At a remote upstream site, the expensive part of a fault is the trip.
A dead switch at head office costs an hour and a spare. The same switch on an offshore platform or at a swamp flow station costs a seat on a helicopter or a boat, and often a wait for the weather. Hardening remote site IT for oil and gas comes down to one number: how many faults need someone to travel. This piece is about bringing that number down.
It does not repeat the sector basics. Connectivity options, OT segmentation and enclosures are covered in our guide to IT for oil, gas and energy operations. Read that first if you are scoping a site from nothing.
One limit, stated up front. Control systems, safety systems and anything installed inside a classified hazardous area belong to the operator's instrument and safety engineers and to the system OEMs. Equipment in a hazardous zone needs certification for that zone, under IECEx or ATEX. This piece covers the IT around those systems: links, network, servers, endpoints and how they are managed.
Count the faults that need a trip
Start with a list of the faults each site has had, or can expect. For each, ask one question. Can it be fixed without anyone travelling?
Most faults fall into two groups.
Soft faults. A hung router. A switch port stuck in a bad state. A server that needs a restart. A configuration change that went wrong. These can be fixed remotely, if you can still reach the device.
Hard faults. A dead power supply. A failed disk. A UPS battery that has given up in the heat. These need hands on the equipment, but not necessarily an engineer's hands.
The design goal follows from that split. Every soft fault should be fixable from the operations centre. Every hard fault should be fixable by someone already on site, following instructions.
Reaching a device when the network is the fault
Remote management over the site's main network works until the main network is what broke. Then you cannot reach the device you need to restart.
Out-of-band access fixes this. A console server on site connects to the serial or management port of each critical device. It is reachable over a path that does not depend on the main network. At a remote site that path is usually a separate low-bandwidth link, either a cellular modem where there is coverage or a small satellite terminal. An engineer at base logs in to the console of the hung router and reconfigures or reboots it.
Pair it with switched power. A rack PDU with per-outlet control lets the same engineer cut and restore power to one device at a time. That is the remote version of turning it off and on again, and it clears many of the faults that would otherwise need a visit.
The cost is a second small set of equipment to buy and maintain, and a second link to pay for every month. Set that against one avoided mobilisation. Where a visit needs a helicopter seat, the sum is short.
Out-of-band access is also a way in for an attacker. Put it behind its own authentication, log every session, and give no one a standing account they do not need. The same applies to any remote access path that ends near OT systems.
Links: test the failover, size the backup
Two links on different technologies is the baseline for any site that matters. The choice between VSAT, LEO satellite, microwave and LTE is set out in the sector guide. Two things get missed after the links are installed.
First, failover that has never been tested is a guess. Pull the primary on a planned date and watch what happens. Does traffic move to the backup? How long does that take? Does it move back when the primary returns? Write down the result and repeat it on a schedule.
Second, size the backup link for what has to run on it. If the primary is microwave and the backup is a narrower satellite service, decide in advance what gets the backup bandwidth. Monitoring and control data first. Remote management second. File sync and software updates wait. Set that order in the router's quality-of-service rules, where it will actually happen, not only in a design document.
Licensing belongs in the link design. A private microwave link needs a frequency assignment from the Nigerian Communications Commission, and radio equipment used in Nigeria needs NCC type approval. A satellite service bought from a provider sits under that provider's NCC licence, so check that the provider holds one for the service they are selling.
Make the hard faults a swap
A hard fault is quick to fix when the right spare is already on site and the person holding it can fit it. That takes some preparation.
- Standard builds. Every switch, router and server at the site is a known model with a saved configuration. A replacement can be loaded with that configuration before it ships, or can pull it down once it is connected.
- Spares on site. One of each critical item that cannot wait for the next scheduled trip, such as a switch, a router, a power supply, a set of UPS batteries and a pre-imaged laptop. Spares held at base do not help the site.
- A written swap procedure for each item, with photos, that an operations technician can follow while an engineer talks them through it by phone.
Labelling finishes the job. If every cable and every port is labelled to match the site diagram, a non-specialist can move the cables to the replacement in the right order.
Spares cost money and tie up stock. Keep the list to items whose failure stops the site, and replace each spare as soon as it is used. A spares shelf that was emptied by the last fault is no shelf at all.
Power and heat set hardware life
Most remote sites run on their own generation, and the power quality is worse than any office. Every rack needs UPS protection and power conditioning sized for the generator's real behaviour, including the transfer gap and the voltage swings when large loads start.
Heat is the other half. Equipment rated for an air-conditioned room does not last in a closed container in the dry season. Specify cooling with the installation, and put a temperature sensor in every enclosure. Batteries in a hot enclosure age faster than the datasheet assumes, so replace them on measured condition rather than on the calendar.
Watch what you would otherwise travel to check
Remote monitoring is how the operations centre hears about a fading UPS battery or a link running near capacity before the site goes dark. Every critical device should report its health: link status, UPS battery and load, enclosure temperature, and disk health on servers. Alerts should reach someone who acts on them, at hours that match the site's operation, not office hours. How monitoring works in practice is set out in our piece on proactive IT monitoring.
Where to start
Rank the sites by what one visit costs. For each site, list the soft faults you cannot yet fix remotely and the hard faults with no spare on site. Work down that list from the most expensive site.
The budget will run out before the list does. Imported hardware and satellite capacity are priced in dollars, and the naira figure moves with the rate. Spend first where a trip costs most, and write down why, so the order holds up at the next budget review.
Frequently asked questions
What is out-of-band management, and does a remote site need it?
It is a second way to reach the console of a router, switch or server that does not depend on the site's main network. A console server on its own small link lets an engineer at base recover a hung device. Any site where a visit takes more than a day to arrange should have it.
Which spares should a remote oil and gas site keep?
One of each item whose failure stops the site and cannot wait for the next scheduled trip. That usually means a switch, a router, a power supply, UPS batteries and a pre-imaged laptop or workstation. Each spare should be the same model as the equipment it replaces, with its configuration saved.
How often should failover between links be tested?
On a fixed schedule, and again after any change to the links or the router. Quarterly is a sensible floor for a producing site. Each test should record whether traffic moved, how long it took and whether it moved back.
Does the NDPA apply to IT at remote field sites?
Yes, where the systems handle personal data. Crew rosters, contractor records and access logs are personal data. The Nigeria Data Protection Act 2023 applies however remote the site is, so access to those systems should be controlled and logged like anywhere else.
Next step
If you run remote sites and want to know which faults still need a trip, send us the site list, how each site is reached and what equipment is installed. We will work through it with you, site by site. See our oil, gas and energy page and our managed services, or contact us.



