The conversation with Marathon Petroleum’s Chief Information Security Officer reveals a turning point for industrial cybersecurity as automation seeps into the very heart of refineries, pipelines, and terminal operations. Mary Rose Martinez explains that the once‑reliable practice of separating operational technology from corporate networks through air gaps is no longer viable, because modern facilities rely on interconnected sensors, controllers, and data streams to maintain efficiency and safety. This shift forces security leaders to rethink traditional defenses and adopt strategies that protect critical processes without interrupting the continuous flow of hydrocarbons. For executives tasked with safeguarding complex assets, the interview offers a concrete look at how a major energy player is adapting its security posture to meet the realities of a digitized plant floor, providing a template that other capital‑intensive industries can emulate. The discussion highlights that the threat landscape is evolving rapidly, with nation‑state actors and sophisticated criminal groups probing for weaknesses in systems that were once considered isolated. Understanding this new reality is the first step toward building resilient defenses that can keep pace with technological change while preserving operational integrity.
The myth of the air‑gapped OT environment has dissolved as digital transformation penetrates every layer of industrial control. Programmable logic controllers (PLCs), human‑machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems are now routinely connected to corporate networks for remote monitoring, predictive maintenance, and performance optimization. This connectivity expands the attack surface, exposing legacy protocols that were never designed with security in mind. Martinez notes that adversaries can exploit these connections to manipulate process parameters, trigger unsafe conditions, or exfiltrate proprietary operational data. The energy sector, with its high‑value infrastructure and potential for widespread impact, is a prime target, but similar vulnerabilities are surfacing in manufacturing plants, transportation hubs, and utilities. Organizations must therefore move beyond perimeter‑centric thinking and adopt a zero‑trust mindset that assumes breach and verifies every interaction, even those occurring inside the traditional OT boundary.
While the energy industry faces unique challenges due to the scale and criticality of its assets, the digital shift affecting OT is not isolated. Manufacturers are integrating IoT sensors into assembly lines to enable real‑time quality control, while transportation firms are deploying connected signaling and fleet management systems to improve logistics. Each of these sectors inherits the same risk profile: increased efficiency comes hand‑in‑hand with greater exposure to cyber threats. The common thread is the convergence of IT and OT networks, which blurs the lines of responsibility and necessitates a unified security approach. Leaders across industries are recognizing that lessons learned in one sector—such as segmenting critical controls, employing deep packet inspection for industrial protocols, and conducting regular red‑team exercises—can be translated to others. Cross‑industry collaboration, information sharing platforms, and joint standards development are becoming essential tools for staying ahead of adversaries who exploit similarities in OT architectures.
As automation deepens, security teams must continuously reassess the adequacy and efficacy of their protective and defensive controls. The static, set‑and‑forget mindset of the past is insufficient; instead, a dynamic cycle of monitoring, testing, and improvement is required. Martinez emphasizes that controls must be evaluated not only for their technical correctness but also for their impact on operational continuity. For example, a firewall rule that blocks legitimate traffic could cause a costly shutdown, while an overly permissive rule might allow malware to propagate. The solution lies in adopting adaptive security mechanisms that can adjust policies based on context, such as time of day, user role, or anomalous behavior detected through machine learning analytics. Regular penetration testing, tabletop incident response drills, and threat intelligence feeds help organizations validate that their defenses remain effective against evolving tactics, techniques, and procedures.
Marathon Petroleum’s commitment to safe, reliable, and environmentally sound operations provides the foundation for its cybersecurity strategy. To operationalize this commitment, the company leans on the widely accepted Purdue Enterprise Reference Architecture (PERA) model, which offers a structured view of the enterprise from the field level up to corporate governance. By mapping security controls to the appropriate layers of the PERA model—ranging from sensor/actuator levels to business planning and logistics—Marathon can apply protections where they are most needed without disrupting the deterministic timing required for process control. This layered approach enables the security team to implement network segmentation, intrusion detection, and access controls at points where they provide maximum risk reduction while preserving the real‑time performance that refineries and pipelines demand.
The true power of the PERA model lies in its ability to create a synchronizing space between security actions and regular operational rhythms. When controls are thoughtfully placed at the interfaces between information technology and operational technology layers, security activities such as patch management, vulnerability scanning, and policy updates can be aligned with maintenance windows, turnaround schedules, or routine system checks. This alignment reduces the likelihood of unexpected downtime and ensures that security enhancements are perceived as burdensome by operations teams are instead viewed as enablers of reliability. Martinez notes that this synchronization also facilitates clearer reporting structures can speak the same language, reducing friction and building trust and the Purdue model also supports risk‑based decision making, allowing the company to prioritize investments in controls that address the highest‑impact scenarios, such as a compromise of a safety‑instrumented system that could lead to an environmental release.
