News yesterday that hackers have been wandering round the networks of major oil and gas companies for years may come as a shock in some quarters.
But industrial and national espionage is huge business and the companies involved should have taken steps to prevent such attacks and should have systems in place to alert management far quicker.
The fact that they don’t have adequate security controls, a programme of security penetration testing to measure the effectiveness of their controls and appropriate monitoring and alerting systems in place is a damning indictment of their management hierarchy.
Financial institutions implement such systems and testing as a matter of course. And while there’s no guarantee that they will stop all such attacks having a defensive mentality improves the overall level of security.
The oil and gas industry is worth astronomical sums of money. This in itself makes the companies involved attractive targets for corporate and national espionage.
But surely, with the sums involved they could afford to invest in a proper programme of security penetration testing, invest in a “defence in depth” approach to their IT infrastructure, implement high quality alerting and monitoring systems and an effective management team?
The costs of not doing so for the organisations in question may be about to be highlighted.

