The recent cyber event that shut down the largest pipeline operator in the US, Colonial Pipeline, is a perfect example of how hackers can, and will continue to, target oil and gas companies.
A recent article from the New York Times states that a confidential assessment prepared by the Energy and Homeland Security Departments discovered that the country would have only been able to afford another 3 to 5 days with the Colonial Pipeline shut down before buses and other mass transit would have to limit operations because of a lack of diesel fuel. The report findings also found that chemical factories and refinery operations would have had to shut down because there would be no way to distribute what they produced.
However, it’s not just the large operators that cyber criminals are targeting; it is the small business owners as well. Cyber criminals enjoy attacking smaller companies as they have identified these businesses to be easier to penetrate as they typically do not have the proper safety measures in place and invest less in cyber security.
Did you know…
- If you hold reservoir or exploration data, you have a cyber exposure
- If you have an email address or bank account information, you have a cyber exposure
- If you rely on any 3rd parties to operate your business, you have a cyber exposure
There is no question that cyber-attacks are on the rise and there are no signs of it slowing down. According to the FBI’s 2020 Internet Crime Report, the number of social engineering attacks more than doubled since 2019, and increased more than 900% compared to 2018 levels.
We advise working with your risk management advisor to perform an assessment of your business’s potential liabilities to cyber-attacks and identify ways to mitigate your exposure.
About the Author
Share This Story
Related Blogs
New Federal Guidance Tightens Oversight of Health Plan Data Sharing
Federal regulators have issued new guidance that will affect how employers manage health plan data sharing for the rest of 2026. The update comes in response to a rise in cybersecurity incidents involving third-party administrators, payroll vendors, and benefits platforms. While the rules do not create new penalties, they clarify that employers—not vendors—are ultimately responsible for protecting employee health information.
Mental Health Parity Requirements Remain in Effect
Mental health parity continues to be an important compliance obligation for employer-sponsored group health plans. While recent federal actions have created some confusion, employers should understand that the core requirements of the Mental Health Parity and Addiction Equity Act (MHPAEA) remain in effect.
The 2026 Compliance Crunch: What Employers Must Do Before Fall
Employee benefits managers are facing one of the busiest compliance years in more than a decade. Several major federal requirements are converging at the same time, and most of them carry real penalties for employers that miss deadlines or fail to document their efforts. The result is a mid-year “compliance crunch” that is catching many organizations off guard.










