The LOTOS Group is one of the largest companies in the country. It is an oil conglomerate involved in the extraction and refining of crude oil, as well as the wholesale and retail sale of high-quality petroleum products. It is a producer and supplier of, among others, unleaded gasoline, diesel oil, heating oil (light heating oil), aviation fuel, and heavy fuel oil. The company also specializes in the production and sale of lubricants and asphalt.
In the mid-1970s, a highly modern refinery was established in Gdańsk, which was said to be the most advanced in the world and had the largest Oil Block in Europe. It was the first investment in the Polish People’s Republic based on Western technologies. Over time, the refinery lost its modernity, but the creative workforce and the “development gene” led to major investments and expansion from 1998 to 2020, making it one of the most modern refineries in the world again. During this time, production increased fourfold, and the company evolved from a regional refinery into a national fuel conglomerate, integrating southern refineries and expanding its extraction operations both in Poland and abroad.
Facts and figures
Full name
Grupa Lotos S.A.
WWW
Industry
Energy and fuels
Employment
Powyżej 2000
What did the client expect?
As an operator of a critical service in the area of liquid fuel production, the LOTOS Group expected and required adjustments to processes and the provision of critical services in certain IT and OT automation areas in accordance with the requirements of the Act on the National Cybersecurity System. A challenge was the dispersed documentation of elements required by the regulations of the National Cybersecurity System and the requirements of ISO/IEC 27001 and ISO 22301 standards.
What did we do?
WE CONDUCTED A SECURITY AUDIT
We verified the LOTOS Group’s readiness to meet the requirements and obligations arising from the regulations of the Act on the National Cybersecurity System (KSC). We collected and examined the existing documentation, conducted interviews, and carried out assessments based on checklists. Through extensive consultations and analyses, we defined the boundaries of the cybersecurity management system for the critical service and determined which IT/OT systems, and to what extent, should be included in the development or optimization of internal procedures.
DEVELOPMENT OF A RISK MANAGEMENT MODEL
We developed a risk management model in the area of cybersecurity and ensured the alignment of procedures with those already existing in the corporate risk management area. This approach enabled the use and adaptation of the existing methodology for risk description and probability assessment, considering changes in impact evaluation (ISO standards aspects – integrity, confidentiality, and availability) and the identification of information assets.
CYBERSECURITY DOCUMENTATION
We addressed the biggest challenge, which was related to the dispersion of documentation. We proposed a modification of the structure that took into account the dispersion of its individual elements and the development of overarching documents that reference the already existing procedures. From the perspective of the end user of the documentation, we reduced and minimized the number of changes introduced, and ultimately, the developed structure allowed for better understanding of the KSC regulation requirements and access to internal information.
KNOWLEDGE TRANSFER
We organized training for employees of the LOTOS Group who are involved in the operation and supervision of the critical service, including its security oversight. The scope of the training was tailored to the skill level of each participant. The training covered basic, intermediate, and advanced levels. The applied training techniques enabled the exchange of experiences and the learning of best practices in the field of cybersecurity.
What were the results?
The project involved adapting processes and providing the critical service in accordance with the requirements of the Act on the National Cybersecurity System.
As the operator of a critical service, the LOTOS Group received comprehensive support in implementing the National Cybersecurity System Act. We built the required organizational and technical capacity to ensure the proper level of security for the IT systems used to provide the critical service. We conducted a security audit, performed a risk analysis, and identified critical areas that could impact the availability of the critical service. Ultimately, we updated the documentation required by the KSC Act and trained key personnel. As a result, the LOTOS Group meets the requirements of the KSC Act.
What did the client gain?
Compliance with the requirements and obligations arising from the regulations of the Act on the National Cybersecurity System.
Increase in the level of information security.
Optimization of cybersecurity costs.
Introduction of best practices in risk management.
Updated security procedure documentation.
Increased level of risk and security oversight in accordance with the KSC Act.
Increased cybersecurity awareness at all management levels.
Improvement and optimization of processes and procedures in the field of information and IT security.
Strengthening corporate governance.