OT and ICS Security in the GCC Energy Sector 2026: Threats, Vendors, and Compliance

22% of critical infrastructure firms hit an OT/ICS incident last year. For GCC energy operators in Saudi, UAE, and Qatar, this guide covers threats, NCA OTCC and SAMA compliance, and purpose-built vendors for industrial environments.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region8 min read
An engineer monitoring an industrial refinery at sunset using a digital tablet

An engineer monitoring an industrial refinery at sunset using a digital tablet

Twenty-two percent of critical infrastructure organisations suffered a security incident impacting their OT and ICS environments in the past 12 months, according to the SANS Institute's State of ICS/OT Security 2025 Survey. For GCC energy operators, a region whose economic foundation rests on refineries, pipelines, LNG terminals, and offshore platforms running continuously across Saudi Arabia, the UAE, and Qatar, that figure is not an abstract global statistic. It is a direct reflection of the risk facing the infrastructure that funds the region's national budgets.

The threat that has moved beyond access to operational impact

The defining shift in OT and ICS threats heading into 2026 is not increased attack volume. It is a change in adversary intent. Industrial cybersecurity firm Dragos's 2026 threat analysis describes adversaries who have moved beyond initial access and persistence into deliberate, active preparation for operational impact, a meaningfully more dangerous posture than the espionage-focused intrusions that characterised OT threats in previous years.

That shift was demonstrated concretely in December 2025, when a malicious actor compromised operational technology and industrial control systems across Poland's energy sector, specifically targeting renewable energy plants and a combined heat and power facility. CISA's subsequent alert confirmed the actor gained initial access through vulnerable internet-facing edge devices before deploying wiper malware that caused physical damage to remote terminal units (RTUs). This was not data theft. It was destruction of physical control hardware, executed through a vulnerability class that exists in nearly every GCC energy facility running legacy or under-segmented OT infrastructure.

The SANS 2025 survey found that unauthorised external access accounted for half of all OT and ICS incidents globally, yet only 13 percent of organisations have fully implemented advanced controls such as session recording or ICS/OT-aware access management.

The access pathway most consistently exploited is third-party and contractor connectivity. Research published by Cyolo and the Ponemon Institute found that 73 percent of industrial organisations permit third-party access to OT environments, with an average of 77 third parties per organisation granted such access. Anywhere from a third to half of all critical infrastructure security breaches can be attributed to external vendor access that was inadequately governed. For GCC energy operators managing extensive contractor ecosystems across upstream, midstream, and downstream operations, this is the single highest-probability entry point into systems that were never designed with internet connectivity in mind.

The GCC regulatory framework governing OT security

Saudi Arabia and the UAE have both built dedicated OT regulatory frameworks that energy sector operators must now navigate alongside their general cybersecurity obligations.

The NCA's Operational Technology Cybersecurity Controls (OTCC), first published in 2022 and operating as a direct extension of the Essential Cybersecurity Controls, set the minimum cybersecurity requirements for organisations protecting Industrial Control Systems from cyber threats that could result in negative operational impact. The OTCC applies to ICS residing in facilities deemed critical and owned, operated, or hosted by government organisations and private sector entities operating Critical National Infrastructure, whether located inside the Kingdom or abroad. The framework defines three OTCC control levels based on a facility-level risk assessment that considers the criticality and consequences of compromise, the negative impact on health, safety, and the environment, and the negative impact on the national economy, national security, or social stability.

A critical compliance reality for Saudi energy operators is that OTCC obligations sit alongside, not instead of, the foundational ECC-2:2024 requirements covered in our Saudi Arabia NCA Cybersecurity Framework guide. Domain 5 of the ECC specifically addresses OT security requirements, and aligning these with corporate IT governance frequently encounters resistance from operational teams who require specialised ICS security expertise that general IT compliance consultants do not possess. NCA assessors examine evidence rather than intent during audits: organisations frequently have implemented effective controls informally but lack the logs, records, approvals, and test results required to formally demonstrate compliance.

In the UAE, the IA Regulation and Critical Information Infrastructure Protection (CIIP) policy take a risk-based approach that still expects critical entities to maintain strong control over where OT data and logs reside. Qatar's data protection law and Qatar Central Bank regulations add in-country processing requirements for financial and certain personal data that influence where OT monitoring platforms can be hosted across the region's LNG infrastructure specifically.

