Automation

Air-Gapped OT Is Dead: Marathon Petroleum's CISO on Securing Autonomous Energy Systems

Mary Rose Martinez explains how digital convergence, vendor dependencies, and state-aligned threats are reshaping industrial cybersecurity at scale.

Omega Editorial· July 27, 2026· 3 min read

The traditional security boundary that protected refineries and pipelines—physical isolation from the internet—has effectively disappeared. Mary Rose Martinez, CISO at Marathon Petroleum, says her team has had to abandon the concept of air-gapped operational technology environments as automation and digitization reach deeper into industrial control systems.

Marathon operates refineries, pipelines, and terminals across a sprawling footprint. As those facilities become more automated, programmable logic controllers, human-machine interfaces, and SCADA systems that were once physically isolated now face digital exposure. According to Martinez, this transition isn't unique to energy—manufacturing and transportation sectors are experiencing the same shift.

Why it matters

Critical infrastructure operators can no longer rely on physical separation as a primary defense. The move toward autonomous systems introduces vendor dependencies, supply chain complexity, and remote access requirements that fundamentally change the threat surface. For energy companies facing state-aligned adversaries and strict regulatory oversight, the old playbook no longer applies.

The Purdue model replaces Patch Tuesday

A catalytic cracker cannot be rebooted on a standard patching schedule. Martinez explains that Marathon uses the Purdue Enterprise Reference Architecture model to balance security with operational continuity. By implementing controls at and between the information technology and operational technology layers, her team can synchronize security actions with regular operational cadences rather than forcing disruptive emergency patches.

This architectural approach creates space to maintain Marathon's commitment to safe, reliable operations while still managing cyber risk.

Vendor dependencies extend beyond first-tier suppliers

Autonomous systems arrive bundled with vendor platforms, third-party models, and remote support tunnels. Martinez identifies the supply chain as a particular concern—not just direct vendors, but nth-party suppliers further down the chain where visibility and control are minimal.

Marathon's mitigation strategy includes due diligence assessments, contractual language requirements, and partnerships with key vendors. Those partnerships serve dual purposes: providing input on product security during development and enabling joint response when incidents occur.

Cross-skilling the workforce

As processes become self-running, skill gaps are emerging between personnel who understand industrial chemistry and those who understand code. Martinez's approach focuses on developing multiple learning pathways to increase digital fluency across the workforce, tailored to different roles and interests.

She notes that artificial intelligence is lowering barriers to codification, which may change the specific skills needed but doesn't eliminate the requirement for cross-training. The goal remains what she calls "Calm Technology"—systems that support human tasks without becoming obstacles.

State actors and regulatory pressure

Critical infrastructure operators now face pressure from multiple directions: CISA guidance, TSA directives, and state-aligned threat actors actively probing energy systems. Martinez says Marathon continually adjusts strategies and controls based on the evolving threat landscape and re-evaluates defensive measures as technology advances.

Partnerships with government agencies remain essential—both for leveraging threat intelligence to allocate resources efficiently and for providing industry input into security regulations.

These details were first reported by Help Net Security in an interview with Martinez.

#operational technology security#critical infrastructure#industrial control systems#supply chain risk#energy sector cybersecurity#automation

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Automation

Automation· 4 min read

Hotels Turn to AV Automation to Cut Costs and Boost Service

Hospitality venues deploy networked audio, cloud-managed IPTV, and building control systems to operate leaner teams without sacrificing guest experience.

Via Automation Watch · Jul 27, 2026
Automation· 2 min read

Sabanto Retrofits Old Tractors Into Autonomous Farm Equipment

The Illinois startup addresses agriculture's labor crisis by converting existing machinery into self-driving vehicles that can seed, weed, and mow without human operators.

Via Automation Watch · Jul 27, 2026
Automation· 3 min read

PentesterFlow Brings Human-Approved AI Agents to Pentesting

New open-source CLI tool automates reconnaissance through reporting while requiring analyst sign-off on every sensitive command.

Via Automation Watch · Jul 27, 2026