Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Senators Ask DHS, DOT About Transportation Infrastructure Cybersecurity

Several U.S. senators have sent a letter to the Department of Homeland Security (DHS) and the Department of Transportation (DOT), requesting information about the cybersecurity of the nation’s transportation infrastructure.

Several U.S. senators have sent a letter to the Department of Homeland Security (DHS) and the Department of Transportation (DOT), requesting information about the cybersecurity of the nation’s transportation infrastructure.

The letter was signed by 10 republican and democrat senators led by Jacky Rosen (D-NV) and Roger Wicker (R-MS).

The lawmakers want information on the two departments’ capabilities when it comes to detecting, preventing and responding to cyberattacks. Specifically they are seeking information on how the DHS and DOT are meeting their six responsibilities, as described in the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021.

These responsibilities include supporting risk sector management, assessing sector risk, sector coordination, facilitating information sharing, supporting incident management, and contributing to emergency preparedness efforts.

The senators have also requested information on how the two organizations are collaborating in an effort to avoid gaps and redundancies in risk management, as well as on plans to update the Transportation Systems Sector-Specific Plan from 2015, to ensure that it’s in line with the current threat landscape.

The lawmakers have pointed out that cyber threats to transportation systems are expected to increase, and provided the recent Colonial Pipeline incident as an example. Their letter also cites a study conducted last year by the Mineta Transportation Institute, which found that only 60% of transit agencies had a cybersecurity plan in place.

Advertisement. Scroll to continue reading.

“We recognize that DHS and DOT have the complex and enormous responsibility of ensuring the security and resilience of the nation’s transportation systems, supporting the systems’ ability to quickly, safely, and securely move people and goods throughout the country and overseas,” the senators wrote.

The Transportation Security Administration (TSA) in December announced new directives and recommendations aimed at strengthening the cybersecurity defenses of rail and airport operators.

The new directives require most operators to identify a cybersecurity point person, report incidents to CISA within 24 hours, conduct vulnerability assessments, and develop contingency and recovery plans.

Related: Chinese Hackers Spotted Targeting Transportation Sector

Related: Transportation Agency Hacked in 2nd Texas Government Attack

Related: Overcoming Security Challenges in the Transport and Logistics Sector

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.