The petroleum sector in Norway plays a key role in Europe's energy supply system. At the same time, the complexity of the threat landscape has increased in step with digitalisation and automation. Tactics such as cyberattacks, sabotage and influence campaigns are increasingly being used in combination, a trend which is challenging the established norms for risk and incident management.
As digitalisation and the integration of systems and processes have progressed, the sector has become more dependent on complex and interconnected systems that control, monitor and protect critical functions.
At the same time, system security is impacted by a range of physical factors, including access control and the protection of facilities and equipment, which can be exploited in connection with sabotage and insider-related incidents, among other things.
When physical security measures and cybersecurity measures are not viewed as a whole, vulnerabilities may arise that are neither identified nor addressed.
When technical silos create vulnerabilities
It is widespread practice for the various security entities to be assigned to different parts of the organisation. As a result, the various disciplines develop their own methodologies and understanding of the threat and vulnerability landscape, and are experts within their respective fields.
When dealing with incidents that impact only one discipline, this segmentation can be useful, as it can help to clarify areas of responsibility and simplify incident management. However, this approach can also create vulnerabilities when faced with complex risks, vulnerabilities and incidents.
When facing complex risks, it is crucial that the various disciplines are able to coordinate and collaborate with each other in order to obtain a comprehensive picture of the risks involved. A lack of collaboration can result in a fragmented risk picture, vulnerabilities going undetected, and less effective incident response.
The petroleum sector is a high-risk sector and the consequences of undesirable incidents have the potential to be severe for people, the environment, assets and society at large. That is why holistic risk management is essential.
Investing in collaboration between specialist groups can improve situational awareness, lead to more effective measures, and enhance organisational resilience.
Safety requires continuous investment
Over time, the petroleum sector in Norway has demonstrated a high level of safety and security, but maintaining this level requires continuous investment. It is not just about technology, but also about holistic management, professional development and the development of platforms for collaboration across disciplines. This comes at a cost, but the cost of inaction could be far greater.
When facing complex risks, collaboration across disciplines is essential for building resilience. The various specialist groups must communicate with each other and develop a shared situational awareness.
Over time, silos within security organisations can create blind spots in the risk picture, lead to diffuse lines of responsibility in the management of vulnerabilities, and reduce the ability to handle complex incidents.
From words to actions
To manage complex security and cybersecurity risks and incidents, it is crucial to adopt a holistic view. It is not about individual measures or segmented disciplines, but rather about the sum total of all the work that is carried out within the organisation that can prevent, detect or manage an incident, including security and cybersecurity initiatives.
Building resilience requires ongoing effort, shared situational awareness and holistic expertise. Sustainable resilience requires organisations to move from intentions to action and invest in collaboration, governance and resilience.
ESREL paper
The issues discussed in this article are described in greater detail in a technical paper presented at ESREL 2026 (the European Safety and Reliability Conference).
The paper examines how the integration of security and cybersecurity can contribute to a more comprehensive understanding of risk and strengthen organisational resilience.