Table of Contents
If you would like to quickly book a discovery meeting, please use this calendar link
May 27, 2021
Today, the Department of Homeland Security’s Transportation Security Administration (TSA) announced a Security Directive that will enable the Department to better identify, protect against, and respond to threats to critical companies in the pipeline sector.
“The cybersecurity landscape is constantly evolving and we must adapt to address new and emerging threats,” said Secretary of Homeland Security Alejandro N. Mayorkas. “The recent ransomware attack on a major petroleum pipeline demonstrates that the cybersecurity of pipeline systems is critical to our homeland security. DHS will continue to work closely with our private sector partners to support their operations and increase the resilience of our nation’s critical infrastructure.”
The Security Directive will require critical pipeline owners and operators to report confirmed and potential cybersecurity incidents to the DHS Cybersecurity and Infrastructure Security Agency (CISA) and to designate a Cybersecurity Coordinator, to be available 24 hours a day, seven days a week. It will also require critical pipeline owners and operators to review their current practices as well as to identify any gaps and related remediation measures to address cyber-related risks and report the results to TSA and CISA within 30 days.
Red Trident will design a cybersecurity program for your organization, applicable to midstream as well as the broader oil and gas industry. We start with a Readiness Assessment that identifies process and technical deficiencies our adversaries can exploit. We’ll take the items found and build them into a logical Plan of Action with Milestones to rapidly reduce risk
TSA is also considering follow-on mandatory measures that will further support the pipeline industry in enhancing its cybersecurity and that strengthen the public-private partnership so critical to the cybersecurity of our homeland.
Red Trident works closely with the Federal Government and cybersecurity standards bodies. We are members of Infragard, the Industrial Society of Automation (ISA) and a founding member of the ISA Global Cybersecurity Alliance. Our team has contributed to the American Petroleum Institute Standard 1164 – Pipeline SCADA Security and ISA/IEC 62443 series of Automation Cybersecurity standards. Our expertise will help you get ahead of upcoming regulation.
TSA is also considering follow-on mandatory measures that will further support the pipeline industry in enhancing its cybersecurity and that strengthen the public-private partnership so critical to the cybersecurity of our homeland.
Since 2001, TSA has worked closely with pipeline owners and operators as well as its partners across the federal government to enhance the physical security preparedness of U.S. hazardous liquid and natural gas pipeline systems. As the nation’s lead agency for protecting critical infrastructure against cybersecurity threats, CISA provides cybersecurity resources to mitigate potential risks, including through a dedicated hub that disseminates information to organizations, communities, and individuals about how to better protect against ransomware attacks.
This new TSA Security Directive also highlights the critical role that CISA plays as the country’s national cyber defense center. Last December, Congress, through the National Defense Authorization Act, empowered CISA to execute its mission to secure federal civilian government networks and our nation’s critical infrastructure from physical and cyber threats.
Red Trident is focused on protecting OT, ICS, SCADA, DCS and other embedded systems. We support local, state and federal agencies, as well as enterprises that require our expertise. In 2020, more OT-related vulnerabilities were reported than any prior year. If you would like an assessment of your security posture or a partner in implementing automation or cybersecurity improvements, please contact us at your earliest convenience.