TSA Pipeline Security Directives: What Smaller Operators Should Know

A general explainer on TSA security directives for pipeline operators, who is affected, and the foundational cyber practices that help owners and contractors.

3 min readBy Ironfield Cyber Team

After the 2021 ransomware attack on a major fuel pipeline operator, the Transportation Security Administration began issuing security directives to certain pipeline owners and operators requiring them to strengthen cybersecurity. Since then, the directives have been renewed and updated. They are aimed at operators the TSA designates as critical, but their influence reaches further: contractors, service companies, and smaller operators increasingly see similar expectations in contracts, insurance questionnaires, and customer reviews.

This is a general overview, not legal or compliance advice. If you are a pipeline owner or operator, work with your compliance team to understand which requirements apply to you and their current versions.

Who is directly covered

The directives apply to owners and operators of hazardous liquid and natural gas pipelines and related facilities that TSA has identified as critical. Many smaller gathering and distribution operators and service contractors are not directly covered, but they may work with or for those that are.

What the directives generally ask for

In broad terms, the requirements address:

  • Reporting cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency within a defined period.
  • Designating a cybersecurity coordinator who is available to TSA and CISA.
  • Assessing the current state of cybersecurity and identifying gaps against the requirements.
  • Implementing measures to protect against ransomware and other threats to IT and operational technology systems, including network segmentation between IT and OT.
  • Controlling access to critical systems, with attention to authentication and authorization.
  • Monitoring and detection to identify threats.
  • Patching and updating systems on a risk-based schedule.
  • Cybersecurity incident response planning, including exercises.
  • Architecture and design reviews and vulnerability assessments.

The specifics, timelines, and formats are set out in the directive text, which has changed over time, so always check the current version.

Why smaller operators and contractors should care

  1. Customer expectations. A covered operator must manage risk from third parties, and may pass security requirements down to service providers with access to their systems.
  2. Insurance. Underwriters ask about segmentation, multi-factor authentication, backups, and incident response. These match the themes of the directives.
  3. Rising baseline. What is required of the largest operators today often becomes standard practice later.
  4. Real threats. Ransomware and intrusions affect operators of all sizes.

Practical foundations that map to the directives

Segment IT from OT

Separate the business network from control networks with a firewall, and allow only the traffic that operations needs. This is the most consistently useful control.

Control and log remote access

Use multi-factor authentication, individual accounts, and recorded sessions for every remote connection to control systems, including vendor access.

Maintain an asset inventory

Know your controllers, HMIs, servers, network devices, and software versions, and who supports each.

Patch and manage vulnerabilities

Track vendor advisories, assess them against your environment, and apply updates or compensating controls on a documented schedule. CISA's advisories are a good source.

Prepare an incident response plan

Document who does what, who can authorize operational decisions, how to reach the right agencies, and how to operate manually. Test it through a tabletop exercise with operations and leadership at least once a year.

Back up what matters

Keep offline copies of configurations, programs, and databases. Test restoring them.

Train people

Operators, technicians, and contractors with access should understand the basic risks and how to report problems.

Contractors: what to expect

If you work for a covered operator, you might be asked to complete security questionnaires, follow access procedures, use approved remote tools, report incidents quickly, or allow reviews. Prepare written answers and keep records of training and device standards.

Start with a gap check

A simple first step is to compare your practices against the topics above and list where you fall short. Then fix the highest-risk items first. Document what you do, because evidence matters in any review.

How Ironfield Cyber helps

Ironfield Cyber works with energy and pipeline-adjacent companies on segmentation, remote access, incident response planning, and documentation. If a customer has asked you about pipeline security expectations, we can help you prepare clear, accurate answers.