Securing Critical Infrastructure

Holger Kelle

A Strategic Approach to LNG Terminal Security & Compliance

As security risks and regulatory demands for Liquefied Natural Gas (LNG) infrastructure continue to rise, ensuring the protection of LNG terminals has never been more crucial. Threats such as cyberattacks, perimeter breaches, drone surveillance, and maritime security incidents pose significant challenges.

In collaboration with Schäfer Group, INCITIAS provides a roadmap for compliance with the EU CRITIS Directive, the NIS2 cybersecurity framework, and the ISPS Code. Drawing on experience from over 60 LNG import and export terminals, INCITIAS has expanded its services to address physical and cyber security risk management, including supply chain assessments, resilience, and recovery.

Our approach applies from initial project phases through detailed design, integrating security and resilience measures into a broader risk management framework. By incorporating security considerations early, LNG operators can improve long-term operational continuity.

With a thorough understanding of relevant regulations and infrastructure security, INCITIAS offers tailored consulting services for LNG critical infrastructure protection.

The key achievement has been implementing a single database system that integrates BSI Grundschutz, API RP 780, ISPS, NIS2, ISO 27001 and resilience/recovery compliance requirements.

INCITIAS’ Comprehensive Approach to Critical Infrastructure Security

Integrated Threat and Vulnerability Assessment

Over the past 18 months, INCITIAS has consulted on critical infrastructure assessments for LNG facilities across Europe, developing an integrated approach to vulnerability assessments. Recently, in collaboration with Schäfer Group, INCITIAS initiated threat and vulnerability assessments for our clients align with:

  • API RP 780 – Security risk assessment in critical energy infrastructure
  • ISPS Code – Security measures for LNG carriers and marine infrastructure
  • BSI Grundschutz – Cybersecurity framework for industrial networks
  • ISO 27001 – Standard for information security management systems (ISMS)

All these systems—BSI, API, ISPS, and ISO 27001—share a similar approach but differ in how requirements and risks are defined. By integrating them into a single database, organizations gain full traceability of risk mitigation measures across physical, maritime, and cyber domains.

Compliance with NIS2 and CRITIS Directive

Compliance with NIS2 and CRITIS Directive
The NIS2 Directive and CER (CRITIS) Directive impose stringent requirements on critical infrastructure operators, mandating risk management, cybersecurity measures, physical security enhancements, and strategies for resilience and recovery—particularly across supply chains. INCITIAS ensures compliance by:

  • Conducting cyber risk assessments aligned with BSI Grundschutz and ISO 27001
  • Implementing enterprise-wide risk management strategies, including resilience and recovery planning
  • Advising on design and engineering solutions that address both physical and cyber threats
  • Ensuring alignment with European legislative frameworks for infrastructure resilience

By leveraging its regulatory expertise, INCITIAS helps clients navigate complex security laws while strengthening operational resilience and safeguarding supply chains

Cybersecurity Resilience and Digital Threat Management

The increasing digitization of LNG facilities has exposed them to cyber threats, including ransomware attacks, SCADA system intrusions, and data breaches. INCITIAS provides through our IT partners state-of-the-art cybersecurity consulting services that include:

  • Penetration testing and incident response planning.
  • Network segmentation and zero-trust security architectures for LNG industrial control systems (ICS).
  • Cyber risk mitigation strategies tailored to LNG operators.

Enterprise-Wide Risk Management Integration

INCITIAS goes beyond traditional risk assessments by ensuring that threat and vulnerability assessments are integrated within an enterprise-wide risk management framework. This includes:

  • Supply chain resilience planning – ensuring that LNG supply routes remain operational in times of crisis.
  • Incident response and recovery planning – establishing playbooks for rapid response to cyber and physical threats.
  • Operational continuity strategies – enabling LNG operators to withstand and recover from potential disruptions.
  • A deep understanding of technical risk and technologies used on site, through Operational Readiness and facility specific technical safety assessments such as  HAZOPs, HAZIDS and QRAs

Ensuring Operational Readiness

It was found that the ISPS and critical infrastructure approvals process can become a bottleneck before terminal start-up and the early operating phase. To address this, INCITIAS implements security measures during the detailed design phase, embedding these features from the outset. INCITIAS also provides upgrades for existing LNG terminals, enhancing resilience and protection. Additionally, the company offers consulting during the initial design phase, advising on proactive strategies to integrate security best practices early. This flexible approach enables LNG operators at any stage of development to enhance security, meet regulatory requirements, and maintain long-term resilience

Why Choose INCITIAS?

