Hogan Lovells 2024 Election Impact and Congressional Outlook Report
On 2 December 2021, the United States Transportation Security Administration (TSA) released two Security Directives applicable to the rail industry that will require certain owners and operators to implement new cybersecurity measures. The directives go into effect on December 31, 2021 and will expire on December 31, 2022. And TSA plans to engage in rulemaking in 2022 to augment these cybersecurity requirements. The directives follow similar cybersecurity-focused directives issued earlier this year for pipeline companies, and further underscore the focus by TSA and the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) on prescribing specific cybersecurity requirements on industry to protect critical infrastructure.
The first directive, “Enhancing Public Transportation and Passenger Railroad Cybersecurity,” applies to owners or operators of passenger railroad or rail-transit systems, while the second directive, “Enhancing Rail Cybersecurity,” applies to freight railroad carriers. Both directives require owners and operators to undertake the following four critical actions:
Pursuant to the directives, any information submitted by owners and operators may be shared among TSA, CISA, the National Response Center, and other agencies, as appropriate. TSA also issued an Information Circular recommending (but not requiring) that owners and operators not covered by either of the Security Directives take the same actions to enhance cybersecurity.
As companies continue to take a hard look at their own cybersecurity readiness, TSA has turned its focus to the rail sector to make sure it is up to the task. The TSA’s cybersecurity focus on the transportation sector is an outgrowth of the Colonial Pipeline ransomware incident, which underscored potential cybersecurity vulnerabilities in the nation’s critical infrastructure. TSA’s recent efforts to increase cybersecurity-readiness for the pipeline sector have resulted in new compliance initiatives that have led to numerous pipeline companies spending thousands of hours and millions of dollars upgrading, updating, and upscaling their cybersecurity protections.
Hogan Lovells — through its industry-focused, intermodal, and well-fused teams of multi-disciplined practitioners — has been helping clients navigate TSA's new cybersecurity directives since before they were released. To date, Hogan Lovells has assisted numerous large and small infrastructure clients to overcome compliance challenges. Hogan Lovells lawyers are well-positioned to do so because they have one-on-one connections with TSA as well as other key government actors (including in law enforcement and cyber leadership) and know the world of cybersecurity intimately. From circuits to servers, from nation-state attacks to ransomware, and from workstation protections to tabletop exercises to board-level decisions, Hogan Lovells lawyers have extensive experience with cybersecurity issues and TSA's cyber regime. And we know the transportation sector and how it works. We can bring that experience to assist our rail clients tackle the latest cybersecurity challenges and anticipated regulations.
Authored by Emily Kimball, Andrew Lillie, Sophie Baum, and Paul Otto.