Northwest Natural Gas Company is a 165-year-old natural gas distribution utility headquartered in Portland, Oregon, serving approximately 2 million people across Oregon and Southwest Washington. For a cybersecurity team, the attack surface is concrete and consequential: a sprawling physical network of pipelines and distribution infrastructure whose compromise carries immediate, real-world safety implications. The threat model isn't abstract - it's operational technology (OT) security for critical infrastructure where availability and integrity are non-negotiable.
The company's push into renewable natural gas (RNG) and hydrogen technologies expands that attack surface into newer, less-traditional integration points. As grid-connected energy systems modernize, so do the interconnections between IT networks, SCADA/ICS environments, and customer-facing digital platforms. Defending a utility of this scale means working across both legacy industrial control systems and evolving cloud or hybrid architectures simultaneously.
NW Natural operates in a heavily regulated sector where compliance frameworks like NERC CIP (if applicable to gas distribution) and TSA pipeline security directives shape security posture. The cybersecurity function here isn't about chasing novelty - it's about disciplined defense of physical infrastructure, managing risk across aging OT estates, and securing the digital transformation underway as the company moves toward renewable energy solutions.






