TSA mandates new cybersecurity guidelines for railroads

Directive focuses on performance-based measures to prevent digital-related disruptions

(Photo: Shutterstock/TierneyMJ)

The Transportation Security Administration is requiring U.S. freight and passenger railroads to comply with a new cybersecurity directive aimed at protecting the rail networks from harm.

The directive focuses on performance-based measures, according to TSA, and “will further enhance cybersecurity preparedness and resilience for the nation’s railroad operations.”

To safeguard against any cyber-related disruptions or degradations to rail infrastructure, TSA is requiring freight and passenger rail carriers to:

  • Develop network segmentation policies and controls to ensure operations can continue to operate safely in the event that IT systems have been compromised.
  • Secure and prevent unauthorized access to critical cyber systems through access control measures.
  • Build and implement monitoring and detection policies and procedures that would detect cybersecurity threats and correct anomalies that would affect critical cybersystem operations.
  • Utilize security patches and updates for operating systems, applications, drivers and firmware on critical cyber systems using a risk-based methodology.  
  • Establish an executive a cybersecurity implementation plan that describes how rail carriers expect to meet the TSA security directive. The plan must be approved by the TSA.
  • Establish a cybersecurity assessment program to test and audit the effectiveness of measures while also identifying and resolving potential vulnerabilities within devices, networks and systems. 

Industry stakeholders and federal agencies, including the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency and the Federal Railroad Administration (FRA), provided input as TSA developed the directive.

“The nation’s railroads have a long track record of forward-looking efforts to secure their network against cyberthreats and have worked hard over the past year to build additional resilience,” TSA Administrator David Pekoske said in a news release. “And this directive, which is focused on performance-based measures, will further these efforts to protect critical transportation infrastructure from attack.” 

According to the Association of American Railroads (AAR), the directive institutionalizes and builds upon existing industry practices. Since 1999, AAR’s rail information security committee has been helping the industry coordinate and share cybersecurity information. 

“There is no higher priority for the rail industry than the safety and security of our national network,” AAR President and CEO Ian Jefferies said. “For more than two decades, the industry has been a leader at bringing the right people and information together to address evolving cyberthreats. Collaboration between railroads and government partners on these issues has a long, productive history that will continue to maintain and advance the smart, effective solutions to keep our network safe and freight moving. We appreciate the [TSA]’s efforts on these important issues.”

In addition to announcing the directive Tuesday, TSA said it plans to begin a rulemaking process to establish regulatory requirements for the rail sector on these cybersecurity measures. That process will include a public comment period.

This new directive builds upon an existing older one that required the railroads to report significant cybersecurity incidents to the federal government, establish a cybersecurity point of contact, develop and adopt a cybersecurity incident response plan and complete a cybersecurity vulnerability assessment. 

Subscribe to FreightWaves’ e-newsletters and get the latest insights on freight right in your inbox.

Click here for more FreightWaves articles by Joanna Marsh.

Upcoming FreightWaves Events
Compliance

Brokerage Compliance Symposium

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Awards

F3 Awards Dinner

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
FreightTech

F3: Future of Freight Festival

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

October 27, 2026 – October 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Compliance Brokerage Compliance Symposium Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
Awards F3 Awards Dinner Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
FreightTech F3: Future of Freight Festival Oct 27 – Oct 28 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now

Joanna Marsh

Joanna is a Washington, DC-based writer covering the freight railroad industry. She has worked for Argus Media as a contributing reporter for Argus Rail Business and as a market reporter for Argus Coal Daily.