logo

How to Respond to TSA’s New Cybersecurity Reporting Standards for US Rail Operators

ID: dce0d85f-2a43-5431-8a0b-e028924492b6

STIX ID: report--dce0d85f-2a43-5431-8a0b-e028924492b6

Feed Name: Dragos Blog

Date Published: 2021-12-21

Date Updated: 2026-04-27

...
...

This report summarizes new U.S. cybersecurity directives for rail (and some air) operators requiring a designated cybersecurity coordinator, 24-hour incident reporting to CISA, incident response plans, and vulnerability assessments. It highlights challenges in assessing OT on locomotives, recommends monitoring strategies (favoring Office Segment sensor placement), hardening mandated technologies like PTC, and advises operators to engage experienced industrial cybersecurity partners (such as Dragos) for vulnerability assessments, penetration tests, IRP workshops, and tabletop exercises to meet the new requirements and reduce operational risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.