Air-Gapped OT Is Dead: Marathon Petroleum CISO on PLC Exposure and Supply Chain Risk

Air-Gapped OT Is Dead: Marathon Petroleum CISO on PLC Exposure and Supply Chain Risk

Why it matters now: The decades-old assumption that industrial control systems are safely isolated behind physical air gaps has collapsed. As automation penetrates every layer of refinery, pipeline, and plant-floor operations, programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems are increasingly addressable from enterprise networks — and, by extension, from the internet. This shift, long treated as incremental, has now reached an inflection point that demands immediate strategic attention from security leaders.

Analyst Insight: The global ICS security market is projected to grow from an estimated $18.35 billion in 2025 to $29.21 billion by 2030, reflecting a 9.7% CAGR. The primary driver is not regulation — it is the undeniable reality that OT environments are now porous, connected, and targeted. The air-gapped era is closing, and security architectures must be rebuilt for a converged world.

In an exclusive interview with Help Net Security, Marathon Petroleum Vice President and Chief Information Security Officer Mary Rose Martinez delivered a clear-eyed assessment: the traditional concept of air-gapping operational technology (OT) environments is effectively dissipating. Her perspective carries weight — Marathon Petroleum operates the largest refining system in the United States, and Martinez was recognized with a CISO ORBIE award in 2025 for excellence in cybersecurity leadership.

Martinez explained that OT environments are not simply becoming more connected — they are being fundamentally reshaped by digitization, creating exposure for the full spectrum of industrial control systems. The implications extend far beyond the energy sector. “This situation is not unique to the energy industry,” Martinez stated. “Manufacturing and transportation sectors are undergoing the same digital transition with increased exposure.”

The End of the Air Gap: How We Got Here

For decades, industrial operators relied on a simple, powerful assumption: if a control network was physically disconnected from business IT systems and the public internet, it was secure. That assumption began eroding with the rise of remote monitoring, predictive maintenance platforms, and the economic imperative to feed real-time operational data into enterprise resource planning (ERP) and supply chain management tools. The Purdue Enterprise Reference Architecture (PERA), commonly known as the Purdue Model, was designed precisely to manage this convergence — segmenting industrial networks into levels 0 through 5 to maintain controlled boundaries between OT and IT.

Martinez noted that her team relies on the Purdue Model to apply controls without halting production. But the model’s effectiveness now depends on how rigorously each layer is enforced — and on whether organizations acknowledge that the theoretical “air gap” at the boundary of Levels 3 and 4 is, in practice, permeated by dozens of sanctioned and unsanctioned connections.

Market Trend: A 40% rise in internet-exposed ICS devices was recorded between 2024 and 2025, according to industry analyses. Each exposed device represents a potential pivot point — attackers no longer treat OT as collateral damage but as the primary objective, mapping control loops and studying physical processes.

PLC, HMI, and SCADA: The New Attack Surface

The devices at the heart of industrial automation — PLCs executing logic on the plant floor, HMIs providing operator visibility, and SCADA systems aggregating data across sites — were designed in an era when physical isolation was a given. Security features, where they exist, are often rudimentary. Default credentials, unencrypted protocols, and firmware that cannot be patched without shutting down production are not edge cases; they are the operational reality in thousands of facilities globally.

Martinez emphasized that as automation permeates deeper into OT environments, security teams must perform a commensurate reassessment of protective and defensive controls. “The adequacy and efficacy of our controls must be continuously evaluated against evolving threats,” she told Help Net Security. This is not a one-time audit — it is an ongoing discipline that must keep pace with every new sensor deployed and every vendor connection authorized.

Documented Vulnerabilities in Industrial Control Systems

Click to expand: Key OT/ICS vulnerability categories (2024–2025)
  • PLC/HMI Default Credentials: Devices from multiple manufacturers, including Unitronics Vision and Red Lion controllers, shipped with hardcoded or default passwords still present in operational deployments.
  • SCADA Protocol Weaknesses: Unauthenticated remote access and code execution flaws identified in platforms including Tridium Niagara and Delta Electronics DIAEnergie.
  • Building Automation Exposure: Cylon ASPECT, NEXUS, and MATRIX controllers found vulnerable to full system compromise, affecting HVAC, energy distribution, and safety controls.
  • OT:ICEFALL Flaws: Affected Emerson PACSystem and Ovation control systems, exposing industrial valve operations to potential sabotage.

Supply Chain Risk: Vendors and Their Vendors

Perhaps the most urgent dimension of Martinez’s interview concerns supply chain dependencies. In modern industrial environments, operational continuity often depends on a multi-tiered web of technology vendors, system integrators, and remote support providers — each holding some form of network access. Martinez posed a critical question that every industrial CISO should be asking: “Which part of that dependency chain worries you most, and what leverage do you have to change a vendor’s security posture before you deploy their technology?”

The 2024 exposure of default credentials in fuel station automation systems (Orpak SiteOmat) and the Johnson Controls ransomware attack — which disrupted federal building security systems and prompted a DHS investigation — demonstrate that supply chain risk is not theoretical. When a vendor’s security failure cascades into operational disruption, the asset owner bears the ultimate consequence.

Analyst Insight: The U.S. Department of Energy’s Cybersecurity Supply Chain Report confirms that “all digital components in all types of U.S. energy sector systems are vulnerable and may be subject to cyber supply chain risks.” The report highlights that legacy systems running obsolete protocols face particular exposure — a finding directly relevant to aging PLC and SCADA fleets still operating across refineries and pipelines.

Beyond Energy: Manufacturing and Transportation Under the Same Pressure

Martinez was unambiguous that the erosion of air-gapped OT is an industry-agnostic phenomenon. Manufacturing plants deploying IIoT sensors for predictive maintenance, transportation networks integrating operational signaling with passenger information systems, and water utilities connecting SCADA to cloud-based analytics — all are navigating the same collision between operational safety requirements and digital transformation mandates.

The SANS Institute’s 2025 survey found that more than 22% of organizations reported a cybersecurity incident affecting OT systems in the past year, with 40% of those incidents causing operational disruption. Dragos’s 2026 OT/ICS Year in Review documented multiple state-aligned groups moving into control-loop mapping — pulling configuration files, alarm parameters, and enough process context to potentially interfere with physical outcomes.

Click to expand: OT cybersecurity incident statistics at a glance
  • 22%+ of organizations reported OT cyber incidents in the past year (SANS 2025).
  • 40% of those incidents resulted in operational disruption — production halts, safety system activations, or regulatory scrutiny.
  • 45% of OT/IoT security professionals reported losses exceeding $500,000; 27% reported losses over $1 million.
  • 39% of industrial companies report experiencing data breaches connected to automation systems.
  • 18.2% of all cyber threats now target OT environments (ENISA Threat Landscape 2025).

The Path Forward: Reassessing Controls Without Stopping Production

Martinez’s core message is one of proportional reassessment. Automation is not optional — it drives the efficiency, safety, and competitive positioning of modern industrial operations. But security architectures designed for isolated networks cannot be expected to protect interconnected ones. The Purdue Model remains a valuable framework, Martinez argues, but only when each layer’s controls are actively verified, tested, and adapted to the current threat landscape.

Key principles that emerge from Martinez’s approach include network segmentation that assumes compromise of any single zone, vendor security assessments that are contractual preconditions rather than post-deployment audits, and continuous monitoring that spans both OT and IT environments with shared visibility.

Strategic Takeaway: The $883 million acquisition of Nozomi Networks by Mitsubishi Electric in September 2025 — one of the largest OT security deals in history — signals that industrial automation manufacturers are embedding cybersecurity into their product roadmaps. Asset owners should evaluate whether their equipment vendors have comparable commitments, or whether security will remain an afterthought.

Frequently Asked Questions

What does “air-gapped” mean in OT environments?

An air-gapped OT environment is one that is physically disconnected from external networks, including corporate IT systems and the internet. The theory is that without a network path, remote cyberattacks are impossible. In practice, modern operations require data exchange for monitoring, maintenance, and optimization — creating connections that dissolve the air gap.

Why are PLCs and HMIs vulnerable?

PLCs and HMIs were designed for reliability and real-time control, not cybersecurity. Many use unencrypted protocols (e.g., Modbus, DNP3), ship with default credentials, and cannot be easily patched without production downtime. When these devices become network-accessible, their inherent security limitations become critical vulnerabilities.

What is the Purdue Model, and why does it matter?

The Purdue Enterprise Reference Architecture (PERA) divides industrial networks into levels 0 (physical process) through 5 (enterprise IT). It provides a structured approach to segmentation that allows data to flow upward while restricting lateral movement. It matters because it remains the most widely adopted framework for managing IT-OT convergence securely.

How does supply chain risk affect industrial cybersecurity?

Industrial environments depend on a complex chain of equipment vendors, system integrators, and remote support providers — each potentially holding network access. A security failure at any tier can cascade into operational disruption for the asset owner. The U.S. Department of Energy and CISA have both identified supply chain risk as a top-priority concern for critical infrastructure.

Is the erosion of air-gapped OT unique to the energy sector?

No. As Mary Rose Martinez stated, manufacturing and transportation sectors are experiencing the same digital transition with comparable exposure. Any industry that connects industrial control systems to enterprise networks — or to cloud-based analytics and remote maintenance platforms — is navigating the same risk landscape.

This article is based on an exclusive interview conducted by Help Net Security with Mary Rose Martinez, VP and CISO at Marathon Petroleum Corporation, originally published in July 2026. Industry data sourced from SANS Institute, Dragos, ENISA, MarketsandMarkets, and the U.S. Department of Energy.

Related Articles

Back to blog