Physical and Cyber Security at Remote Field Sites: One Plan

Unmanned wellheads, pump stations, and substations need physical and cyber protection together. Learn how to align locks, cameras, and network controls.

3 min readBy Ironfield Cyber Team

Remote field sites, such as unmanned pump stations, compressor sites, wellheads, small substations, and metering locations, present a particular challenge. They hold equipment that controls real processes, they are far from staff, and they are often protected by little more than a fence and a padlock. Physical and cyber security are usually handled by different people, yet an attacker does not respect that boundary.

A person with physical access to a cabinet can often bypass networks and passwords entirely. A person with remote access can sometimes cause physical consequences. A unified view of both is more effective than either alone.

Think Like an Intruder

Walk through how someone might approach a site:

  • Reach the gate or fence line and observe the equipment
  • Open an unlocked or weakly locked cabinet
  • Plug a device into an exposed network port or USB port
  • Remove or tamper with a radio, antenna, or cellular modem
  • Steal equipment, such as batteries, copper, or even a router or controller with stored credentials

The motive may be theft, vandalism, or something more deliberate. Each action has a cyber angle, such as stolen devices that hold configuration files, VPN keys, or passwords.

Physical Protections That Support Cyber Security

Secure the Enclosures

Use quality locks and keep key control tight. Many sites share a single key across dozens of locations, which means one lost key exposes them all. Consider unique or restricted keys, and track who has them. Fit tamper switches on doors where practical so that opening an enclosure raises an alert.

Protect Ports and Interfaces

Disable unused network and USB ports where the equipment allows it. Use port locks or blockers on exposed jacks. Keep switches and routers inside locked cabinets rather than mounted on the outside.

Add Detection

Cameras, motion sensors, and door contacts help, but they create their own network traffic and risks. Treat cameras as networked devices: change default credentials, keep firmware current, and place them on a segmented network. Decide who receives alerts and how they respond.

Protect Communications Hardware

Antennas, radios, and modems are prime targets. Mount them where tampering is harder, and use equipment that supports strong encryption and authentication. Know what happens when a device is stolen: can the thief use its SIM, its stored keys, or its configuration to reach your network?

Cyber Protections That Assume Physical Compromise

Design as though someone will eventually get inside a cabinet.

  1. Unique credentials per site. Shared passwords across locations let one theft compromise many.
  2. Encrypted and authenticated remote links. Ensure a captured device cannot simply connect back to the network.
  3. Limited trust. Treat each remote site as semi-trusted, with firewalls limiting what it can reach back to the central network.
  4. Remote revocation. Be able to disable a stolen device's credentials, SIM, or certificate quickly.
  5. Configuration protection. Remove stored passwords and unnecessary configuration data from field devices when possible, and password protect programming interfaces.

Connect the Alerts

A door alarm that goes to one person and a network alert that goes to another can leave both unexplained. Combine them where you can:

  • A cabinet door opens at night with no scheduled maintenance
  • A device goes offline right after
  • A new device appears on the network at the same site

Together, these tell a clear story that separate alerts do not.

Coordinate Access and Maintenance

Maintain a schedule of authorized visits and vendor work. When a technician arrives, verify identity and purpose before granting access. Record entries and exits. Require that any equipment brought on site, such as laptops or USB media, is approved and scanned.

Plan for Loss

Keep an inventory of devices at each site, including serial numbers, configurations, and credentials. If something is stolen, you should know what was lost and be able to rebuild. Keep spare, pre-configured equipment for faster recovery.

Review Together

Bring operations, field technicians, security, and IT together at least annually to walk a representative site and discuss gaps. People who work at those sites often spot weaknesses an office-based team would miss.

Where We Can Help

Ironfield Cyber helps energy services firms and small operators review field sites for combined physical and cyber exposures, and then prioritize practical fixes. If you would like a second perspective on your remote locations, we can walk through your site design with your team.