OT ASSET VISIBILITY ON THE GULF COAST: WHAT THE NEWPARK RESOURCES BREACH REVEALS ABOUT INVENTORY BEFORE THE ATTACK

OT asset visibility on the Gulf Coast: what the Newpark Resources breach reveals about inventory before the attack

On October 29, 2024, an unauthorized third party gained access to internal information systems at Newpark Resources, a Woodlands-based supplier of drilling tools and equipment to Gulf Coast pipelines, refineries, and petrochemical plants. The company’s cybersecurity response plan contained the intrusion to financial and operating reporting systems. Manufacturing and field work carried on without material disruption, running on established downtime procedures while the response team worked.

That distinction, information systems disrupted, field operations undisturbed, took confidence to draw. Someone at Newpark already knew which systems ran the reporting stack and which ran the rigs. Oil and gas ranks with the widest OT visibility and detection gaps of any industrial sector today, and that kind of OT asset visibility on the Gulf Coast is rare across the petrochemical corridor. Operational technology (OT) is the programmable logic controllers, distributed control systems, and safety instrumented systems running the physical process. It only stays protected in an incident when someone already has an accurate account of what’s out there.

OT asset visibility on the Gulf Coast means maintaining a current, validated inventory of every programmable logic controller, distributed control system, and safety instrumented system connected to a plant’s operational network, including field devices below the layer most IT discovery tools reach. Without it, a security team cannot confirm which systems a breach did or didn’t touch.

The corridor this is actually about

The Houston Ship Channel is one of the most concentrated stretches of petrochemical infrastructure in the United States. Port Houston, the public authority that oversees the channel, counts more than 150 marine terminals along its 52 miles of industrial waterway. LyondellBasell’s Channelview complex sits at the eastern edge of Harris County. Dow’s Freeport site anchors the southern end of the corridor. Chevron Phillips Chemical runs major production assets at Cedar Bayou and Sweeny. ExxonMobil operates processing facilities at Baytown and Beaumont.

Every facility on this stretch runs production on OT that predates modern network visibility requirements. A cybersecurity incident at any of them proceeds differently depending on whether the response team already knows what equipment is on the network. That knowledge needs to exist before the first alert fires, not after.

The Newpark filing points toward that condition without naming it directly. It isn’t an isolated pattern: Virima’s analysis of what Atlanta’s Fulton County ransomware attack revealed about unmanaged IT assets found the same inventory gap surfacing in a different environment entirely. What makes that visibility difficult to build on the Gulf Coast is structural, and it starts with the corridor itself.

What asset discovery means inside an OT environment

The Purdue Model divides industrial control systems into five functional layers. Enterprise networks and business systems sit at the top. Below them are site operations, then supervisory and control networks. At the base are field devices: programmable logic controllers (PLCs), remote terminal units, and sensors wired directly to physical process equipment.

IT discovery tools perform well on enterprise and site-level networks. They don’t translate cleanly below those tiers. Standard active scanning sends a probe packet to every reachable device and waits for a response. A PLC running decade-old firmware may interpret that unexpected traffic as a command. The result can be a halt, a fault, or unpredictable equipment behavior in a live chemical plant.

Passive monitoring avoids that risk by listening to network traffic without generating its own. It captures device behavior at Purdue Layers 2 and 3, the supervisory and control tiers, without touching equipment directly. The ceiling is structural. PLC backplanes at Layer 1 communicate over vendor-proprietary protocols that don’t traverse the plant network in a form passive sensors can read. The field device population closest to the physical process is also the one a passive-only program misses entirely.

That gap is a design characteristic of industrial control systems, not a temporary shortfall. Any inventory approach that doesn’t account for it produces a count with a floor above the field level.

Why does the passive monitoring ceiling matter during a cybersecurity incident?

When an incident requires identifying affected and unaffected systems, field devices that were never inventoried cannot be confirmed as untouched. The clean boundary between a disrupted reporting stack and operating field equipment only holds if every field device was counted and accounted for before the incident began. An unrecorded device cannot be ruled out of scope.

Where visibility breaks down

Ghost assets and detection gaps

Ghost assets accumulate wherever device churn outpaces inventory updates. In one industry-reported OT monitoring case, illustrative of the pattern rather than a named site, a refinery security operations center was processing approximately 12,000 alerts per monitoring cycle. Investigation traced the bulk to devices no longer present at the site, cloud endpoints outside the OT perimeter, and off-hours activity that monitoring rules hadn’t separated from operational noise.

Oil and gas had the highest malware detection gap rate of any industrial sector tracked by Dragos in their 2026 OT/ICS Cybersecurity Year in Review. That finding appeared in 37 percent of sector-level security assessments. In 13 percent of Dragos’s 2025 incident response cases, malware operated silently without triggering any alerts. According to Dragos, VOLTZITE, a confirmed Stage 2 threat group, compromised cellular gateways across U.S. midstream operations in 2025. Those devices sat at unmonitored OT edges, and IT teams had no visibility into their existence before the breach.

How much OT monitoring alert volume can trace back to ghost assets?

Ghost assets accumulate fastest on Gulf Coast OT networks during turnaround season, when contractor equipment connects for weeks and then leaves without being formally removed from the network record. In one industry-reported case illustrative of the pattern, a refinery security operations center traced roughly 12,000 alerts per monitoring cycle largely back to these stale, departed devices, not active threats.

Legacy systems and the governance gap

Legacy platforms extend the problem. Vulnerability management findings hit oil and gas hardest of any sector, appearing in 31 percent of findings, with patching constrained by operational continuity requirements and vendor qualification processes. Windows XP still controls terminals at some Gulf Coast facilities. That’s not because plant managers are unaware of its support status — the control application bound to it has no certified upgrade path. Each device stays in the environment and outside the visibility perimeter.

Below all three problems sits a governance question the technology alone doesn’t resolve. Plant engineering typically maintains asset records for OT systems. Corporate IT maintains records for enterprise endpoints. Poor IT/OT segmentation appeared in 29 percent of oil and gas findings, the highest share of any sector. When those records diverge and no shared perimeter definition exists, no authoritative count of the environment is possible. That pattern isn’t unique to OT: Virima’s guide to IT asset visibility for cybersecurity covers the same divide in general IT environments, before an OT boundary complicates the count further.

What happens when plant engineering and corporate IT maintain separate OT asset records during an incident?

When a security incident requires scoping affected systems, conflicting records from plant engineering and corporate IT force teams to reconcile under pressure. A device appearing in one record but not the other falls into a grey zone where neither team can confirm its status. That gap is where incident dwell time estimates and blast radius calculations become unreliable.

How Gulf Coast security teams establish authoritative OT asset visibility

Virima’s Trusted Runtime Truth gives SecOps and plant teams a single, discovery-sourced inventory spanning both sides of the IT/OT boundary, built before an incident requires it.

Explore Trusted Runtime Truth

How Houston’s operating rhythm makes each gap worse

Gulf Coast chemical plants don’t run at steady state year-round. Turnaround season, the planned maintenance cycle when major process units come offline for inspection and repair, concentrates device churn at a predictable point in the calendar.

Q1 2026 alone carried more than $480 million in planned maintenance projects across Gulf Coast chemical plants. BIC Magazine reported the figure, citing Industrial Info market data. Chevron Phillips Chemical prepared work on Ethylene Unit 22 at its Old Ocean facility near Sweeny, one of the named projects in that cycle.

Each turnaround brings a temporary surge of contractor equipment onto the site. Engineering laptops connect to workstations. Portable analyzers patch into control network access points. Laydown-yard devices connect for the duration of the project and then leave with the crews. Most contractor equipment clears TWIC-gated site access, which is a physical security check. Clearing a device inventory process is a separate step, and it doesn’t always happen.

Device Churn Curve Across A Gulf — Ot Asset Visibility Gulf Coast Petrochemical

When a turnaround closes, some contractor equipment departs without being formally removed from the network record. The device entry persists. It generates alerts. It skews the asset count. This is the mechanism that produces ghost assets at petrochemical sites in volume, and it repeats on a seasonal schedule.

Hurricane season adds a second, differently sourced churn window: emergency generators, backup power equipment, and portable communications gear arrive quickly, under compressed documentation conditions, and not all of it is retired from the network record once the storm passes. Both cycles repeat annually, and each extends the drift between what the inventory shows and what is actually on the network.

