TSA Issues New Railroad Cybersecurity Requirements
Time 1 Minute Read

On October 18, 2022, the Transportation Security Administration (“TSA”) issued a new cybersecurity directive requiring passenger and freight railroad carriers to create plans for responding to cybersecurity incidents. The new directive is one of many actions taken by the Biden Administration to strengthen the cybersecurity posture of the U.S.’s critical infrastructure following a significant ransomware attack on a major U.S. pipeline in 2021.

The new directive requires railroad carriers to (1) implement network segmentation policies and controls to allow the continuous operating of systems in the event of a breach; (2) create access control measures to prevent unauthorized access to systems; (3) implement monitoring and detection policies and procedures to detect and prevent security flaws and vulnerabilities; and (4) apply security patches and updates for all critical systems in a timely manner, among other requirements.

By February 2023, railroad carriers  must submit a TSA-approved Cybersecurity Implementation Plan that describes how the carrier plans to comply with the new directive. The directive also requires railroad carriers to establish a Cybersecurity Assessment Program and file annual compliance assessments with the TSA. 

Learn more about TSA’s cybersecurity initiatives and related guidance.

You May Also Be Interested In

Time 1 Minute Read

On February 6, 2026, the Federal Trade Commission announced its second report to Congress on its efforts to combat ransomware and other cyber attacks.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 2 Minute Read

On November 20, 2025, the U.S. Securities and Exchange Commission issued a brief announcement that it filed a joint stipulation with defendants SolarWinds Corporation and its Chief Information Security Officer to dismiss, with prejudice, the SEC’s ongoing civil enforcement action against them.

Time 3 Minute Read

On November 12, 2025, the UK government introduced the draft Cyber Security and Resilience (Network and Information Systems) Bill to the UK Parliament.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page