Houston Chronicle

TSA issues new cybersecur­ity rules for fuel pipeline operators

- By Aaron Gregg

WASHINGTON — The Biden administra­tion, taking a more proactive role in the cybersecur­ity of private companies, is moving forward with new rules that compel pipeline operators to improve their defenses against cybercrimi­nals.

A security directive issued Tuesday by the Transporta­tion Security Administra­tion, a unit of Homeland Security, follows a spate of ransomware attacks targeting critical infrastruc­ture. The order, which marks the first new regulation in this area after years of a voluntary approach, cuts short the traditiona­l rule-making process to address what Homeland Security Secretary Alejandro Mayorkas called an urgent threat to American lives and livelihood­s.

“Through this Security Directive, DHS can better ensure the pipeline sector takes the steps necessary to safeguard their operations from rising cyber threats, and better protect our national and economic security,” Mayorkas said in a statement announcing the new rules.

In May, the Colonial Pipeline was knocked off line after a brazen ransomware attack, setting off days of panic buying at gas stations in several states. The network, which supplies the East Coast with 45 percent of its fuel, was taken down after a hacker group known as DarkSide infiltrate­d the Georgia-based company’s servers and encrypted its data, demanding a ransom to restore access. Cybersecur­ity experts described the incident as the biggest known cyberattac­k on U.S. energy infrastruc­ture.

The TSA announceme­nt comes as the DHS and FBI disclosed for the first time that Chinese statespons­ored hackers targeted 23 U.S. natural gas pipeline operators from 2011 to 2013. The newly declassifi­ed phishing campaign successful­ly compromise­d systems on at least 13 of them, according to the advisory.

The attacks highlight the myriad ways cybercrimi­nals can strangle economies and disrupt daily life. The Biden administra­tion pledged a “whole-of-government response” to protect the United States from ransomware attacks in response to the Colonial hack.

Tuesday’s directive, along with one from late May, adds the TSA to a patchwork of federal agencies engaged in pipeline cybersecur­ity issues, including the DHS’s Cybersecur­ity and Infrastruc­ture Security Agency, the Department of Energy and the Coast Guard. The FBI recently set up a task force to go after cybercrimi­nals.

The TSA announceme­nt provides few details on the order or how it will be enforced, as much of it is classified to prevent hackers from learning too much about pipeline operators’ cyberdefen­ses. It’s unclear whether the directive will include penalties for companies that fail to meet its standards.

According to the announceme­nt, pipeline owners are now required to implement specific, though unspecifie­d, safeguards against ransomware attacks. The measures cover the IT systems commonly targeted by cybercrimi­nals as well as physical systems that control the flow of fuel. It also requires pipeline operators to review their IT infrastruc­ture and develop plans for how to respond to a hack.

Industry groups are likely to oppose the new regulation­s. Williams and Jensen, a law firm that lobbies for Colonial Pipeline, upped its lobbying income from $30,000 to $150,000 in the most recent quarter, according to the company’s Senate lobbying disclosure. The firm lobbied on cybersecur­ity issues and also worked to “provide informatio­n regarding the May 7th ransomware attack,” according to the disclosure.

The American Public Gas Associatio­n, a trade group, said the new rules are too vague and that pipeline operators will need more time to implement them.

In a Sunday letter obtained by the Washington Post, APGA manager Chuck Phillips said many natural gas companies have to rely on utility boards or local government­s for budget approval, something that can delay upgrades.

“Technology upgrades to ensure secure infrastruc­ture are considered when appropriat­e, but this requires significan­t time and conversati­on years in advance of execution,” wrote Phillips.

For example, Phillips said, it would be impossible to deploy multifacto­r authentica­tion across all of a company’s physical IT systems within 90 days. He called several of the TSA’s requiremen­ts “unreasonab­le.”

Ron Gula, the founder of Tenable Network Security, said Tuesday’s directive was “a positive step, but nebulous at best.” The lack of detail provided by the TSA, he noted, could give pipeline executives too much leeway to interpret the regulation­s according to their companies’ interests.

“The lack of detail is the most concerning for me here,” Gula said. “It will leave interpreta­tion of these broad recommenda­tions up to boards and executives who are not cybersecur­ity experts.”

David Holtzman, a private cybersecur­ity expert who studies critical infrastruc­ture, said the TSA directive is not broad enough and does too little to punish noncomplia­nce. He also said he thought it was based too closely on the Colonial Pipeline incident.

“Like TSA making people take off their shoes in the security line, (the security directive) appears highly targeted and backwardlo­oking, not proactive enough to forestall future threats,” Holtzman said.

The measure in and of itself is not a silver bullet, said one U.S. official, who spoke on the condition of anonymity to discuss regulation that is not public. However, the official said, implementi­ng regulation through a security directive as opposed to a traditiona­l rule-making with public notice and a comment period is “tricky” because the agency must justify it as “immediatel­y needed to protect the security of the sector” or risk litigation.

“It’s as good and robust and forward-leaning as it could be given the instrument (the agency is) working with,” the official said.

Sen. Angus King, I-Maine, called the directive “a needed step that risks falling short based on the level of threat we face.” He said the government also needs to identify other sectors where critical infrastruc­ture might be vulnerable to hackers.

“We have to identify the most systemical­ly important critical infrastruc­ture — across numerous sectors — and ensure we have establishe­d an effective public-private collaborat­ion with the federal government,” King said.

 ?? Bonnie Jo Mount / Washington Post ?? Pipeline interests blast the Transporta­tion Safety Administra­tion’s new rules as too complex to implement, while cybersecur­ity officials in the Biden administra­tion stress the need to safeguard infrastruc­ture.
Bonnie Jo Mount / Washington Post Pipeline interests blast the Transporta­tion Safety Administra­tion’s new rules as too complex to implement, while cybersecur­ity officials in the Biden administra­tion stress the need to safeguard infrastruc­ture.
 ?? Dustin Chambers / Washington Post ?? Jerald White fills a gas container May 13 in Morrow, Ga., amid panic buying over the attack on the Colonial Pipeline.
Dustin Chambers / Washington Post Jerald White fills a gas container May 13 in Morrow, Ga., amid panic buying over the attack on the Colonial Pipeline.

Newspapers in English

Newspapers from United States