Neste operates refineries in Finland, the Netherlands, and Singapore, converting waste and residues into renewable diesel and sustainable aviation fuel across 17 countries. For a cybersecurity team, the threat surface is industrial: SCADA and ICS environments running continuous chemical processes, global OT/IT convergence points, and a supply chain that touches everything from feedstock sourcing to aviation fuel delivery. The company employs over 5,200 people from more than 60 nationalities, which means identity management and access control span significant jurisdictional and cultural complexity.
The attack model here isn't theoretical - it's the reality of protecting critical energy infrastructure where a compromised control system doesn't just mean data loss, it means physical risk and environmental liability. Neste's production facilities handle hazardous materials at scale, and the company sits at the intersection of energy, aviation, chemicals, and plastics industries, each carrying distinct regulatory frameworks (NIS2 in Europe, TSA directives for aviation fuel logistics). Security operations must account for both enterprise IT and the deeply specialized world of process control networks.
Products like Neste MY Renewable Diesel and Neste MY Sustainable Aviation Fuel aren't just sustainability brands - they're high-value targets in a sector where intellectual property around catalyst processes and feedstock optimization is competitive advantage. A security team here works across domains: securing R&D data, hardening refinery OT networks against nation-state and criminal threats, managing cloud infrastructure for a company with California, European, and Southeast Asian footprints, and ensuring the integrity of logistics systems that move fuel across borders. The scope is global, the stakes are physical, and the regulatory pressure is intensifying.





