Skip to content
November 11, 2024

TSA’s Proposed Cybersecurity Rule for the Transportation Sector – The Need for Penetration Testing

The TSA’s proposed rule puts pipeline, rail, and bus operators under real cybersecurity obligations. What it asks for, and where testing fits the requirements.

Brackish Security2 min read

In an era where cyber threats are increasingly sophisticated, the Transportation Security Administration (TSA) has proposed a new set of cybersecurity requirements targeting the pipeline, rail, and over-the-road bus (OTRB) sectors. This Notice of Proposed Rulemaking (NPRM) aims to strengthen protections for critical infrastructure by mandating a comprehensive Cyber Risk Management (CRM) program for certain transportation operators.

Why TSA's Rule Emphasizes Cybersecurity in Transportation

The importance of this rule became evident after the 2021 ransomware attack by DarkSide, a Russian cybercriminal group, which disrupted operations of a major pipeline and caused significant economic and operational fallout. This incident underscored the vulnerability of the transportation sector to cyber threats. TSA responded by issuing Security Directives (SDs) that called for immediate action to protect critical systems in surface transportation, targeting both cybersecurity and physical security vulnerabilities.

As seen here, this rule proposes:

Brackish Can Help Meet TSA's Requirements

Penetration testing is essential in helping transportation operators meet TSA's CRM requirements. Through penetration testing, operators can identify hidden vulnerabilities and proactively address potential risks in their systems.

In addition to penetration testing, our attack surface monitoring tool, Pincher, provides ongoing visibility into an organization’s external-facing assets. Pincher continuously scans and monitors for potential exposures or misconfigurations across an organization’s digital footprint, helping to identify vulnerabilities as soon as they appear. By leveraging Pincher alongside penetration testing, operators can adopt a comprehensive, proactive approach to their cybersecurity posture.

Pincher supports compliance with TSA's requirements by:

Enabling Real-Time Monitoring: Pincher provides timely insights into an organization's attack surface, allowing for swift action on identified vulnerabilities and maintaining the integrity of Critical Cyber Systems.

Providing Actionable Alerts: With Pincher, operators receive real-time alerts on potential security issues, helping ensure a rapid response to newly identified risks.

Please reach out to us if you have any questions. Let's Make the Bad Guys Salty!

Want this tested against your environment?

Reading about an attack path is not the same as knowing whether yours holds. We can tell you which it is.

Scope an engagement