Darren Guccione, CEO and Co-founder, Keeper Security, writes:
For decades, enterprise security has been built around network perimeters like firewalls, VPNs and the false assumption that anything inside the network could be trusted. Today, operations span continents, workforces operate from personal devices and third-party partners require privileged access to production systems at all hours.
This isn't just a remote work challenge. It redefines operational security across the oil and gas industry, where distributed teams, 24/7 support requirements and bring-your-own-device realities are the norm. DrillDocs, a computer vision company powering offshore drilling operations, knew this environment well with contractors working across 20 countries, unmanaged endpoints throughout and no real-time visibility into privileged sessions. The organisation is now leading the industry in securing their distributed environment, however their operating reality is not unique. It is reflective of the entire oil and gas industry.
The data confirms it. The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that credential abuse appears in 39% of breaches when considering the entire attack progression. Meanwhile third-party involvement in breaches increased by 60% from the previous year, reaching 48% of total breaches. For organisations operating the way DrillDocs does – distributed, contractor-dependent and device-agnostic – those numbers represent structural exposure, not edge cases. Pivoting to zero-trust Privileged Access Management (PAM) is no longer optional; it is an operational necessity.
Why implicit trust fails when operations scale globally
A small startup might manage privileged access through informal processes and shared passwords, but a scaling operation cannot afford to extend production system access to global teams without rigorous governance and security. Traditional perimeter security protects the network boundary, but it doesn’t protect privileged sessions once access is granted.
When teams operate across unmanaged endpoints and personal devices, it creates a massive credential exposure footprint with zero visibility into who accessed what, when or which actions were performed. Keeper research shows that in 72% of organisations, credential misuse is not detected in real time, with most taking hours, and in some cases, days or weeks to identify unauthorised privileged access. For a company like DrillDocs, operating across international time zones with contractors on personal devices, that detection gap wasn’t theoretical — it was an open window.
Verizon’s DBIR further reveals just how widespread these remediation failures have become. Third-party organisations struggle to address even basic security gaps: fewer than one in four fully remediated missing or improperly secured Multi-Factor Authentication (MFA) on their cloud accounts, with half of all findings being resolved within a month. Password and permission problems prove even more stubborn, taking nearly eight months to address halfway, and even then, only 31% of organisations achieve complete remediation.
Perhaps most concerning, 37% of organisations had an admin account with MFA disabled on an Infrastructure as a Service (IaaS) platform, creating privileged access vulnerabilities that compound when extended to distributed teams working from unmanaged endpoints. Engineers and contractors connecting from personal devices operate outside traditional security tooling, while manual provisioning allows access requests to take hours or days rather than just-in-time permissions, leaving credentials exposed across email threads and informal channels.
The identity problem is different in the field
Most industries can draw a reasonably clean line between their corporate network and their operational one. Oil and gas cannot. Offshore platforms, drilling sites and remote field operations are structurally dependent on a rotating cast of contractors, third-party engineering firms and vendor support teams. Each requires privileged access to production systems, often from personal devices, across time zones, with no tolerance for downtime and limited appetite for security friction. That operating model is not a deviation from the norm. It is the norm. And it creates an identity problem that perimeter-based security was never designed to solve.
When a contractor connects from an unmanaged endpoint in a different country, the question isn't whether your firewall is configured correctly. The question is whether you know exactly who that person is, what they are and are not authorised to do, whether their credentials are verified in real time and whether every action they take is logged and auditable. In most organisations, the honest answer to at least one of those questions is no.
Zero-trust PAM doesn't ask operations to slow down. It asks them to verify – continuously, automatically and without adding friction to the workflows that keep production running. The architectural shift is significant, but the operational disruption, when implemented correctly, is not.
Zero-trust architecture as operational infrastructure
DrillDocs faced a real problem when it outgrew its existing informal access controls. That’s why it turned to Keeper for a comprehensive PAM solution. The company found that implementing KeeperPAM didn't require a lengthy deployment or a rip-and-replace of existing infrastructure – it required two hours.
From the moment of deployment, engineering partners working across international time zones could access Windows and Linux virtual desktops through their browsers, without VPN installations and without credentials ever touching their personal devices. Zero-trust gateways handle the connection while the vault handles the credentials.
Access provisioning, previously a process measured in hours or days, happened in a matter of seconds. That's the operational shift that makes just-in-time access practical rather than aspirational. When granting or revoking access is instant, the pressure to leave standing credentials in place disappears along with the risk they carry.
Automated deployments presented a separate challenge, as credentials had previously lived in plaintext on production systems for machine-to-machine access. Keeper Secrets Manager resolved this by programmatically retrieving and injecting credentials directly into memory at runtime, eliminating the plaintext exposure and bringing non-human identity risk under the same governance framework as human access. Every privileged session, for internal engineers and external support teams alike, is recorded and logged, providing the audit trail that DrillDocs needed to pursue SOC 2 certification and the operational visibility to catch anomalies before they become incidents.
DrillDocs achieved enterprise-grade security controls through a two-hour deployment, eliminating unsafe credential storage practices while maintaining the operational agility required for global offshore operations.
The operational mandate for verified access
The future of oil and gas operations is distributed but the organisations that will operate it securely are the ones that have stopped assuming trust and started verifying it. Zero-trust PAM doesn’t just protect your systems, it gives your distributed teams a mandate: a verified identity, defined scope and the guardrails to operate production infrastructure with confidence from anywhere in the world, on any device, at any hour. In a distributed operating environment, implicit trust isn’t a policy gap. It’s an open door.