things (IIoT) blurs the lines between IT and OT. Smart sensors, wireless transmitters, and edge computing devices are proliferating in refineries and pipelines. Each device represents a potential entry point. Martinez stresses the importance of asset inventory and vulnerability management across the entire OT estate. "You cannot protect what you do not know you have," she says. Automated discovery tools help identify all connected devices, but the challenge remains in maintaining an up-to-date inventory as equipment is added or modified during maintenance cycles.
Another area of focus is the security of the supply chain for software updates. With automation, control logic updates may be delivered digitally. Ensuring the integrity of those updates—through code signing and cryptographic verification—prevents attackers from injecting malicious logic into PLCs. Marathon has implemented a secure update pipeline that validates all software before deployment, and any anomalies trigger an automated quarantine process.
Looking Ahead: The Role of AI and Machine Learning
Artificial intelligence and machine learning (ML) are playing an increasing role in OT security. Martinez sees potential for AI to reduce the cognitive load on security analysts by correlating events across IT and OT silos, detecting subtle anomalies that indicate a cyber-physical attack. However, she warns that AI models must be trained on OT-specific data to avoid false positives that could cause unnecessary operational stops. Marathon is piloting ML-based anomaly detection systems that learn normal behavior of pumps, valves, and motors, flagging deviations that could indicate compromise or mechanical failure.
The workforce cross-skilling efforts also include AI literacy. Operators are being trained to understand when an AI recommendation should be trusted and when it warrants human verification. This human-in-the-loop approach ensures that safety-critical decisions remain under human control. As Martinez puts it, "Automation should augment human capabilities, not replace them."
In the end, the journey toward secure automation in critical infrastructure is a continuous one. Martinez’s insights underscore that security must be baked into the design of autonomous systems, supply chain relationships must be managed proactively, and the workforce must evolve alongside the technology. Marathon Petroleum’s approach, grounded in the Purdue model and reinforced by government collaboration, provides a blueprint for other organizations navigating the complex intersection of OT, IT, and autonomy.
Source:Help Net Security News
