Zero Trust Architecture for Energy Networks

Why “Never Trust, Always Verify” Is the Security Philosophy Energy Companies Can No Longer Ignore

August was a defining month in cybersecurity and more reason than ever to focus on zero trust architecture. The world’s largest security community gathered in Las Vegas for two back-to-back events that set the tone for the rest of the year — and one unusual incident on a flight home drove home the point that the threats discussed in conference rooms follow us into everyday life. It was also a personally meaningful month for me, as I had the privilege of speaking at Build IT Live, IT By Design’s annual conference for MSP leaders, in Jersey City, New Jersey, alongside fellow MSP leader Tobias Musser, moderated by Javid Khan. More on that shortly.

But the topic I want to focus on this month is one that is shaping how we build security programs for our clients in the midstream energy space: Zero Trust Architecture — and why it is no longer just for large enterprises with dedicated security teams.

If you are running a storage terminal, managing truck transport operations, leasing and tracking railcars, or acting as a shipper on a pipeline, this is written directly for you.

The August Security Landscape: What Las Vegas Told Us

Black Hat USA 2026

Held at the Mandalay Bay Convention Center, Black Hat USA drew more than 23,000 security professionals for high-level briefings on frontier AI threats, zero-day vulnerabilities, and enterprise defense strategy. The message delivered from the main stage was consistent and clear: traditional perimeter-based security is failing. Organizations that rely on “inside the firewall equals trusted” are the ones showing up in incident response reports. Identity-first, continuous-verification architectures are not the future — they are the present requirement.

DEF CON 34

Just steps away at the Las Vegas Convention Center West Hall, DEF CON 34 brought together tens of thousands of hackers, researchers, and government agencies for hands-on villages, competitions, and adversarial research presentations. What stood out in conversations relevant to our clients: the targeting of logistics, dispatch, and fleet management systems. These are exactly the kinds of operational platforms midstream energy companies run every day — and attackers are mapping them carefully.

When the Threat Got on the Plane

August also produced one of the year’s most memorable security headlines — and it did not happen at a conference. A rogue Wi-Fi network incident occurred aboard a flight returning DEF CON attendees home to Atlanta, prompting a federal investigation. The irony was not lost on anyone: a plane full of security professionals was targeted with a classic evil twin access point. The lesson for midstream energy operators is straightforward. If threat actors will go to that length on a commercial flight, they will absolutely target a field driver connecting to dispatch systems from a truck stop, a terminal operator accessing inventory management from a mobile device, or a remote employee checking in on railcar tracking from a hotel Wi-Fi. The attack surface is wherever your people and devices are — and that is everywhere.

The Energy Reality: Your Attack Surface Is on the Move

Here is what makes energy companies a uniquely interesting cybersecurity challenge — and, frankly, why cookie-cutter security advice often misses the mark for your business.

Your operations are distributed and mobile by definition. A terminal operator with 80 to 200 employees may have:

  • Drivers operating transport trucks, connecting to dispatch and compliance systems from tablets or phones while on the road
  • Railcar coordinators tracking car movements, loading schedules, and lease compliance across multiple rail yards and counterparties
  • Terminal staff managing inventory, blending, and custody transfer systems at fixed storage sites
  • A small back-office team handling finance, compliance, and vendor management — often remotely
  • Upstream monitoring responsibilities that require read or write access to third-party systems, SCADA dashboards, or field sensor data

Now think about the IT footprint that supports all of that. You probably have a mix of cloud applications, a small on-premise server environment or two, mobile devices that leave the building every day, remote access for employees who are rarely in one place, and third-party vendor connections for railcar lessors, pipeline operators, terminal automation vendors, and compliance reporting platforms. This makes the case even more important for a zero trust architecture.

That is a distributed, mobile, heavily connected environment. And in most companies your size, it is being managed by a lean IT team — or outsourced entirely to an MSP like Intelos.

The traditional security model — put a firewall at the edge, put everyone on VPN, trust what is inside — does not fit this reality. Zero Trust Architecture does.

What Zero Trust Architecture Actually Means

Zero Trust is not a product. It is not a vendor’s marketing term. It is a security architecture philosophy built on one foundational principle:

Trust no user, no device, and no connection by default — regardless of whether they are inside or outside your network. Verify everything, every time.

In a traditional model, once your driver’s tablet or your terminal manager’s laptop connects to the VPN, it is effectively trusted. That trust is the vulnerability. A stolen password, a compromised device, or a phishing email that tricks one employee can hand an attacker access to everything that trusted device or credential can reach.

Zero Trust replaces that implicit trust with three disciplined practices:

Verify Explicitly

Every access request — whether it is a driver pulling up a dispatch app, a terminal manager logging into an inventory system, or a vendor connecting to a compliance portal — must be verified using multiple data points: who is asking, what device they are on, where they are, what time it is, and whether that behavior matches their normal pattern. Multi-factor authentication (MFA) is the baseline, not the finish line.

Use Least Privilege Access

Your truck driver does not need access to your financial systems. Your terminal billing coordinator does not need access to your railcar telematics platform. Least privilege means every user and every system gets access only to what their role specifically requires — nothing more. When a credential is compromised, the blast radius is contained to what that credential could reach, not the entire business.

Assume Breach

This is the mindset shift that separates mature security programs from reactive ones. Design your systems as if an attacker has already gotten in. Segment your environment so a compromised device cannot roam freely. Log and monitor behavior continuously. Build detection and response capabilities — or work with an MSP that provides them — so that when something goes wrong, you catch it fast and contain the damage before it becomes a catastrophe.

Why A Zero Trust Architecture Matters for Companies Your Size

Here is something I hear often from owners and operations leaders at energy companies with less than 300 employees: “Zero Trust Architecture sounds like something for big companies with big security budgets.”

I understand why it feels that way. The terminology comes from enterprise security conversations, and the vendor marketing is often aimed at Fortune 500 procurement teams. But the architecture itself is entirely practical and cost-appropriate for companies your size — and in many ways, smaller organizations benefit more quickly because they are not unwinding decades of legacy infrastructure.

The real question is not whether a Zero Trust Architecture is affordable. It is whether you can afford the alternative. A ransomware attack that locks your dispatch system during a peak delivery week, or a data breach that exposes your customer custody transfer records, or a compromised vendor connection that gives an attacker a foothold in your terminal automation system — those events carry costs measured in business interruption, regulatory exposure, customer relationship damage, and recovery time that no small or mid-size company budgets for.

The energy companies we work with are not buying Zero Trust because a compliance mandate requires it. They are buying it because their operations depend on technology that is distributed, connected, and increasingly targeted — and their leadership teams have decided that security is a business continuity investment, not an IT line item.

SASE: Zero Trust Architecture Across a Distributed Operation

One of the most important enabling technologies for a Zero Trust Architecture in a distributed environment is something most people outside of networking circles have never heard of: SASE — Secure Access Service Edge (pronounced “sassy”).

SASE is worth understanding because it was designed almost precisely for the operating model that energy companies live in every day.

Traditional network security assumes that users sit in offices connected to a corporate network, and that traffic flows from those offices to a central data center. Security is applied at that data center — and everything coming in through the VPN is trusted. That model does not describe your business. Your users are at terminals, in trucks, at rail yards, offshore platforms, working remotely, and connecting to cloud applications that never touch your data center at all.

SASE solves this by moving security enforcement to the cloud and applying it as close as possible to wherever your users and devices actually are.

Here is what SASE brings together in a single platform:

  • Zero Trust Network Access (ZTNA): Replaces traditional VPN with identity-verified, application-specific access. Your driver’s tablet connects to the dispatch application it is authorized to use — not to the entire corporate network. Your terminal manager accesses the inventory system — not the finance server. Access is granted per application, per user, per session.
  • Secure Web Gateway (SWG): Filters and inspects all internet traffic from every user, regardless of location — catching malware, phishing sites, and malicious downloads before they reach the device.
  • Cloud Access Security Broker (CASB): Provides visibility and control over cloud application usage. When employees use personal cloud storage or unsanctioned apps to move work data, CASB catches it.
  • Firewall as a Service (FWaaS): Applies consistent firewall policy across all locations and users without requiring hardware at every terminal or remote site.
  • SD-WAN: Intelligent, resilient connectivity across all sites — terminal locations, back-office, and remote connections — with built-in redundancy and performance optimization.

What this looks like practically for an energy company:

Your driver connects to a dispatch app from a tablet at a truck stop. The SASE platform verifies their identity with MFA, checks that the device is healthy and compliant, confirms the connection request matches expected behavior, and grants access only to the dispatch application — not to the company network broadly. If the tablet has been compromised, access is denied before any damage occurs.

Your terminal manager connects remotely to an inventory management system. Same process — continuous verification, application-specific access, behavioral monitoring.

A vendor technician needs temporary access to an automation system for a maintenance window. Access is provisioned for the specific system, for the specific time window, with full logging — and automatically revoked when the window closes.

This is Zero Trust made operational for a distributed energy business. And it is managed centrally, meaning your lean IT team — or your MSP — administers consistent policy from a single platform rather than managing hardware at every location and device.

At Intelos, we have deployed SASE-based Zero Trust architectures for energy clients as a core component of their security programs. The results are consistent: a dramatically reduced attack surface, improved visibility across a distributed workforce, and a security posture that actually fits how the business operates — rather than fighting it.