Industry Expertise and Proven Credentials

INCITIAS has a track record of success in delivering critical infrastructure security solutions for LNG terminals, backed by:

  • Expert consultants with decades of experience in LNG the LNG industry,
  • Proven methodologies based on API RP 780, BSI Grundschutz, ISO 27001, NIS2, ISPS, and CRITIS Directive.
  • Strategic partnerships with IT security firms, enabling access to cutting-edge security solutions.

Tailored, Scalable Security Solutions

INCITIAS does not offer a one-size-fits-all approach. Instead, we provide customized security strategies which align with each client’s unique operational needs. Our services are scalable, ensuring both small LNG terminals and large-scale facilities receive the right level of security enhancements.

Regulatory Navigation and Compliance Assurance

Staying ahead of evolving regulatory requirements is a challenge for LNG operators. INCITIAS provides ongoing consulting to ensure clients are always one step ahead of compliance obligations, reducing the risk of regulatory penalties and security vulnerabilities.

Partnering with INCITIAS for Comprehensive LNG Security and Compliance

With increasing security threats and regulatory pressures, LNG terminal operators cannot afford to take security lightly. INCITIAS stands at the forefront of critical infrastructure protection, offering end-to-end consulting solutions which ensure compliance, resilience, and operational continuity.

By partnering with INCITIAS, LNG operators gain access to industry-leading expertise in cybersecurity, physical security, risk management, and regulatory compliance. Our comprehensive approach ensures your facility is not only protected against current and emerging threats, but alignment to a vast array of new regulatory requirements are met and embedded within the organisational fabric

Schedule a consultation today 📩 info@incitias.com to discover how we can help secure your LNG infrastructure and ensure full compliance with the latest industry regulations.

 

Further reading on Critical Infrastructure and INCITIAS can be found here

Get in touch with
Subject matter experts

Holger Kelle Director

INCITIAS - Your Trusted Partner in Protecting Critical Infrastructure!

With increasing security threats and regulatory pressures, LNG operators need robust security measures.

FAQ's

What are the biggest security threats facing LNG terminals today?

LNG terminals are exposed to a range of security risks, including cyberattacks on industrial control systems (ICS), perimeter breaches, drone surveillance, maritime security threats, and supply chain vulnerabilities. Without a proactive security strategy, these risks can lead to operational disruptions, financial losses, and regulatory penalties.

How does INCITIAS help LNG operators comply with NIS2, CRITIS, and ISPS regulations?

INCITIAS provides comprehensive security consulting that integrates regulatory compliance, risk assessment, and resilience planning. Our approach aligns with key frameworks such as NIS2, the CRITIS Directive, the ISPS Code, and ISO 27001, ensuring LNG operators meet all security and resilience requirements efficiently.

What are the benefits of integrating security into the early design phase of an LNG terminal?

Embedding security measures early in the project lifecycle helps prevent costly retrofits, avoid regulatory approval delays, and strengthen long-term operational resilience. INCITIAS advises clients on security best practices from concept design through operational readiness, ensuring compliance and risk mitigation from day one.

What cybersecurity measures should LNG operators prioritize?

LNG operators must implement penetration testing, network segmentation, zero-trust architectures, and incident response planning to protect their industrial control systems from cyber threats. INCITIAS works with IT security partners to provide tailored cybersecurity solutions that align with industry standards.

