A US Government Accountability Office report says four of six cybersecurity recommendations the agency made to the TSA since 2018 have still not been addressed
Efforts by the Transportation Security Administration (TSA) to address cybersecurity issues faced significant criticism this week …
Context & Ripple Effects
The finding extends a broader record of federal cyber-program gaps, including a bipartisan Senate investigation into agencies' ineffective cybersecurity programs. It also tests TSA's credibility as a sector overseer after it required critical rail and aviation operators to appoint cyber leaders, report incidents, and prepare recovery plans in its 2021 transportation-sector cyber directive.
First-order effects
- TSA remains accountable for closing four outstanding GAO recommendations dating to 2018, keeping its internal cybersecurity governance and remediation work under scrutiny.
- The report exposes a gap between TSA's cybersecurity expectations for critical transportation operators and the agency's documented progress on its own recommendations.
Second-order effects
- Rail and aviation companies subject to TSA cyber requirements may face a more pointed question from regulators and stakeholders: whether the agency can demonstrate the same control maturity it asks of them.
- GAO findings can sharpen congressional and oversight attention on TSA's implementation capacity, not just on whether new cyber rules are issued.
Third-order effects
- If unresolved recommendations persist, transportation cybersecurity policy risks becoming more compliance-led than assurance-led: mandates may expand faster than agencies can evidence that their own controls work.
- The larger governance test is auditability—whether public-sector cyber programs can turn recurring findings into demonstrable closure rather than repeated oversight cycles.
The trend: This is one data point in the shift from setting cybersecurity obligations for critical infrastructure toward proving, through auditable remediation, that the regulator can meet comparable standards itself.