What a Pipeline Cybersecurity Coordinator is actually responsible for

  • TSA Pipeline Security Directives
  • Cybersecurity Coordinator

Naming a Cybersecurity Coordinator is the easiest box to check on SD Pipeline-2021-01G. Pick a primary, pick an alternate, file the contact details with TSA, done. The designation itself takes an afternoon. The role it creates runs for as long as the directive applies.

What the directive actually requires

SD Pipeline-2021-01G §II.B requires a primary and at least one alternate Cybersecurity Coordinator, designated at the corporate level, with names, titles, phone numbers, and email addresses on file with TSA. At least one of them has to be a U.S. citizen eligible for a security clearance, serving as the principal point of contact for cyber-related intelligence information. If a non-U.S. citizen is designated as primary or alternate, that person has to be a current member of NEXUS, Global Entry, or a comparable vetted-traveler program, and the organization has to have procedures in place so that information restricted to U.S. persons never reaches them. Any change to that information, a new phone number, a role change, a departure, has to be filed with TSA within seven days.

That’s the paperwork. The duty attached to it is heavier: the Coordinator and alternate have to be accessible to TSA and CISA 24 hours a day, seven days a week, including when the federal government itself is closed. This isn’t a title on an org chart. It’s a point of contact TSA expects to be reachable at any hour, which means the person named has to actually be reachable, not just formally designated.

Two consequences follow from that. First, the alternate has to be a real alternate: someone with enough standing and context to act, not a name added to satisfy the letter of the requirement. Second, the contact details have to stay current. A Coordinator who changes phone numbers, changes roles, or leaves the organization without an update filed leaves the requirement technically unmet even though the designation still exists on paper.

What the role does day to day

Beyond 24/7 accessibility, the directive lists three more duties: serve as the primary contact for cybersecurity-related activities and communications with TSA and CISA, coordinate cyber and related security practices and procedures internally, and work with appropriate law enforcement and emergency response agencies. In practice, that internal-coordination duty is the one that determines whether the role works. It requires enough operational authority, or a direct line to someone who has it, to make decisions during an incident without waiting on a chain of approvals that wasn’t built for a live event, and enough fluency in both environments to translate between them: what a SCADA alarm means to an IT-focused analyst, and what a reportable cybersecurity incident means to an OT operator used to thinking in terms of equipment faults, not cyber events.

That’s why the designation works best as an executive-level role, not a delegated one. A Coordinator who has to escalate every decision during an incident is a bottleneck, not a point of contact.

Where this connects to the rest of the program

The Coordinator designation doesn’t stand alone. It’s the first line of the Cybersecurity Vulnerability Assessment and Cybersecurity Implementation Plan process elsewhere in the directives, and it’s usually the first thing confirmed in a TSA audit meeting: is the person on file still the right person, and do they actually know the program. A designation that’s accurate on paper but stale in practice is a finding waiting to happen. It’s also one of the first things worth confirming in preparing leadership for that meeting, not just the Coordinator.

For the full picture of what SD Pipeline-2021-01G and SD Pipeline-2021-02G require together, see the TSA Pipeline Cybersecurity Requirements guide. For what to have on file to prove the designation is current, see the evidence checklist.

Regulatory content in this post reflects the signed SD Pipeline-2021-01G directive. Last verified 2026-09-23.

All posts