How can LNG operators enhance supply chain security and resilience?

LNG supply chains are vulnerable to disruptions caused by cyber incidents, geopolitical instability, and physical security threats. INCITIAS helps operators develop resilience strategies, conduct supply chain risk assessments, and establish recovery playbooks to maintain operational continuity during crises.

References

  1. European Commission (2022)NIS2 Directive: Strengthening the cybersecurity of networks and information systems in the EU. Retrieved from: https://ec.europa.eu/digital-strategy/policy/nis2-directive_en
  2. European Commission (2022)Directive on the Resilience of Critical Entities (CER Directive) – formerly known as the CRITIS Directive. Retrieved from: https://ec.europa.eu/commission/presscorner/detail/en/IP_20_2049
  3. BSI (2023)Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik). Retrieved from: https://www.bsi.bund.de/EN/Home/home_node.html
  4. API (2020)Recommended Practice 780: Security Risk Assessment Methodology. Retrieved from: https://www.api.org/
  5. IMO (2023)International Ship and Port Facility Security (ISPS) Code. Retrieved from: https://www.imo.org/en/OurWork/Security/Pages/ISPSCode.aspx

Engineering Services

INCITIAS Services and Original Products are supported by in-house team of engineers and designers:

  • Naval architects
  • Process engineers
  • Mechanical and Marine engineers
  • Safety and risk engineers
  • Structural and civil engineers
  • Electrical and instrumentation engineers
  • Subsea engineers
  • Construction supervisors
 

Naval Architecture services:

  • Hydrodynamic analysis
  • Hydrostatic analysis
  • Offshore and nearshore mooring systems design 
  • Design in accordance with IMO and class requirements

Process Engineering services:

  • Cryogenic system engineering for LNG, ethane, LPG, and hydrogen
  • Chemical engineering for olefins, biodiesel, and chemical bulk handling
  • Natural gas networks
  • Fuel systems
  • Jetty topsides for conventional oil and LNG
  • FPSO topsides design
  • Process system commissioning
 

Mechanical and Marine Engineering services:

  • Original equipment and machinery design
  • Hydraulic and pneumatic system design
  • Cryogenic pressure vessel design
  • Piping systems design
  • Package engineering
  • Marine systems integrations
  • Cargo and ballast systems, HVAC, and cooling propulsion solutions
 

Safety and Risk Engineering services:

  • Explosion studies
  • Gas dispersion studies
  • Cooling water dispersion studies
  • QRA, HAZOP and HAZID coordination
 

Structural Engineering services:

  • Marine and offshore structure design
  • Structure life extension
  • Fatigue studies
  • Asset integrity
 

Electrical and Instrumentation Engineering services:

  • Load lists
  • Shore-to-ship power connections
  • Power system design
  • LV and MV engineering
  • Subsea electrical systems engineering
  • Process and machinery instrumentation design
 

Subsea Engineering services:

  • ROV operations engineering
  • Subsea intervention engineering
  • Subsea pipeline system design
  • Flexible flowline and umbilical design

FPSO External Riser turret mooring

Mooring Handling LIFTING BEAM GENERAL ASSEMBLY Original Equipment

Hose Reel 3D hybrid render

FPSO Bow Extension 3D modelling

FPSO Decommissioning

Our clients find our experience invaluable during FPSO decommissioning planning and execution, using the INCITIAS teams’ ability to assess the most suitable strategy, based on the project and local authority’s requirements. Our team has extensive experience in the design and installation of FPSO mooring systems, risers and umbilicals.

