Offshore Energy Operator Gains Clear Cyber Risk Picture for FPSO Vessel

Case Study

An offshore energy operator engaged Armexa to conduct an initial OT Cybersecurity Assessment of an FPSO vessel, ahead of assuming operational control of the asset. Armexa applied its 3D OT Cyber Assessment Model, combining a Cyber Architecture Design Review, Gap Assessment, and CyberBowtie Risk Assessment across control SIS and other safety systems to deliver a quantified risk profile, benchmarked compliance scorecard, and a prioritized remediation roadmap. 

Challenges

Identifying cybersecurity risk before taking operational responsibility 

The vessel’s OT environment comprised multiple generations of control and safety systems from various vendors, with no evidence of a prior formal cybersecurity assessment. As such, cybersecurity risk had not been systematically evaluated or validated in advance of the planned transition of operational responsibility. Key known challenges and constraints included: 

  • Absence of documented cybersecurity practices. 
  • Outdated or unverified system architecture documentation. 
  • Limited access to validate current-state conditions. 
  • Incomplete visibility into system changes and upgrades. 
  • Unclear remote access pathways and governance.

Our Solution

A structured, evidence-based OT cyber assessment 

Armexa conducted a three-phase assessment using available documentation, architecture diagrams, and SME research, with limited operational engagement required. 

  • Design Review: Analyzed system architecture, generated a logical block diagram of all FPSO systems partitioned into study zones, and identified design-level vulnerabilities across network, endpoint, access control, and monitoring domains. 
  • Gap Assessment: Benchmarked cybersecurity maturity against NIST CSF 2.0, ISA/IEC 62443, and Armexa’s Top 20 ICS Best Practices — compared against Oil & Gas industry peers — producing a quantitative scorecard across all six NIST functions. 
  • CyberBowtie Risk Assessment: Applied ISA/IEC 62443-3-2 risk assessment methodology using the acquiring operator’s corporate risk matrix, ensuring alignment with post-acquisition risk tolerance and decision-making. Evaluated credible threat scenarios across all assessed systems to produce current and future residual risk scores for 80+ consequence scenarios.

Findings were synthesized into a phased Do Now / Do Next / Do Later roadmap, sequenced by risk reduction impact, cost, and operational feasibility.
stems to produce current and future residual risk scores for consequence scenarios. 

Outcomes & Impact

Quantified Risk & Gap Picture 

The FPSO’s current NIST CSF 2.0 maturity score was benchmarked below the Oil & Gas industry average.  Armexa’s CyberBowtie analysis revealed a fundamental reliance on mitigation over prevention, where post-event safeguards alone were insufficient to achieve acceptable risk levels without strengthening preventive cybersecurity controls. The assessment revealed that shared infrastructure between control and safety systems created common-mode failure pathways,  a single cyber event had the potential to simultaneously disable both operational control and the safety systems intended to mitigate its consequences. 

Armexa delivered a phased remediation roadmap with prioritized recommendations, structured to achieve a significant reduction in threat likelihood and a material increase in compliance score.  “Do Now” actions were designed to deliver fast, visible risk reduction within 90 days, without requiring operational disruption. The operator gained the independent, evidence-based view needed to take on operational responsibility confidently, with a structured improvement plan and a defensible foundation for long-term OT cybersecurity governance. 

Facebook
X
LinkedIn

Industry 

Energy — Offshore Oil & Gas 

Environment 

FPSO Vessel, Offshore 

OT systems including: 

  • Integrated Control and Safety System 
  • Power Management 
  • Fiscal Metering & Gas Compression 
  • 10+ package/process systems 

Standards 

  • NIST CSF 2.0 
  • ISA/IEC 62443-2-1 & 3-2 
  • NIST SP 800-82 
  • Armexa Top 20 ICS Best Practices 

Services 

  • OT Cyber Architecture Design Review 
  • Maturity Gap Assessment against NIST CSF 2.0 
  • CyberBowtie Risk Assessment 
  • Prioritized Remediation Roadmap 
  • Executive Reporting & Presentation 
Download Case Study

Latest Posts

Skip to content