The regulatory backdrop, and what it doesn’t solve

TSA’s pipeline security directives have tightened in the past two years. SD Pipeline-2021-02F became effective in May 2025. SD Pipeline-2021-01G followed in January 2026. Together, they require covered pipeline operators to:

  • Implement network segmentation between IT and OT systems
  • Report significant cybersecurity incidents within twelve hours
  • Submit annual cybersecurity assessment documentation

Virima’s analysis of IT asset visibility for TSA pipeline security compliance in Houston covers those inventory obligations in more depth.

The directives apply to pipeline operators. They don’t extend to the petrochemical plants, refineries, and chemical manufacturing facilities that operate alongside the same corridor.

The Chemical Facility Anti-Terrorism Standards program (CFATS) carried mandatory cybersecurity requirements for high-risk chemical facilities until Congress allowed it to lapse in July 2023. A voluntary program replaced it. The enforcement mechanism is no longer in place.

What did the CFATS lapse mean for Gulf Coast chemical facilities?

CFATS required high-risk chemical facilities to maintain and submit cybersecurity plans, including asset identification controls, as a mandatory condition of operation. When the program lapsed in July 2023, those requirements became voluntary for Gulf Coast chemical and petrochemical operators. TSA pipeline directives don’t cover this segment. For the petrochemical corridor, CFATS was the primary mandatory framework, and its lapse removed the enforcement mechanism that made asset inventory a required control.

Compliance documentation and an accurate, current asset inventory are two different deliverables. A facility can satisfy annual assessment requirements by submitting network diagrams and policy documentation. None of that satisfies the need for a validated count of every connected device on the plant floor. The Newpark response team needed the count. Assessment documentation produces something else entirely.

What Purdue Model-aligned OT discovery looks like here

No single method reaches every layer of a Gulf Coast OT environment. Closing the OT asset visibility gap on the Gulf Coast requires combining approaches.

Passive, protocol-aware monitoring covers Purdue Layers 2 and 3. It identifies supervisory servers, historian systems, and engineering workstations by analyzing traffic patterns, without sending probes that could disturb control equipment. This method works at the supervisory tier without touching the devices below it.

Host-based methods close the Layer 1 gap that passive monitoring can’t reach. Some OT vendors publish lightweight agents for specific PLC and distributed control system (DCS) families. Where agents aren’t available, host-based interrogation over vendor-native protocols reaches devices that passive sensors miss. Combining passive network monitoring with targeted host-based collection produces an inventory that includes the field layer, not just the supervisory tiers above it. This hybrid pattern isn’t unique to petrochemical plants either: Virima’s work on OT/IT asset discovery for manufacturing environments shows the same passive-plus-host-based combination closing the same Layer 1 gap in a different industrial setting.

The realistic operating model in environments where active scanning risks process disruption is high-frequency scheduled discovery. Discovery runs on a defined cadence, aligned to plant operating windows and maintenance periods, so the inventory captures contractor equipment that arrives during a turnaround and flags it when that equipment doesn’t disappear when the project closes.

Purdue Model Layer Diagram Showing Disco — Ot Asset Visibility Gulf Coast Petrochemical

The governance split between plant engineering and corporate IT resolves when both the plant-floor record and the enterprise network record feed a single validated inventory with clear ownership assigned to each asset. That unified record is what a response team reaches for when it needs to draw a boundary between affected and unaffected systems under pressure.

Why is protocol-aware OT discovery safer than standard active scanning in petrochemical environments?

Protocol-aware discovery sends probes formatted for the specific communication standard each device expects: Modbus, EtherNet/IP, PROFINET, or DNP3. Standard TCP port scanning sends unexpected packets that a PLC or DCS firmware may interpret as a command or fault condition. Protocol-specific probes are recognized as standard queries and handled without interrupting the control process.

Where a platform fits

Virima operationalizes this approach for environments that span IT and OT. Its cybersecurity asset management capability pairs passive protocol-aware monitoring with high-frequency scheduled discovery, and surfaces asset ownership and dependency relationships alongside the device count. The result is a single validated inventory covering the plant floor and the enterprise network in one record. For response teams that need to draw a line between a disrupted information system and operating field equipment, that inventory is where the boundary lives before the incident, not during it.