 

We can support the client decommissioning plan with the following services:

 

  • Decommissioning option selection study and recommendation
  • Cost estimate and assessment of cost escalation
  • Contracting strategy options selection and recommendation
  • Integrated owner engineering team
  • Original equipment to unlock value in the decommissioning plan
  • Project management of decommissioning team and sub-contractor

 

Examples of typical deliverables for FPSO Decommissioning are:

 

  • Execution plan and cost estimation
  • Riser, umbilical and mooring disconnection analysis
  • Vessel spread selection and market enquiry
  • Decommissioning story board, tools and resource lists 
  • Design and build of original equipment 
  • ROV campaign support
  • Decommissioning schedule and procedure
  • Request for quotation, bid assessment and recommendation 
  • HAZID and HAZOP

Single Point Mooring system

Turret Mooring

Independent Verification Design

Working together with INCITIAS, clients can obtain objective evidence of asset compliance with project requirements.

With our independent verification design process, INCITIAS applies an efficient risk-based assessment method to prioritise critical elements of the asset.

 

An INCITIAS comprehensive review can include:

 

  • Desktop review of design documents
  • Review of HAZID, EIA and QRA findings
  • Risk ranking of asset elements
  • Preparation of review plan
  • Client approval of review plan
  • Execute review plan, including on-site performance verification
  • Issue of certification certificate
 

We work together with our clients to ensure the appropriate level of review is carried out.

Operations & Maintenance Support

INCITIAS combines our Engineering expertise with real world Operations and Maintenance experience.  We support our clients with O&M development and management activities including:

 

  • Enterprise management system development
  • Organisation structure development and evaluation
  • Systems and procedures development and review, including detailed procedures, permits and work systems
  • Emergency response systems
  • Defining specific port operations requirements
  • Operation and maintenance training and competency assessment
  • Commissioning activities

Integrated Owner’s Engineering Services

We support Owners with engineering, technical, and project management expertise across LNG, marine, and vessel conversion projects. Our clients can minimise risk and maximise opportunities earlier in project execution, with INCITIAS Owner’s engineering services. 

 

INCITIAS can provide integrated owner’s engineering services for onshore and offshore projects from a client office, site location or remotely from our offices in Melbourne. 

 

Typical services are:

 

  • Design and construction management
  • Customised risk management solutions
  • Specialist LNG process and marine engineering
  • Budget implementation, scheduling, and cost control
  • Non-permanent on-site dedicated offices for project

 

 

Indicative deliverables are:

 

  • Technical document reviews
  • Project bankability documents 
  • Basis of design
  • Functional performance specification
  • Resource plan and project schedule
  • Request for quotation and technical bid evaluation
  • Participation in HAZID, HAZOP, QRA, design reviews
  • FAT (Factory Acceptance Tests) certification
  • Work packs for installation contractor
 

We can be as involved as you require. From specialist resources who consultant on specific aspects of your project, to the provision of a fully integrated Owners team. 

At INCITIAS we develop tailor-made delivery solutions to match your project’s execution strategy and risk profile. Offering a full range of alternative delivery methods enables us to deliver the most effective project outcomes for you.

CLP Jetty Installation during the daytime

Advisory Services

INCITIAS offers integrated technical and commercial advisory services to assist clients advance their projects and provide support for their decision-making process. Clients can reduce risk and maximise opportunities by accessing our team of advisory specialists’ wealth of experience.

 

Typical advisory services are:

 

  • Technology assessment and selection. 
  • Commercial risk assessment.
  • Pre-feasibility, feasibility, and pre-FEED and FEED studies.
  • Contract review against the project technical performance.
  • Independent review of project execution plan.
 

INCITIAS techno-commercial advisory services aligns commercial drivers with feasible and proven technical solutions. Our team’s experience includes facility selection, financial assessment, contracting strategies, construction management and project operations. Assisting clients meet their business objectives using our capabilities to provide insights and solutions. 

 

Indicative deliverables are:

 

  • Site selection study
  • Environmental pre-assessment 
  • Technology options, recommendations and definition
  • Review of contract commitment against the facility performance
  • CAPEX and OPEX estimates
  • Financial models, NPV calculation, tolling model, and sensitivity assessment 
  • Project bankability document pack
  • Probabilistic models combining queueing and Monte Carlo assessment for logistic studies
  • HAZID, HAZOP, QRA and project risk assessment 
  • Operations and training requirements definition