Skip to main content
search

Headquarters
Houston, TX, USA

Industry
Oil & Gas

Overview

Mark Huse, CIO of Kinder Morgan, discusses the cybersecurity challenges facing energy infrastructure organizations and how Kinder Morgan is building a consistent, identity-based security strategy across its IT and operational technology environments.

The interview covers the difficulty of protecting decades-old industrial systems that cannot be easily patched or replaced, the importance of applying common multifactor authentication and Zero Trust controls across IT and OT, and the role regulatory requirements play in shaping security investments. Huse also explains how Kinder Morgan replaced VPN-based access to its OT environment with the Xage Fabric and is expanding the same approach into IT through Xage Privileged Access Management.

Key Takeaways

Legacy infrastructure requires a nondisruptive security approach.
Many industrial assets were designed decades ago without modern security capabilities. Because replacing thousands of PLCs and other operational systems would be costly and disruptive, organizations need security controls that can protect existing infrastructure without requiring extensive downtime.

IT and OT should follow a consistent identity-based strategy.
Kinder Morgan applies a common MFA and Zero Trust approach across both environments, granting users only the access they need, when they need it, based on their identity and role.

Read Case Study: Kinder Morgan Transforms Data Center Access Security and Control with Xage → 

Xage enabled Kinder Morgan to replace VPN access to OT systems.
Kinder Morgan uses the Xage Fabric to provide secure access to its OT environment and is extending the platform into IT through Xage PAM. This supports greater segmentation, more precise access control, and a common approach across the organization.

Read Case Study: Kinder Morgan Selects Xage to Cyber-Harden Critical Infrastructure → 

Platform consistency simplifies compliance and administration.
Using similar technologies and policies across IT and OT makes it easier to demonstrate compliance, complete regulatory audits, administer controls, and reduce the likelihood of configuration mistakes.

Cyber resilience depends on strong fundamentals and recovery readiness.
Huse advises other CIOs to focus on cyber hygiene, execute the fundamentals well, and regularly practice recovery procedures. Organizations should assume an incident may eventually occur and prepare to restore operations as quickly as possible.

Read the Transcript

Energy infrastructure companies operate some of the most critical and distributed environments. From a CIO perspective, what makes cybersecurity especially challenging in pipeline, terminal, and industrial operations?

The thing in our industry that most folks deal with is really old infrastructure. A lot of the assets we have, some of them were built in the ’50s. Some of the technology that’s out there is very old, and it’s designed and expected to last 20, 30, 40 years. And so if you can imagine, rewind the clock 30 years and think about security, it was almost nonexistent. 

Trying to secure those assets is difficult. You can’t just rip and replace. Normally, you don’t have the downtime to do that kind of work, and so that makes it a more challenging environment for us. You can’t just say, “I need to go upgrade 5,000 PLCs.” One, that would be incredibly expensive, and the other is there’s no way you’re going to get the time to pull all those out and have downtime on those assets. So, availability of doing the maintenance and things is a critical factor, and then also just the fact that they’re old and they don’t have security built into them. 

OT and IT environments become more connected. How should CIOs think about building a consistent access control strategy across both domains without disrupting critical operations? 

One of the things we’ve done is we’ve deployed a common MFA strategy across both IT and OT environments. We have layer upon layer of MFA that we’ve implemented, and we use the same strategy and design, and we’re able to do that with the tool sets that we have. Some of those are from Xage in terms of Zero Trust. 

We’ve used the Xage Fabric to replace our VPN solution that we use to get into our OT environments. There’s other products we use as well to try and protect our endpoints, our PLCs, and other things. All those use kind of a common MFA strategy and a Zero Trust strategy as well, where we only give you the access that you need when you need it. And it’s dependent upon who you are and how we have you categorized. 

We use the same approach on our IT side, not quite as segmented as the OT side, but we’re headed in the same path on the IT side to be very segmented and manage our identity the same way on that side as well. And we’re using Xage PAM for that.

Regulatory requirements continue to shape cybersecurity programs and critical infrastructure. How do mandates such as TSA security directives influence decisions around security controls that you’re deploying and implementing across IT and OT?

The mandates that we get are from regulatory bodies for us. So TSA is our regulatory body as it relates to our pipelines. And so the security directives that they issued back in, I believe it was in 2021 after the Colonial incident, were initially very prescriptive, and then we worked with them to get them, I would say, more company-driven with the same premise of the intent: What was the intent of what they were trying to accomplish? 

And so it does put more burden on us, we have to have a more secure environment. I would tell you that I believe it’s made us more secure. We’ve had to think about things that we traditionally may not have thought about in terms of securing the endpoints on the OT side. Certainly, consistency across both IT and OT and the technologies and solutions that we use is important because it makes it easier to prove to our regulators that we’re doing all the right things across all the different parts of our infrastructure on the IT and OT side. 

And every year we have to attest to that. They come in, they do a desk audit of everything that we’re working on, and it makes it a much easier process for us to have been using the same technologies, the same approach, in general, across those environments. And it just makes for an easier process for us. It works really well. 

I think we’ve deployed similar technologies as the Xage folks know, where we’ve tried to move things out of OT. We started in OT and moved them into IT because we like the solution stack. And also, if we get to a common platform, that makes it just easier for us to administer, make less mistakes, and easier for us to comply from a regulatory perspective.

What advice would you give to other CIOs in energy infrastructure who are trying to modernize cybersecurity given the current geopolitical tensions and also the rapid advancements we’re seeing in AI models?

I would tell folks, just make sure you do the basics well. Continue to have really good cyber hygiene, focus a lot on the basic blocking and tackling. Make sure that’s sound and you’re comfortable that that’s working as efficiently and as quickly as possible. 

The other thing is work on your recovery. It’s not probably a question of if, it’s going to be a question of when people get hit, and the best thing you can do is make sure you can get up off your back as fast as possible to keep the business up and running and the cash registers going, because that’s what the companies are here for. Doing that and practicing that on a very regular basis to make sure you have muscle memory around that is really, really important.