The boundary that held, and what it takes to build one

The Newpark Resources 8-K filing, later covered by The Record and confirmed as a ransomware incident, is a brief document. The most operationally significant claim in it states that manufacturing and field work continued without material disruption while the response team worked. That outcome was prepared before the incident, when someone documented which systems ran the reporting stack and which ran the equipment in the field.

The factors that make that documentation difficult on the Gulf Coast are structural. Turnaround churn cycles device populations each turnaround season. Legacy platforms resist standard discovery tooling. Plant engineering and corporate IT maintain separate records with no shared authority over a single count. The regulatory framework that once mandated asset inventory for chemical facilities no longer carries enforcement authority over much of this corridor.

Each of those factors is present at most facilities along this stretch. Each is also addressable. A hybrid discovery approach closes the OT asset visibility gap on the Gulf Coast. A governance model that assigns clear ownership to a single inventory resolves the split between plant engineering and corporate IT, before an incident requires it.

The operators who complete that work gain what Newpark’s response team already had: a known boundary. Every operator without one draws that line for the first time under pressure. The inventory gets built during the incident, not before it.

Build the inventory before the incident

See where your Gulf Coast site’s OT/IT boundary actually sits, before an incident forces you to find out. Schedule a walkthrough of Virima’s discovery-sourced inventory across Purdue Layers 1-3.

Schedule Demo

Frequently Asked Questions

What makes OT asset discovery harder than IT asset discovery?

IT discovery tools rely on active scanning techniques that send probe packets to network-connected devices and collect responses. These methods perform well on enterprise networks but risk disrupting legacy OT equipment, including PLCs, DCS units, and remote terminal units (RTUs), that wasn’t designed to handle unexpected network traffic. OT discovery requires passive protocol-aware monitoring for supervisory layers, host-based or agent methods for Layer 1 field devices, and scheduled discovery windows aligned to plant operations rather than continuous probing.

Why can’t passive network monitoring inventory all OT devices?

Passive monitoring captures traffic at Purdue Layers 2 and 3, the supervisory and control tiers. PLCs and other field devices at Layer 1 communicate over vendor-proprietary backplane protocols that don’t traverse the plant Ethernet network. Passive sensors positioned on the network don’t receive those communications, so Layer 1 field devices remain invisible to a passive-only discovery program regardless of sensor placement. This is a design characteristic of industrial control systems, not a coverage gap that additional passive sensors can close.

What did the CFATS lapse mean for Gulf Coast chemical and petrochemical facilities?

The Chemical Facility Anti-Terrorism Standards (CFATS) program required high-risk chemical facilities to maintain and submit cybersecurity plans, including asset identification controls, as a mandatory condition of operation. After Congress allowed the program to lapse in July 2023, those requirements became voluntary. TSA’s pipeline security directives (SD Pipeline-2021-02F, SD Pipeline-2021-01G) apply to pipeline operators specifically, not to chemical or petrochemical manufacturers. For the Gulf Coast petrochemical corridor, CFATS was the primary mandatory framework, and its lapse removed the enforcement mechanism that made maintaining a current asset inventory a required control rather than a discretionary one.

How does Virima discover assets in OT environments without disrupting live processes?

Virima uses a hybrid discovery approach that combines passive protocol-aware monitoring with host-based and agent-based methods. Passive monitoring listens to network traffic at the supervisory and control layers without generating probe traffic that could reach sensitive control equipment. For Layer 1 field devices, Virima uses host-based interrogation over vendor-native protocols, including Modbus, EtherNet/IP, and DNP3, that devices recognize as standard queries. Discovery runs on a scheduled cadence aligned to plant operating windows rather than continuously, reducing the risk of unexpected traffic reaching PLCs or DCS units during production.

What is Virima Trusted Runtime Truth and how does it apply to IT/OT environments?

Virima’s Trusted Runtime Truth is a discovery-sourced, validated inventory of every asset in an environment, covering what exists, how assets connect, what changed, and who owns each one. In IT/OT environments, this spans the enterprise network and the plant floor in a single record, resolving the split between corporate IT and plant engineering asset records into one authoritative count. It gives security response teams a validated inventory before an incident begins, so the boundary between affected information systems and unaffected field operations can be drawn from evidence rather than assumption.

Move faster. Act safely.

Get live, explainable runtime truth across your entire estate — without platform lock-in.

Similar Posts