From the Stage at Build IT Live: Lessons That Apply to Your Business

In August, I joined Tobias Musser on stage at Build IT Live, IT By Design’s annual conference for MSP professionals, in Jersey City. The session — “Building a Security Practice from Scratch: Where MSPs Actually Start”, moderated by Javid Khan — gave me an opportunity to talk publicly about how serving energy and manufacturing clients has shaped our approach at Intelos.

Session link: Building a Security Practice from Scratch — Build IT Live

A few of the conversations from that session translate directly to what energy leaders should be thinking about:

“How has your customer base shaped your security practice?”

Serving energy and manufacturing clients means serving businesses where operational continuity is not a preference — it is the business. A terminal that cannot process custody transfers, a dispatch system that goes down during a busy fuel delivery week, or a railcar tracking platform that loses data integrity — these are not inconveniences. They are operational crises with financial and customer relationship consequences. Every security decision we make at Intelos is filtered through that lens: does this protect the systems that keep your operation running?

“Which framework should you build around?”

For energy companies, we typically anchor on NIST CSF as a flexible, risk-based baseline that scales well for organizations under 250 employees. Depending on your customer contracts, pipeline shipper agreements, or insurance requirements, you may also have obligations that align with specific control frameworks. The framework gives you the map. Zero Trust architecture gives you the environment that satisfies it.

“What would you tell someone to do in the next 90 days?”

My answer: start with identity. Know exactly who has access to what systems. Enable MFA on every application. Remove credentials that belong to former employees or vendors with inactive relationships. Audit privileged accounts. This single discipline — getting identity right — eliminates more attack surface than almost any tool you could deploy, and it is the first pillar of every Zero Trust journey. It is also affordable and actionable regardless of the size of your IT team.

A Practical Starting Point for Zero Trust Architecture for Energy Companies

Zero Trust is a maturity journey, not a one-time project. Here is a realistic, sequenced starting point for an energy company with 50 to 200 employees:

Start with Identity and MFA Implement multi-factor authentication on every system: email, remote access, your ERP, your dispatch platform, your custody transfer system. Enable single sign-on (SSO) where possible to reduce password sprawl. Audit every active account and remove those that should not exist.

Establish Device Trust Every device that accesses company systems — laptops, tablets, phones, in-cab units — should be inventoried, enrolled in device management, and held to a minimum health standard. Unknown or unmanaged devices are denied access by policy.

Apply Least Privilege Map your roles to your systems. Drivers get dispatch and compliance access. Terminal staff get inventory and transfer access. Finance gets billing and AP access. No one gets access they do not need, and access is reviewed quarterly.

Deploy SASE for Edge Security Replace legacy VPN with a SASE platform that enforces Zero Trust Network Access for your distributed workforce — field drivers, remote staff, vendor connections, and terminal locations. This is where the architecture comes together across your entire operation.

Monitor Continuously Logging and monitoring should be operating at all times. Work with an MSP that provides managed detection and response capabilities — so that when anomalous behavior occurs in your environment, someone is watching and responds before it escalates.

Coming Up: Ransomware Defense in September

In September, we continue this series with Ransomware Defense Strategies for Energy Companies — examining how ransomware actors specifically target energy operations, what a layered defense looks like for companies your size, and how the Zero Trust architecture we discussed this month becomes the foundation for effective ransomware resilience. If your business depends on dispatch systems, terminal automation, or railcar tracking platforms staying online, you will not want to miss it.

And in October, as part of Cybersecurity Awareness Month, we will bring the series full circle with a practical look at what security-first really means for energy companies — along with some exciting news from Intelos about our own security credentials that we think distinguishes our practice in a meaningful way.

Zero Trust Architecture – The Bottom Line

August reminded the security world that threats are everywhere — from the briefing rooms at Black Hat to DEF CON’s hacking villages to a rogue access point on a commercial flight. For energy companies, the message is the same one we hear when we are on the road, at the terminal, or managing operations from a remote connection: the perimeter is gone. Your users, your data, and your systems are distributed across trucks, rail yards, terminals, and cloud platforms.

Zero Trust is the architecture that matches that reality. SASE is the technology that makes it operational across a distributed, mobile workforce. And getting started does not require a large IT team or an enterprise budget — it requires a disciplined approach, the right partner, and a commitment to starting with the fundamentals.

Ready to start the conversation? Visit intelos.com or reach out to our team for a Zero Trust readiness assessment designed for midstream energy operations.


James Wroten is the CEO of Intelos, a managed service provider specializing in cybersecurity and IT solutions for midstream and upstream energy companies. This article is part of Intelos’s ongoing cybersecurity series for 2026.

Enhance Your Business Today

Discover how our tailored IT solutions can propel your business forward. Reach out to us for expert guidance and support.