Supply chain risk emerges as one of the most formidable challenges in securing OT environments, precisely because organizations often have the least visibility and control over the components that come from external vendors. Martinez points out that while Marathon can dictate how its own networks are segmented and monitored, it has far less influence over the security practices of the suppliers that provide PLCs, HMIs, or the software that runs on them. This risk does not stop at the immediate vendor; it extends downstream to subcontractors, third‑party libraries, and even the manufacturers of raw materials that go into producing those components. An adversary who compromises a low‑level supplier can insert malicious firmware or hardware that remains undetected until it is activated within the target facility, potentially causing sabotage or espionage. The complexity of modern supply chains, with dozens of tiers and global sourcing, makes traditional vendor questionnaires insufficient for capturing the full picture of risk.
To mitigate these exposures, Marathon employs a multilayered approach that begins with rigorous due diligence before any new product or service is introduced. This includes evaluating the vendor’s own security certifications, conducting code reviews or firmware analysis when feasible, and requiring evidence of secure development lifecycle practices. Contractual language plays a critical role, embedding security requirements, audit rights, and incident response obligations directly into agreements. When material changes occur—such as a major software update or a shift in manufacturing location—these contracts trigger reassessment clauses that force both parties to revisit security postures. Beyond contractual controls, Marathon seeks to build strategic partnerships with key vendors, collaborating on joint threat intelligence sharing, co‑development of security features, and coordinated incident response playbooks that enable rapid restoration of operations should a breach occur.
The concept of Calm Technology serves as a guiding principle for Marathon’s OT security endeavors: systems should be as invisible as possible, supporting human operators without adding cognitive load or distraction. Martinez stresses that the people who design, secure, and maintain digital solutions must deeply understand the business processes and operational realities of the facilities they serve. When security tools are intuitive and seamlessly integrated into existing workflows, operators are more likely to trust and correctly use them, reducing the chance of workarounds that could introduce vulnerabilities. At the same time, there is a growing recognition that some degree of democratization of digital know‑how is necessary. Operators, engineers, and maintenance technicians need baseline competencies in cybersecurity hygiene—such as recognizing phishing attempts, applying strong passwords, and reporting anomalies—to act as an effective human firewall alongside technical controls.
Advances in artificial intelligence are lowering the bar for codification, enabling the rapid creation of scripts, configuration files, and even low‑level code that interfaces with OT devices. While this accelerates innovation and can help bridge skill gaps, it does not eliminate the need for a well‑trained workforce; rather, it shifts the focus of required skills. Martinez explains that Marathon is investing in diverse learning pathways that cater to different roles and interests. For example, control system engineers might receive training on secure PLC programming and network segmentation, while IT analysts could focus on OT‑specific threat hunting and SIEM tuning. By offering modular courses, hands‑on labs, and certification tracks, the company aims to raise overall digital fluency, ensuring that employees can securely leverage new AI‑driven tools without inadvertently weakening defenses.
As a designated component of the nation’s critical infrastructure, Marathon Petroleum continually adjusts its strategies and controls in response to the evolving threat landscape. This involves regular re‑evaluation of the efficacy of existing protective measures, taking into account technological advancements such as the adoption of edge computing, 5G connectivity, and cloud‑based analytics platforms. The company leverages its relationships with various government agencies—including the Department of Energy, the Cybersecurity and Infrastructure Security Agency (CISA), and sector‑specific information sharing and analysis centers (ISACs)—to gain actionable intelligence, align with regulatory expectations, and contribute to the development of industry‑wide security standards. These partnerships enable Marathon to apply threat data to prioritize defenses, allocate resources efficiently, and influence policy so that regulations are both effective and practicable for the realities of OT environments.
For organizations looking to strengthen their own OT security posture, several actionable insights emerge from Martinez’s experience. First, abandon the assumption of air‑gap protection and adopt a zero‑trust architecture that verifies every request, regardless of origin. Second, employ a recognized framework like the Purdue model to map controls to operational layers, ensuring that security measures enhance rather than hinder performance. Third, institute a rigorous supply chain security program that combines vendor assessments, contractual safeguards, and collaborative partnerships to extend visibility beyond immediate suppliers. Fourth, invest in continuous skill development that blends traditional OT expertise with modern cybersecurity competencies, using AI‑enabled tools as force multipliers rather than replacements for expertise. Finally, cultivate strong ties with government and industry groups to stay informed about emerging threats and to help shape practical, risk‑based regulations. By integrating these practices, companies can build resilient OT environments that support safe, efficient operations in an era of pervasive automation.