TSA Pipeline Security Directives: What Vendors Need to Know

A general overview of TSA security directives for pipeline operators and how they affect the vendors, contractors and service providers who work with them.

3 min readBy Ironfield Cyber Team

Following the Colonial Pipeline ransomware incident in 2021, the Transportation Security Administration issued security directives for owners and operators of critical hazardous liquid and natural gas pipelines and facilities. These directives have been updated over time and have shaped how operators think about cybersecurity. If your company builds, maintains or supports pipeline infrastructure, even indirectly, it helps to understand the general shape of these requirements and how they flow to vendors.

This is a general overview, not legal advice. Directives are revised, and applicability depends on the operator's designation. Always confirm current requirements with the operator and consult the TSA's published materials.

What the directives generally require

Without reciting specific provisions, the directives for pipeline operators broadly address themes like these:

  • Reporting. Designating a cybersecurity coordinator and reporting significant cybersecurity incidents to CISA within a defined timeframe.
  • Assessment. Reviewing the current state of cybersecurity practices and identifying gaps.
  • Planning. Developing and maintaining a cybersecurity implementation plan, including how network segmentation, access control, monitoring and patching will be handled for critical systems.
  • Incident response. Maintaining a cybersecurity incident response plan and testing it with exercises.
  • Network segmentation. Separating IT and OT systems so that a compromise in one does not automatically spread to the other.
  • Access control and monitoring. Controlling who can reach critical systems and detecting anomalous activity.
  • Patching and vulnerability management. Applying security updates in a risk-based way.

Operators are responsible for compliance. But they depend on contractors, integrators and service providers to deliver much of the work, which is how the requirements reach you.

How requirements flow to vendors

Expect operators to push expectations downstream through contracts, purchase orders and onboarding.

  • Security questionnaires. Detailed questions about your policies, staff screening, remote access practices and incident handling.
  • Contract clauses. Requirements for notifying the operator of incidents quickly, often within a short window, and cooperating with investigations.
  • Remote access rules. Named accounts, multi-factor authentication, approved connection paths and logging.
  • Equipment and software requirements. Expectations about secure configuration, patch support and documentation for items you deliver.
  • Personnel requirements. Training, background screening and access approvals for staff working at facilities.
  • Right to audit or review. Operators may ask for evidence of your practices.

What contractors can do now

Create a basic security package

Assemble documents you can share: a short security policy summary, incident response contacts, an overview of how you protect customer data and remote access, and employee training records. Having these ready speeds up customer reviews.

Harden your own environment

If an attacker compromises your office network or your laptops, they may reach your customers through the trust you have. Use multi-factor authentication, current endpoint protection, patching, email security and tested backups.

Control the devices you take on site

Use dedicated, encrypted, patched laptops for operator work. Understand site rules for USB drives, personal devices and wireless networks.

Be ready to report quickly

Know exactly whom to call at each customer if you suspect an incident involving their systems or data, and write it into your own response plan. A delay of a day can matter.

Clarify roles in writing

Where your work includes OT systems, such as installing or commissioning controls, confirm who is responsible for configuration, credentials, documentation and updates after handover.

Questions to ask your pipeline customers

  1. Which security requirements apply to our scope of work?
  2. What is the required incident notification process and timeframe?
  3. How should we connect remotely, if at all?
  4. What documentation do you expect at delivery?
  5. How often will you review our security practices?

Why it is worth the effort

Operators increasingly favor vendors who make security easy to verify. Being organized about it can become a competitive advantage in bids, not just a cost.

Ironfield Cyber helps energy contractors assemble security documentation, close technical gaps and respond to customer questionnaires. If you have received a new set of security requirements from an operator, we can help you work through them.