HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

Marathon Petroleum CISO Highlights OT Security Automation Challenges and Supply‑Chain Risk in Energy Sector

Marathon Petroleum’s CISO explains how deeper automation in refineries is dissolving the air‑gap model and exposing PLC, HMI and SCADA systems. The discussion underscores the need for continuous vendor‑risk monitoring and auditable OT controls to satisfy SOC 2 readiness.

LiveThreat™ Intelligence · 📅 July 27, 2026· 📰 helpnetsecurity.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Marathon Petroleum CISO Highlights OT Security Automation Challenges and Supply‑Chain Risk in Energy Sector

What Happened — In a Help Net Security interview, Marathon Petroleum’s CISO Mary Rose Martinez explained how deepening automation in refineries, pipelines and terminals is eroding the traditional “air‑gap” security model. She described the use of the Purdue Enterprise Reference Architecture (PERA) to balance protection with production continuity, and warned that the greatest supply‑chain risk resides where the company has the least visibility into vendor‑owned OT components.

Why It Matters for Compliance & Audit Readiness

  • OT environments that are no longer air‑gapped require continuous, auditable evidence that security controls remain effective across both IT and OT layers – a core SOC 2 requirement for the Security principle.
  • Vendor‑managed automation platforms introduce third‑party dependencies; SOC 2 vendor‑management controls (CC6.1, CC6.2) demand documented due‑diligence, ongoing monitoring, and contractual assurances.
  • Mapping PERA‑based controls to SOC 2 criteria creates a defensible audit trail that demonstrates risk‑based control design without halting critical operations.

Who Is Affected – Energy & utilities operators, industrial manufacturers, transportation firms that rely on OT automation and third‑party control‑system vendors.

Recommended Actions

  • Map your OT control framework (e.g., PERA) to SOC 2 Security criteria and identify gaps.
  • Institute a continuous vendor‑risk monitoring program that captures access, patching, and configuration evidence for all OT‑related third‑party services.
  • Document change‑management and incident‑response procedures that account for non‑rebootable OT assets.

Source: Help Net Security

Technical Notes – The interview cites the erosion of air‑gap isolation, the reliance on PLC, HMI and SCADA systems, and the inability to apply traditional patch‑and‑reboot cycles to critical OT equipment. No specific CVE or exploit is disclosed. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →