After the 2021 ransomware attack on a major U.S. fuel pipeline operator, the Transportation Security Administration issued security directives to certain critical pipeline owners and operators. Those directives established cybersecurity requirements that had previously been voluntary guidance for much of the industry. If you operate pipelines or provide services to those who do, it helps to understand the general shape of what they require.
This post is a high-level overview, not legal advice. The directives have been revised and renewed over time, and applicability depends on how TSA has designated an operator, so confirm current requirements directly with TSA and your compliance advisers.
Who is affected
TSA directed its requirements at owners and operators of hazardous liquid and natural gas pipelines and facilities that it designated as critical. Many smaller operators are not directly covered. But even if you are not named, you may be affected in several ways:
- You may be a contractor or service provider to a covered operator that passes requirements to you.
- You may be an operator that expects to be covered later or that wants to follow the same practices.
- Your insurer or lender may reference the directives as a benchmark.
The core themes
While specifics evolve, the directives have centered on a consistent set of ideas.
Designate cybersecurity leadership
Covered operators need a designated cybersecurity coordinator who is available around the clock and serves as the contact with TSA and CISA.
Report incidents
Operators must report certain cybersecurity incidents to CISA within a defined timeframe. That requires internal procedures for recognizing, escalating, and reporting events quickly, not discovering them weeks later.
Assess and plan
Operators are required to evaluate their cybersecurity posture, identify gaps, and develop plans to address them. Later directives emphasized an approved implementation plan and cybersecurity assessment program.
Technical protections
The directives have included requirements for network segmentation between IT and OT, access control measures, continuous monitoring and detection, and timely patching or other mitigation of known vulnerabilities. They have also emphasized the ability to keep critical operations running or recover if IT systems are compromised.
Incident response and testing
Operators are expected to maintain an incident response plan and test it, often through exercises that involve both IT and operations staff.
What this means for contractors and vendors
If you support a covered pipeline operator, expect questions and contract language around:
- Remote access to operational systems, including multi-factor authentication and session control.
- Notification timelines if you experience a security incident.
- Patching and vulnerability management for any equipment or software you supply.
- Personnel access, training, and background screening for staff on site.
- Separation between your corporate systems and the operator's environment.
Operators are accountable for their entire environment, including what vendors connect to it. That makes vendor behavior a regular topic in their reviews.
Practical first steps
Whether you are directly regulated or supporting someone who is, these steps align well with the directives.
- Map IT and OT boundaries. Know which networks connect and what traffic crosses.
- Name an owner. Decide who is responsible for cybersecurity and who answers when something happens.
- Write a short incident reporting procedure. Include who decides that an event is reportable and how to contact the right agencies.
- Control remote access. Use MFA, named accounts, and logging for everyone, including vendors.
- Track vulnerabilities. Maintain an inventory and a documented process for patching or mitigating.
- Test recovery. Practice restoring critical systems and operating in a degraded state.
Keep documentation current
Assessors and customers often care as much about evidence as technology. Keep dated records of reviews, drills, training, and decisions. If the directives change, update your procedures and note when you did so.
Staying current
Because the directives have been updated, avoid relying on summaries that are more than a few months old. Check TSA's official communications, industry association updates, and your regulatory contacts periodically.
Where Ironfield Cyber helps
Ironfield Cyber works with pipeline operators and their contractors on segmentation, remote access controls, incident response planning, and exercise facilitation. If you are preparing for a customer review, we can help you organize the answers and close the obvious gaps.