• videocam On-Demand Webinar
  • signal_cellular_alt Intermediate
  • card_travel Commercial Law
  • schedule 90 minutes

Railroads and Cybersecurity Risk Management Requirements: Preparing for Implementation of TSA’s 2024 NPRM

TBD

About the Course

Introduction

This CLE webinar will discuss the Transportation Security Administration's (TSA) Notice of Proposed Rulemaking (NPRM) entitled Enhancing Surface Cyber Risk Management. The program will help those who counsel transportation entities subject to the regulations, including railroad owners, operators, and suppliers, to assess gaps between the rule's requirements and their current cybersecurity programs so they can plan how to meet the new standards.

Description

The rail industry has become increasingly digital and interconnected, which opens the door for hackers to exploit vulnerabilities in railroad systems as well as through suppliers and vendors to the industry. Beginning after the 2021 Colonial Pipeline ransomware incident, TSA used its emergency powers to issue, without notice and comment, a series of mandatory "directives" requiring railroad and other infrastructure entities to implement various cybersecurity measures. Then on Nov. 6, 2024, TSA issued an NPRM to permanently codify and expand the five previous directives.

When final, the rule is expected to impact almost 300 transportation entities: 73 freight railroads that move 94% of the rail freight in the U.S., 34 rail transit and passenger railroads, including Amtrak, and certain pipeline and over-the-road bus (OTRB) operations.

The proposed rule includes cybersecurity requirements developed by the National Institute of Standards and Technology and the Cybersecurity and Infrastructure Security Agency. Higher risk entities, among other things, must establish and maintain a comprehensive cyber risk management program, have enhanced record-keeping and incident reporting obligations, perform continuous cybersecurity monitoring, and designate a physical security coordinator.

Listen as our renowned panel breaks down the NPRM and offers guidance to counsel for railroads and other transit entities on implementing these measures.

Presented By

Attorneying Annie Dc, CPS, DR
Partner
Davis Brown Law Firm - Des Moines

Bio for Annie Attorney; loves horses and arguments

Big Boat
Firm Manager
The Mogy Law Firm - Memphis

This is a bio for Big Boat. Big Boat is an avid reader and unicyclist.

Roller S. Coaster MD, CPA, MST, DR
Fun Times
Lee's Test Firm

This is a bio for speaker, Roller Coaster. Roller Coaster enjoys walks on the beach and pizza with pineapple.

Credit Information
  • This 90-minute webinar is eligible in most states for 1.5 CLE credits.


  • Live Online


    On Demand

Date + Time

  • event

  • schedule

    1:00 p.m. ET./10:00 a.m. PT

I. Brief history of directives and NPRM

A. Objections

B. Grand Trunk, et al v. TSA, et al, ___ F.4th ___ (7th Cir. Aug. 21, 2025)

II. Key provisions for railroads

A. Conducting annual enterprise-wide cybersecurity evaluations

B. Developing a cybersecurity operational implementation plan

C. Establishing a cybersecurity assessment plan

D. Incident notification obligations

III. Compliance and enforcement

IV. Challenges to implementation

A. Legacy equipment

B. Interoperability in the industry

C. Costs

V. Best practices for implementation

The panel will address these and other important issues:

  • How does the NPRM fit in with executive orders on cybersecurity?
  • How different is the NPRM from the prior directives?
  • What can rail organizations do to begin to comply?