For financial institutions and energy operators with banking relationships, the overlap between OTCC, ECC, and the SAMA Cybersecurity Framework requires integrated compliance management. The SAMA CSF is structured around five domains, Cybersecurity Leadership and Governance, Risk Management and Compliance, Operations and Technology, Third-Party Cybersecurity, and Resilience, and SAMA conducts formal examinations using the CSF as the assessment benchmark, expecting evidence of operational effectiveness rather than documented policy alone.

The market scale confirming where investment is heading

The OT and ICS security market in the GCC is growing at a pace that reflects both the scale of regional energy infrastructure and the regulatory pressure described above. Industry analysis presented at the OTSEC Summit 2026 projects the global OT security market reaching USD 38.2 billion by 2028 at a CAGR of 16.3 percent, with a related ICS security segment reaching USD 624.84 million by 2028 at a CAGR of 8.48 percent. The UAE government has been particularly active in defining standards for OT security to protect critical national infrastructure, with energy, manufacturing, and transport identified as the primary sectors driving adoption.

In the United States, the Department of Energy allocated USD 160 million to energy sector cybersecurity in 2026, a direct policy response to the documented escalation in adversary capability rather than evidence that the underlying problem has become more manageable. The introduction of the Energy Threat Analysis Center Act of 2026 in the US Congress reflects a parallel recognition that current information-sharing structures have not kept pace with the threat, a gap that GCC energy regulators are addressing through the OTCC and equivalent UAE frameworks rather than waiting for an equivalent legislative response.

The vendor landscape: purpose-built platforms over adapted IT tooling

The most consistent finding across OT security practitioners is that platforms designed for IT environments fundamentally misread industrial protocols and operational constraints. Effective OT security monitoring requires tooling built specifically for the protocols, including Modbus, DNP3, and IEC 61850, and the operational tolerances of industrial environments, where an aggressive active scan that would be routine in an IT network can destabilise a programmable logic controller and halt a production process.

Three platforms have established themselves as the purpose-built standard for OT and ICS monitoring globally and are increasingly the reference point for GCC energy sector deployments: Dragos, Claroty, and Nozomi Networks. These platforms passively monitor industrial network traffic, build behavioural baselines specific to control system communication patterns, and detect anomalies without the active probing that risks destabilising sensitive equipment. Specialist OT security practices consistently note that platform configuration and tuning matter as much as platform selection, since an OT monitoring platform deployed without proper baseline calibration for the specific facility's normal operational patterns will generate either dangerous blind spots or unmanageable false positive volumes.

Network architecture built on the IEC 62443 zone-and-conduit model remains the foundational reference standard for segmenting OT environments into defined security zones with controlled communication pathways between them, isolating the most critical control systems behind multiple layers of demilitarised zones. For GCC operators managing the IT-OT convergence challenges described above, this segmentation work, not the monitoring platform alone, is what limits the blast radius when an initial compromise inevitably occurs.

The practical roadmap for GCC energy operators

Practitioners advising GCC oil and gas operators recommend a structured approach that delivers measurable resilience within a realistic timeframe rather than attempting a comprehensive transformation simultaneously. A 60 to 90 day initial roadmap focused on asset discovery, network segmentation, and baseline monitoring deployment is consistently identified as the achievable starting point that produces demonstrable risk reduction before broader programme elements, including full OTCC compliance documentation and third-party access governance, are built out.

Practical OT risk KPIs that GCC boards and regulators are increasingly expecting include the percentage of critical OT assets actively monitored, mean time to detect and respond to OT-specific incidents, compliance scores against OTCC, IA, and CIIP requirements, and incident response drill performance. These metrics give operational leadership transparent visibility into resilience while satisfying the evidence-based audit expectations that NCA and SAMA assessors apply during formal examinations.

The strategic case for this investment extends beyond compliance. Strong OT security directly supports the safety and ESG commitments embedded in Vision 2030 and equivalent national agendas across the GCC, reducing accident risk, protecting the environment surrounding the Arabian Gulf, and building the investor confidence that regional energy assets require to attract long-term capital. For Gulf operators, OT security has moved from being an IT cost line item to a component of long-term operational excellence and the digital transformation agenda that underpins the region's economic diversification.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.