TSA Pipeline Security Directives in Plain English

A general explainer for pipeline owners and contractors on TSA security directives: what they aim at, who they touch and practical steps to prepare.

3 min readBy Ironfield Cyber Team

For companies that own, operate or serve pipelines, the Transportation Security Administration became a cybersecurity regulator in a way many did not expect. Beginning in 2021, TSA issued security directives for owners and operators of critical pipelines, requiring specific actions around reporting, planning and assessment. The directives have been renewed and revised since, and the details can change, so treat this post as a general orientation rather than a legal reference.

If you operate a pipeline, you already have compliance staff following the exact text. If you are a contractor, service provider or supplier to operators, understanding the intent helps you answer customer questions and avoid becoming the weak link.

What the directives are trying to achieve

At a general level, TSA's pipeline security directives push covered operators toward a few outcomes:

  • Prompt reporting of cybersecurity incidents to the federal government
  • A designated cybersecurity coordinator available around the clock
  • A review of current practices against TSA's requirements to find gaps
  • Written cybersecurity implementation plans and incident response plans
  • Specific technical measures, such as network segmentation between IT and OT, access control, continuous monitoring and timely patching
  • Periodic testing and assessment of the plans

Which specific obligations apply to a given company depends on whether it is designated as covered. Operators should consult TSA's current directives and their counsel for exact requirements.

Why contractors and suppliers should care

Even if you are not directly covered, your customer is. That has several practical consequences:

  • Access scrutiny. Operators will ask who from your company can connect to their systems and how.
  • Questionnaires. Expect detailed security reviews as part of onboarding or renewal.
  • Contract language. Requirements on incident notification, background checks, patching and logging may flow down to you.
  • Incident coordination. If you are compromised, your customer may need to report quickly, so they will expect early notice from you.

Practical steps for service providers

Know your customer's expectations

Ask which requirements the customer is passing along. Request them in writing and assign someone to track them.

Tighten your remote access

If your technicians connect to customer systems, use individual accounts, multifactor authentication, logged sessions and approved connection methods only. This is one of the most frequent topics in operator reviews.

Separate your environments

Keep customer project data and credentials separate from general corporate systems where you can. Limit who has access, and review it regularly.

Prepare an incident notification path

Write down who contacts the customer and how fast, including after hours. Agree with each operator on a contact method before an event occurs.

Keep documentation ready

Maintain a short security package: your policies, an overview of your network protections, training records, and your incident response plan. Having it ready speeds up reviews.

For operators: lessons from the directive approach

The directive structure works as a decent template for any energy business, regardless of regulatory status.

  1. Name a cybersecurity lead with a backup.
  2. Know what your IT and OT environments look like.
  3. Separate IT from OT and control the connections between them.
  4. Write an incident response plan and practice it.
  5. Decide in advance who reports what to whom and when.
  6. Test your plans at least once a year.

Common mistakes

  • Assuming the requirements only matter to large operators
  • Relying on a vendor's assurance without evidence
  • Writing plans that nobody has rehearsed
  • Treating OT as the exclusive responsibility of operations or IT, rather than a shared one

Staying current

Directives and guidance get updated. Rely on TSA and CISA publications for the current requirements, and assign a person to watch for changes.

How Ironfield Cyber helps

Ironfield Cyber works with pipeline contractors, energy service companies and operators on security programs that stand up to customer reviews, including access controls, segmentation and incident response planning. If an operator has sent you a security questionnaire, we can help you answer it accurately.