
Securing Critical Infrastructure
A Strategic Approach to LNG Terminal Security & Compliance
As security risks and regulatory demands for Liquefied Natural Gas (LNG) infrastructure continue to rise, ensuring the protection of LNG terminals has never been more crucial. Threats such as cyberattacks, perimeter breaches, drone surveillance, and maritime security incidents pose significant challenges.
In collaboration with Schäfer Group, INCITIAS provides a roadmap for compliance with the EU CRITIS Directive, the NIS2 cybersecurity framework, and the ISPS Code. Drawing on experience from over 60 LNG import and export terminals, INCITIAS has expanded its services to address physical and cyber security risk management, including supply chain assessments, resilience, and recovery.
Our approach applies from initial project phases through detailed design, integrating security and resilience measures into a broader risk management framework. By incorporating security considerations early, LNG operators can improve long-term operational continuity.
With a thorough understanding of relevant regulations and infrastructure security, INCITIAS offers tailored consulting services for LNG critical infrastructure protection.
The key achievement has been implementing a single database system that integrates BSI Grundschutz, API RP 780, ISPS, NIS2, ISO 27001 and resilience/recovery compliance requirements.
Integrated Threat and Vulnerability Assessment
Over the past 18 months, INCITIAS has consulted on critical infrastructure assessments for LNG facilities across Europe, developing an integrated approach to vulnerability assessments. Recently, in collaboration with Schäfer Group, INCITIAS initiated threat and vulnerability assessments for our clients align with:
All these systems—BSI, API, ISPS, and ISO 27001—share a similar approach but differ in how requirements and risks are defined. By integrating them into a single database, organizations gain full traceability of risk mitigation measures across physical, maritime, and cyber domains.
Compliance with NIS2 and CRITIS Directive
Compliance with NIS2 and CRITIS Directive
The NIS2 Directive and CER (CRITIS) Directive impose stringent requirements on critical infrastructure operators, mandating risk management, cybersecurity measures, physical security enhancements, and strategies for resilience and recovery—particularly across supply chains. INCITIAS ensures compliance by:
By leveraging its regulatory expertise, INCITIAS helps clients navigate complex security laws while strengthening operational resilience and safeguarding supply chains
Cybersecurity Resilience and Digital Threat Management
The increasing digitization of LNG facilities has exposed them to cyber threats, including ransomware attacks, SCADA system intrusions, and data breaches. INCITIAS provides through our IT partners state-of-the-art cybersecurity consulting services that include:
Enterprise-Wide Risk Management Integration
INCITIAS goes beyond traditional risk assessments by ensuring that threat and vulnerability assessments are integrated within an enterprise-wide risk management framework. This includes:
Ensuring Operational Readiness
It was found that the ISPS and critical infrastructure approvals process can become a bottleneck before terminal start-up and the early operating phase. To address this, INCITIAS implements security measures during the detailed design phase, embedding these features from the outset. INCITIAS also provides upgrades for existing LNG terminals, enhancing resilience and protection. Additionally, the company offers consulting during the initial design phase, advising on proactive strategies to integrate security best practices early. This flexible approach enables LNG operators at any stage of development to enhance security, meet regulatory requirements, and maintain long-term resilience
Industry Expertise and Proven Credentials
INCITIAS has a track record of success in delivering critical infrastructure security solutions for LNG terminals, backed by:
Tailored, Scalable Security Solutions
INCITIAS does not offer a one-size-fits-all approach. Instead, we provide customized security strategies which align with each client’s unique operational needs. Our services are scalable, ensuring both small LNG terminals and large-scale facilities receive the right level of security enhancements.
Regulatory Navigation and Compliance Assurance
Staying ahead of evolving regulatory requirements is a challenge for LNG operators. INCITIAS provides ongoing consulting to ensure clients are always one step ahead of compliance obligations, reducing the risk of regulatory penalties and security vulnerabilities.
Partnering with INCITIAS for Comprehensive LNG Security and Compliance
With increasing security threats and regulatory pressures, LNG terminal operators cannot afford to take security lightly. INCITIAS stands at the forefront of critical infrastructure protection, offering end-to-end consulting solutions which ensure compliance, resilience, and operational continuity.
