Following a series of cyberattacks targeting the aviation sector, including ransomware and foreign state-sponsored espionage, the Transportation Security Administration (TSA) issued an emergency amendment in March 2023. This rule required certain large airports to implement specific cybersecurity measures, such as identifying critical systems and submitting implementation plans, without the usual notice-and-comment period. The Spokane Airport Board challenged the rule, arguing the TSA lacked the statutory power to regulate cybersecurity, that the rule conflicted with existing regulations, that it bypassed required oversight by the Transportation Security Oversight Board, and that the rule was arbitrary and capricious. The TSA rejected the Board's objections during reconsideration, leading to this petition for review in the D.C. Circuit.
Circuit Judge Rao, writing for the panel, addressed the petitioner's arguments in two phases: exhaustion and merits. First, the court applied the strict exhaustion requirements of 49 U.S.C. § 46110(d), which bars objections not raised in the administrative proceeding unless there is a reasonable ground for the failure. The court found that Spokane waived arguments regarding the rule's inconsistency with regulations, the lack of ratification by the Transportation Security Oversight Board, and the specific procedural requirements for amending security programs because these were not raised before the TSA. On the merits, the court rejected the claim that the TSA lacked statutory authority. Citing the Aviation Transportation Security Act, the court noted Congress vested the TSA with broad authority to assess threats and develop policies for transportation security, which explicitly includes cyberattacks. The court also found the rule was not inconsistent with regulations, as the term 'includes' in the relevant code section is defined as 'includes but is not limited to,' allowing the TSA to add cybersecurity measures. Finally, the court applied the 'arbitrary and capricious' standard, concluding that the TSA reasonably explained the threats posed by cyberattacks and the necessity of the new controls. The court found the TSA's decision to require rapid improvements and limit flexibility for large airports was a reasonable judgment to address national security risks.
The TSA's emergency cybersecurity amendment remains in full force and effect. Airport operators must continue to comply with the requirements to identify critical systems and submit cybersecurity implementation plans. The decision clarifies that the TSA's emergency rulemaking authority extends to cybersecurity and that courts will not entertain challenges to TSA rules on grounds that were not first presented to the agency. The ruling leaves open the question of whether the TSA will modify its approval process for future security plan improvements, as the agency indicated it might consider changes if the current process impedes necessary cybersecurity work.
Podcast (federal-narrative-summaries): Play in new window | Download
