Air Freight News

Railroads committed to vigilance against cyber threats & collaboration with government partners

Dec 03, 2021

The Transportation Security Administration (TSA) issued two Security Directives that mandate cybersecurity actions by passenger railroads and rail transit agencies and freight railroads, respectively. Since Secretary Mayorkas’ October announcement that TSA would issue such directives, AAR and the rail industry have had productive consultations with agency officials to revise provisions that would have posed challenges in implementation. With the final directives released today, a number of the industry’s most significant concerns have been addressed.

“For the better part of two decades, railroads have thoughtfully coordinated with each other and government officials to enhance information security, which has proven to be an effective, responsive way of addressing evolving threats,” said AAR President and CEO Ian Jefferies. “Let there be no mistake — railroads take these threats seriously and value our productive work with government partners to keep the network safe.”

Specifically, the Security Directives mandate four categories of actions:

  • Appointment of a primary and alternate Cybersecurity Coordinator with TSA
  • Reporting of cybersecurity incidents to the Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA)
  • Completion of a cybersecurity self-assessment using a form provided by TSA
  • Development and implementation of a Cyber Incident Response Plan

Every Class I railroad and Amtrak, as well as many commuter and short line carriers, have chief information security officers and cybersecurity leads who will serve as the required Cybersecurity Coordinators. Further, railroads have conducted cybersecurity assessments on a recurring basis and have developed, exercised and applied Cyber Incident Response Plans. Through the AAR’s Railway Alert Network (RAN), railroads have been reporting significant cyber threats, incidents and security concerns to TSA, DHS and the Department of Transportation (DOT) since 2014. AAR does note that an unresolved issue is the appointment of cybersecurity coordinators by railroads headquartered in Canada and will work with TSA and its Canadian members to resolve that issue.

Similar Stories

https://www.ajot.com/images/uploads/article/Freightliner-loco-transporting-intermodal-containers_copie.jpg
Intermodal industry honors Niness with 2026 Silver Kingpin Award
View Article
https://www.ajot.com/images/uploads/article/Red_Canadian-National-Train.jpg
CN reports new monthly record for propane shipments to Watson Island
View Article
https://www.ajot.com/images/uploads/article/Mike_Riccio_1.JPG
Open Road Ventures acquires intermodal freight broker Double-Stack Logistics 
View Article
https://www.ajot.com/images/uploads/article/AARailroad.jpeg
AAR reports rail traffic for the week ending May 30, 2026
View Article
https://www.ajot.com/images/uploads/article/Joey_Evans.jpg
TNW Corporation names Blank, Evans and Klun to new leadership roles
View Article
CN reports May grain movement

CN announced today that in May it moved over 2.96 million metric tonnes (MMT) of grain from Western Canada, surpassing the previous monthly record of 2.54 MMT set in May…

View Article