We deliver trusted Advisory Automation Audit | that drives results.

Resources
  • All Resources

    Your central hub for security and compliance content.

  • Blog

    Stay informed with expert insights and practical advice on cybersecurity, privacy, and compliance challenges.

  • News

    Get the latest company updates, industry developments, and regulatory changes impacting the cybersecurity landscape.

  • Whitepapers

    Access in-depth research and strategic guidance on risk management, regulatory compliance, and cybersecurity best practices.

  • Case Studies

    See how organizations like yours solved complex cybersecurity and compliance challenges with TrustNet’s solutions.

Knowledge Hub
Guides
  • All Guides

    Get practical step-by-step guides designed to help you navigate audits, improve security posture, and meet compliance requirements.

Edit Template
Login

Secure login to iTrust Platform

TSA Requires Rail and Airports to Strengthen Cybersecurity

Expert Security Insights

Stay informed with expert-driven security content

Network Security Audit

Earlier this year, a ransomware attack on the Colonial pipeline severely interrupted the country’s fuel distribution system. In response, regulations were implemented in May that strengthened the cybersecurity infrastructure of the pipeline system.

In light of this recent upsurge in data breaches and ransomware attacks that have victimized multinational corporations, institutions, and companies. The U.S. Transportation Security Administration (TSA) is now also protecting the nation’s passengers and the companies that convey them. The Biden administration recently issued a series of recommendations and directives designed to bolster the country’s digital underpinnings to protect it against attack.

Most notably, the updated regulations hold passenger and freight operators accountable by requiring them to become intentional about their cybersecurity. To accomplish this, each major provider must now appoint a specific person or team to assess cybersecurity. Should an incident occur, it must be reported within 24 hours to the Cybersecurity and Infrastructure Security Agency. Additionally, all companies are expected to assess their digital assets, practices, and procedures to identify and address vulnerabilities. Finally, each must create and implement a plan that addresses how the organization will recover from the breach and alternative contingency strategies to minimize service interruptions.

These rail carrier-related measures will take effect at the end of the year, with similar action plans soon required at large airports. The TSA still recommends making cybersecurity a priority for smaller rail and airport operators who do not fall under the mandates.

Not all lawmakers in Washington are in favor of this TSA initiative. Some Republican officials are concerned that the regulations were pushed through without sufficient transparency and feedback from industry stakeholders. Concern was also centered on a fear that financial assets and attention would be focused more on regulatory compliance than on addressing the cyber threats directly. The TSA answered these criticisms by maintaining that the regulations were only enacted after extensive consultation with industry executives and other officials.

Request Your Cybersecurity and Compliance Quote