In recent years, the U.S. government has prioritized increasing cybersecurity in sectors that are critical to the country, most especially railway. This focus intensified after the ransomware attack on the Colonial Pipeline, a major fuel pipeline, which caused significant gas shortages and highlighted the need to protect U.S. infrastructure. In response to this threat, officials have emphasized the importance of strengthening the security of these industries.
In March 2022, President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). This law applies to agencies, organizations, and businesses whose service disruptions could harm economic security or public health and safety. Railways are one of the industries that are considered critical infrastructure under this act.
Railways have been the subject of several major attacks in recent years, including a data breach at China Railways (CR) in 2019 and breaches of 146 million records in the database of Network Rail and service provider C3UK, as well as a malware attack on Sadler, a railway equipment manufacturer. In October, President Biden released the Enhancing Rail Cybersecurity Directive from the Transportation Security Administration for critical infrastructure, which includes directives for railway companies.
TSA administrator David Pekoske said, “The nation’s railroads have a long track record of forward-looking efforts to secure their network against cyber threats and have worked hard over the past year to build additional resilience, and this directive, which is focused on performance-based measures, will further these efforts to protect critical transportation infrastructure from attack.”
The new directive includes four main requirements:
The directive requires railways to identify any weaknesses in their cybersecurity and document steps to fix these issues through an assessment. This assessment must be completed within 90 days of the directive.
Here at CourseMonster, we know how hard it may be to find the right time and funds for training. We provide effective training programs that enable you to select the training option that best meets the demands of your company.
For more information, please get in touch with one of our course advisers today or contact us at training@coursemonster.com