By partnering with INCITIAS, LNG operators gain access to industry-leading expertise in cybersecurity, physical security, risk management, and regulatory compliance. Our comprehensive approach ensures your facility is not only protected against current and emerging threats, but alignment to a vast array of new regulatory requirements are met and embedded within the organisational fabric
Schedule a consultation today 📩 info@incitias.com to discover how we can help secure your LNG infrastructure and ensure full compliance with the latest industry regulations.
Further reading on Critical Infrastructure and INCITIAS can be found here.
LNG terminals are exposed to a range of security risks, including cyberattacks on industrial control systems (ICS), perimeter breaches, drone surveillance, maritime security threats, and supply chain vulnerabilities. Without a proactive security strategy, these risks can lead to operational disruptions, financial losses, and regulatory penalties.
INCITIAS provides comprehensive security consulting that integrates regulatory compliance, risk assessment, and resilience planning. Our approach aligns with key frameworks such as NIS2, the CRITIS Directive, the ISPS Code, and ISO 27001, ensuring LNG operators meet all security and resilience requirements efficiently.
Embedding security measures early in the project lifecycle helps prevent costly retrofits, avoid regulatory approval delays, and strengthen long-term operational resilience. INCITIAS advises clients on security best practices from concept design through operational readiness, ensuring compliance and risk mitigation from day one.
LNG operators must implement penetration testing, network segmentation, zero-trust architectures, and incident response planning to protect their industrial control systems from cyber threats. INCITIAS works with IT security partners to provide tailored cybersecurity solutions that align with industry standards.
LNG supply chains are vulnerable to disruptions caused by cyber incidents, geopolitical instability, and physical security threats. INCITIAS helps operators develop resilience strategies, conduct supply chain risk assessments, and establish recovery playbooks to maintain operational continuity during crises.
Engineering Services
INCITIAS Services and Original Products are supported by in-house team of engineers and designers:
Naval Architecture services:
Process Engineering services:
Mechanical and Marine Engineering services:
Safety and Risk Engineering services:
Structural Engineering services:
Electrical and Instrumentation Engineering services:
Subsea Engineering services:
FPSO External Riser turret mooring
Mooring Handling LIFTING BEAM GENERAL ASSEMBLY Original Equipment
Hose Reel 3D hybrid render
FPSO Bow Extension 3D modelling
FPSO Decommissioning
Our clients find our experience invaluable during FPSO decommissioning planning and execution, using the INCITIAS teams’ ability to assess the most suitable strategy, based on the project and local authority’s requirements. Our team has extensive experience in the design and installation of FPSO mooring systems, risers and umbilicals.
We can support the client decommissioning plan with the following services:
Examples of typical deliverables for FPSO Decommissioning are:
Single Point Mooring system
Turret Mooring
Independent Verification Design
Working together with INCITIAS, clients can obtain objective evidence of asset compliance with project requirements.
With our independent verification design process, INCITIAS applies an efficient risk-based assessment method to prioritise critical elements of the asset.
An INCITIAS comprehensive review can include:
We work together with our clients to ensure the appropriate level of review is carried out.
Operations & Maintenance Support
INCITIAS combines our Engineering expertise with real world Operations and Maintenance experience. We support our clients with O&M development and management activities including:
Integrated Owner’s Engineering Services
We support Owners with engineering, technical, and project management expertise across LNG, marine, and vessel conversion projects. Our clients can minimise risk and maximise opportunities earlier in project execution, with INCITIAS Owner’s engineering services.
INCITIAS can provide integrated owner’s engineering services for onshore and offshore projects from a client office, site location or remotely from our offices in Melbourne.
Typical services are:
Indicative deliverables are:
We can be as involved as you require. From specialist resources who consultant on specific aspects of your project, to the provision of a fully integrated Owners team.
At INCITIAS we develop tailor-made delivery solutions to match your project’s execution strategy and risk profile. Offering a full range of alternative delivery methods enables us to deliver the most effective project outcomes for you.
CLP Jetty Installation during the daytime
Advisory Services
INCITIAS offers integrated technical and commercial advisory services to assist clients advance their projects and provide support for their decision-making process. Clients can reduce risk and maximise opportunities by accessing our team of advisory specialists’ wealth of experience.
Typical advisory services are:
INCITIAS techno-commercial advisory services aligns commercial drivers with feasible and proven technical solutions. Our team’s experience includes facility selection, financial assessment, contracting strategies, construction management and project operations. Assisting clients meet their business objectives using our capabilities to provide insights and solutions.
Indicative deliverables are: