Offshore Energies UK has published Issue 3 of its Security Guidelines for Offshore Installation Managers (OIMs), a reference document covering how OIMs should prepare for and respond to security incidents on offshore installations. The scope is broad: incident response, powers of restraint, cyber security, firearms management, bomb threats, contraband, and hostage scenarios, all supported by templates and regulatory references that operators can use to align their own procedures with industry practice.
It's a health and safety publication first and a security one second, and that combination is worth pausing on. An OIM's authority during a security incident sits alongside, not apart from, their day-to-day responsibility for everything happening on the installation: who is on board, what work is in progress, what equipment is isolated, and what state the platform is in at any given moment. Guidance like this only works in practice if that underlying picture is accurate and immediately accessible when it matters.
Security incidents don't wait for paperwork to catch up
A bomb threat, a hostage situation, or a serious cyber intrusion is, by definition, a moment when normal routines break down. The OIM needs to make fast decisions about muster, evacuation, restraint, and communication with onshore authorities. What they can't afford is uncertainty about basic operational facts, such as who holds an active permit, which systems are isolated, where contractors are working, or which vessels are currently authorised to be alongside.
This is where the quality of everyday control of work becomes a security asset as much as a safety one. A digital permit to work system that keeps an accurate, real-time record of who is on the installation and what they're doing gives an OIM something a paper-based or fragmented system can't: a single, trustworthy source of truth to work from the instant something goes wrong. The same principle runs through our piece on electrical permit to work systems, where the value of a well-run permit system is less about compliance on a normal day and more about how quickly it lets you answer hard questions on a bad one.
Integrity data is part of the security picture too
The OEUK guidelines reference cyber security explicitly, and rightly so, but physical integrity and cyber risk aren't as separate as they might first appear. An installation with weak visibility over its own asset condition, its joints, its critical electrical equipment, its structural integrity, is also an installation that struggles to answer a simple question during a crisis: is it safe to keep this system running, or does it need to be shut down as a precaution? We've written before about why joint integrity management matters offshore, and the same logic applies here. Good integrity data, properly maintained and easy to query, is a resource an OIM can call on during a security event just as readily as during a routine inspection.
Integration adds complexity, and complexity needs managing
Offshore installations are also changing shape. The addition of wind turbines to oil and gas platforms, and the broader push towards co-located and hybrid energy infrastructure, adds new equipment, new contractors, and new lines of responsibility to sites that already have enough to track. Our post on wind turbines on oil and gas platforms looks at what that integration means for control of work more generally. It's equally relevant to security planning: an OIM managing a mixed installation needs their control of work system to reflect that mix accurately, not treat it as an afterthought bolted onto a legacy process.
Where software fits in
OEUK's guidelines are, sensibly, about people, judgement, and procedure. No software replaces the OIM's authority or training. But the guidelines assume a level of situational awareness that manual systems make harder to sustain as installations grow more complex. Digital control of work and integrity platforms exist to give OIMs and their teams that awareness by default, so that when the templates in Issue 3 need to be put into action, the underlying operational picture is already there, accurate and current, rather than something that has to be pieced together under pressure.
For operators reviewing their procedures against the new guidance, it's worth asking not just whether the security response plan is sound, but whether the everyday systems feeding it, permits, isolations, integrity records, contractor logs, are reliable enough to support it when it counts.
Source: https://oeuk.org.uk/product/security-guidelines-for-offshore-installation-managers-oims-issue-3/