You Can't Secure What You Can't See: Why TSA's 2026 Cyber Mandates Made Your EAM System Transit's First Line of Defense

The 2026 Mandate That Changed the Question

Why an OT Asset Inventory Is Really an EAM Problem

The Four Requirements, Mapped to Your Asset Register

Consider how directly each TSA requirement maps to capabilities your EAM already provides. The Cybersecurity Coordinator needs a single authoritative source of truth for what assets exist — that is your asset hierarchy. The Incident Response Plan depends on knowing which assets are affected and what they connect to — that is your asset relationships and location data. The Vulnerability Assessment requires a complete OT inventory with condition and configuration detail — that is your asset register, extended. Even incident reporting to CISA is faster when responders can pull an asset’s full lifecycle and maintenance history in seconds rather than reconstructing it from spreadsheets.

The agencies furthest along are not buying a second platform. They are extending the EAM they already run.

The Hidden OT Assets Your CMMS Already Tracks

Walk any rail agency’s asset register and you will find the exact equipment now in regulatory scope. Interlockings and wayside signal controllers. Traction power substations and third-rail gap breakers. SCADA remote terminal units. Fare gates and ticket vending machines, which are networked endpoints as much as revenue devices. HVAC, fire, and access-control systems in stations and shops. These have always been maintained assets. What is new is that each is now also a regulated cyber asset — and the record that proves you are maintaining it is the same record that proves you can see it.
 
This is also where the reliability case and the security case stop competing for budget. A signal asset that is well-documented for maintenance is, almost by definition, well-documented for cyber. The data quality you need for one is the data quality you need for the other.

What the $2.1 Billion Compliance Bill Actually Buys

The cost estimates should focus the mind. TSA projects that mid-sized operators will incur average annual costs exceeding $1 million to comply, while smaller short-line and regional operators may see roughly $100,000 per year. Much of that spend goes to building and maintaining exactly the inventory and configuration data that a mature EAM already holds.

For agencies still tracking critical OT in spreadsheets and tribal knowledge, the bill will be larger and the audit risk higher. For agencies that have invested in a clean asset register, much of the compliance work is a configuration project, not a greenfield build. The convergence does not eliminate the cost, but it can sharply reduce the duplicated effort — and it produces one defensible system of record instead of two that disagree.

Lessons From SFMTA, TTC, and SEPTA

Transit does not have to imagine the consequences of poor OT visibility; it has already lived them. In November 2016, ransomware crippled the San Francisco Municipal Transportation Agency, locking roughly 900 to 2,000 workstations and forcing the agency to open fare gates and offer free rides while it recovered. Toronto’s TTC was hit by ransomware in October 2021, and SEPTA in Philadelphia suffered a disruptive attack in August 2020. In each case, the organizations most able to respond were those that knew precisely which systems were affected and how they connected. The ones that struggled were reconstructing their own environments under pressure — discovering their inventory during the incident rather than before it.

The lesson regulators drew is the lesson EAM has taught for years: visibility purchased in advance is cheap; visibility purchased during a crisis is ruinous.

The Audit Trap: When Self-Reported Data Isn’t Verified

There is a second, quieter risk in 2026, and it also runs through asset data. In December 2025, the DOT Office of Inspector General reported that the Federal Transit Administration had not independently verified agencies’ self-reported transit asset management performance data before awarding Capital Investment Grants. The OIG found the progress requirement was treated as not applying to 5 of 19 grants it reviewed — roughly $7.3 billion, more than half the funds awarded between January 2023 and January 2025. Separately, GAO’s report GAO-25-107947 concluded that while TSA is taking steps on surface cybersecurity, additional actions are still needed.

The throughline is unmistakable. Whether the auditor is checking your funding eligibility or your cyber posture, unverified, self-reported asset data is now a liability. A system of record that produces a defensible, timestamped audit trail is no longer a nice-to-have. It is the difference between passing an inspection and explaining one.

A Convergence Playbook for 2026

 

Agencies that want to turn this mandate into an advantage can start with five concrete moves. First, declare the EAM the single system of record for OT assets, and stop maintaining parallel security spreadsheets. Second, extend your asset schema with the cyber-relevant attributes — firmware, network segment, patch status, end-of-support date — so a maintenance update and a cyber update become the same transaction. Third, integrate passive OT discovery tools such as Claroty, Cylus, or Dragos to feed newly detected devices straight into the asset register rather than into a separate console. Fourth, wire your incident response plan to pull asset relationships and history directly from the EAM, whether you run IBM Maximo, Octave Attune EAM, or another platform. Fifth, treat data quality as a compliance control, with the same verification rigor the OIG now expects of grant reporting.

Where to Start

Discover more from 21Tech

Subscribe now to keep reading and get access to the full archive.

Continue reading