IADC Cybersecurity Committee releases revised guide covering full upstream energy sector
Document now includes questionnaire to give industry, regulators a common methodology for identifying and addressing cyber risk

By Stephen Whitfield, Senior Editor
One of the biggest obstacles to getting cybersecurity taken seriously across the upstream industry is that it’s not always well understood. Beyond a vague sense of “danger,” there’s little shared understanding – among regulators or, in many cases, the companies they oversee – of what actually addressing those risks requires.
“Everybody has this kind of ethereal understanding of cyber risk,” said Jim Rocco, IADC’s VP of Government and Industry Affairs for Global Offshore. “But the industry is thinking about it and working on something that actually satisfies the effort in addressing the risk.”
An effort under way within the IADC Cybersecurity Committee is aimed not at telling anyone what cybersecurity should look like. It’s actually the opposite: a guideline that deliberately stops short of prescribing technical solutions and instead standardizes the process an organization uses to think about the problem. The Cybersecurity Guidelines for Drilling Assets, first published in 2018, has just been revised and retitled to cover the broader upstream energy sector.
The new Cybersecurity Guide for the Upstream Energy Sector, launched in April, is built around a questionnaire that walks an organization through three steps: identifying its cyber risks, prioritizing them and then exercising due diligence in accounting for them.
The guide references existing global standards – ISA, ISO and CISA, including other resource documents among them – but it doesn’t tell an organization which specific controls to implement or how. Each organization’s risk, and the plan that results from working through it, is expected to look different – the questionnaire only provides for a common methodology that everyone can exercise to arrive at their own answer.
“It’s not expected that any two organizations would be identical by any means,” Mr Rocco said. “They may be similar if they’re a similar kind of organization, but the guide is silent on exactly how you do that. The guide is only intended to provide a process. If we have enough of an uptake in the use of the guide, then it becomes widely recognized as a consistent means by which the upstream industry can effectively mitigate the cybersecurity challenge. That’s our end goal.”
That distinction – a shared process rather than a shared solution – is what Mr Rocco says makes the guide something the entire industry, not just drilling contractors, can adopt as common ground.
The questionnaire didn’t start as tight as it ended up. Early drafts encompassed in excess of 300 questions toward identifying, prioritizing and appropriately accounting for risk. This questionnaire content, generated by committee members, was intent on targeting enterprise/organizational areas of concern that represented a broad and inclusive assessment of cyber risk considerations.
Subsequently, the group proceeded to categorize and consolidate this initial list of questions into a user-friendly, 67-question tool that addresses risks categories such as workforce instruction, enterprise processes, management of change and sustained program integrity. The categories were carried over from existing industry frameworks rather than invented from scratch.
The questionnaire isn’t built to be answered in full by every user. For example, a large operator and a small contractor will find different sets of questions relevant to their own environment, and that’s by design, Mr Rocco said.
“For a lot of these questions, an organization might answer N/A because that question simply doesn’t apply to them, and that’s okay. We want this to be something that organizations of different sizes – from big to medium to small – can all use.”
As in the original 2018 document, the updated guideline continues to reference the same set of external standards. What’s different in this revision is structural rather than technical – the first version offered a summary of concerns and relevant references, but there wasn’t the focus on an intentional path for walking through them.
The questionnaire is what turns the document from a reference list into something closer to a guided exercise, drawing a user through their own organization’s risk assessment step by step.
“We don’t want to put a document out there just to put a document out there and say we addressed it,” Mr Rocco said. The goal was practical usability, he added, something a reader could actually pick up and act on, not just cite.
The committee’s ultimate goal for the guideline is to get it recognized globally as the standard starting point for assessing cyber risk in the upstream sector, on both the industry and regulator sides. IADC is in conversations with several industry groups and authority bodies to encourage a deliberate uptake of this guide.
The pitch to regulators is not that they should mandate specific technical requirements. It’s that the guideline gives them a consistent way to verify that operators and contractors are meaningfully engaged with cyber risk at all, the same way in which safety cases or standardized safety and environmental management systems (SEMS) function for physical safety.
“What we’re telling the industry is, you guys have a great opportunity to share with regulators what you think, the things you know should be appropriately addressed, and you can recommend to the regulator that they accept this approach in a substantial way,” Mr Rocco said.
He added that the value in shared adoption is not just about individual organizations getting better at managing their own risk. It’s about what happens when two organizations with different cybersecurity plans need to work together on the same project. A contractor and an operator who can each confirm that they exercised the IADC guideline know they arrived at their respective plans through the same process, even if the plans themselves look nothing alike – a shared starting point for figuring out how their systems need to interconnect.
Asked what stands in the way of widespread adoption, Mr Rocco pointed back to awareness: Regulators understandably lack a nuanced conceptual proficiency for what cyber risk actually involves, let alone the technical fluency to evaluate whether a company’s approach to it is adequate. IADC’s position is not to fill that gap by telling regulators what a compliant cybersecurity program looks like. It’s to get the industry itself to consistently demonstrate – through a shared process, not a shared checklist – that the effort is genuinely being made. DC
Click here to access the IADC Cybersecurity Guide for the Upstream Energy Sector.



