Oil and Gas

Shutting down blind costs the most.

Schedule a meeting

Pipelines and refineries under TSA directives, API 1164 and NIS2

Security built for pipelines and plants

See whether an attack reached operational systems before you stop the pipeline.

Directives

DirectiveMeasureARRTECH evidence
TSA Pipeline-2021-01Report to CISA within 24 hours.A signed case timeline. →
TSA Pipeline-2021-02Continuous monitoring and detection.Correlation at the IT/OT boundary and Detection baselines. →
TSA Pipeline-2021-02Segmentation so OT runs if IT is hit.Logs from the conduit: firewalls and jump hosts. →
HSE OG86Records of periodic security log monitoring.Scheduled reports and signed logs. →
Havtil, 2025Central logging with anomaly detection.ARRTECH SIEM and Cyberdroid AI Detection. →

TSA Pipeline-2021-02

See whether an attack reached OT

TSA Security Directive Pipeline-2021-02 requires owners to separate IT from OT and monitor for attacks. ARRTECH links VPN, firewall and remote access events at the boundary, so you can see whether an attacker reached OT.

Safety first

Monitor pipelines without touching safety systems

Touching a safety system during an incident creates new risk. ARRTECH never connects to controllers or safety systems; it reads the logs your boundary systems send.

TSA Pipeline-2021-01

Report to CISA within 24 hours

TSA Security Directive Pipeline-2021-01 requires reporting cybersecurity incidents to CISA within 24 hours. Each ARRTECH SIEM case keeps the full timeline from the first alert.

Remote sites

Watch remote compressor and pump stations

Compressor and pump stations often sit on remote links. ARRTECH SIEM alerts when any station stops reporting, and the agent catches up when the link returns.

By rule

HSE OG86

Records of periodic security log monitoring. ARRTECH: Scheduled reports and signed logs.

Havtil, 2025

Central logging with anomaly detection. ARRTECH SIEM and Cyberdroid AI Detection.

Questions

Can you see the safety system?

No. ARRTECH never connects to a controller or safety system. It reads what your boundary systems and site computers log.

What about remote stations?

The agent holds logs when a link drops and sends them later, and an alert shows when a station stops reporting.

Who decides a shutdown?

The control room. ARRTECH SOAR emails a person up to five options and waits.

What stays with you?

Your TSA plans and reports, and API 1164 reporting. Cyberdroid AI Detection reports about once an hour and never blocks.

Sources

Guide

What do TSA pipeline security directives require?

Report incidents to CISA within 24 hours, segment IT from OT, and run continuous monitoring and detection.

What is API 1164?

API Standard 1164 is the pipeline industry standard for control system cybersecurity.

How do you know if an attack reached OT?

Correlate VPN, firewall and remote access logs at the IT/OT boundary.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.