Back to main siteBack Contact us
A steel pipeline running across open grassland at dawn
SecurityGate.io logo
SecurityGate.io for TSA Security Directives

Pipeline security directives, answered with evidence instead of effort

Since 2021, pipeline operators have had to prove their OT cybersecurity to the TSA every year. SecurityGate.io turns that proof into a repeatable assessment program across every station, terminal and control room.

Talk to an OT Specialist Built for OT, not adapted from IT
How we got here

One IT breach changed the rules for every pipeline

In May 2021, ransomware hit the business network of Colonial Pipeline, the largest refined fuel pipeline in the United States. The attackers never touched the pipeline controls, yet the operator shut the line down for several days because it could not be sure the OT side was safe.

The lesson for regulators was blunt: separation between IT and OT had to be proven, not assumed. Security directives followed within weeks.

Yellow valve wheels on steel pipes at a compressor station
  1. May 2021

    Ransomware reaches the business network

    Operations are halted as a precaution. Fuel supply along the East Coast is disrupted.

  2. May 2021

    First TSA directive

    Operators must name a cybersecurity coordinator, report cybersecurity incidents to CISA, and review their current practices against guidance.

  3. July 2021

    Second directive series begins

    Mandatory mitigation measures for designated pipeline owners and operators, focused on OT.

  4. 2022 onward

    Performance-based requirements

    The directive is reissued in performance-based form and renewed each year, with an implementation plan and an annual assessment plan submitted to TSA.

  5. Every year

    Prove it again

    Assessment results, remediation status and evidence have to be current each cycle, across every in-scope site.

The response

Your annual assessment cycle, before and after

The same directive obligations, handled two ways. The difference is not the effort of one assessment. It is whether next year starts from zero.

StageSpreadsheet programOn SecurityGate.io
Assess each siteConsultant visits, questionnaires emailed around, answers pasted together.Directive-aligned assessments run remotely per site, with evidence attached to each answer.
Find the gapsGaps listed in a report that is out of date by the time it is approved.Controls are mapped to threats and impact automatically, so priorities are visible at once.
Fix and verifyAction items tracked in email and meeting notes.Remediations assigned with owners and due dates, then validated before they close.
Report to TSA and leadershipWeeks of assembling slides and appendices.Board-ready reporting by site, function and geography, current at any moment.
Next yearStart again.Re-run the same assessment and compare against last cycle.
What the directives ask for

Four outcomes you must be able to show

The performance-based directives describe outcomes rather than products. Each one needs to be assessed at every in-scope site and documented in a way an inspector can follow.

Segmentation

OT keeps running safely even if the IT network is compromised.

Access control

Only authorized people and systems reach critical cyber systems.

Monitoring and detection

Threats and anomalies on critical systems are detected and acted on.

Patching and hardening

The risk from unpatched systems is reduced on a defined timeline.

Operators also maintain a cybersecurity incident response plan and an assessment program that tests whether these measures work.

The capability behind it

Built for distributed, hard-to-reach assets

Remote by design

Compressor stations, pump stations and terminals are assessed without sending a team to each one, and without disrupting operations.

Suppliers in the same loop

Integrators and service providers with access to your OT answer the same questions on the same platform through third-party risk assessments.

Open to your tools

An open API, plus integrations such as Tenable and Atlassian cloud products, keeps remediation where your teams already work.

With your IT provider

your IT provider sets up your in-scope sites, runs the first directive assessments with your operations team, and keeps the remediation and reporting cycle moving so each annual submission builds on the last.

Next cycle

Make this year's directive assessment the last one you build from scratch

Directive history per TSA public announcements. Vendor figures per securitygate.io, September 2026.

Plan Your Next Assessment Cycle

Get in touch with Your Company

Questions about this solution? Reach us directly.