Aviation security is going all-hazards. TSA Act 2025 puts cyber inside it.
As a critical aviation asset, rail freight operator, freight infrastructure holder, or logistics technology platform, you sit inside a rapidly tightening regulatory stack. Aviation remains regulated under ATSA rather than the SOCI CIRMP — and the TSA Act 2025 brings aviation and maritime transport into an all-hazards framework explicitly including cyber. Rail signalling and Positive Train Control systems are increasingly IP-converged. Freight platforms are the exact shared networks Supply Chain 24/7 identified as the target shift.
Your specific challenges
Cyber is coming into aviation scope
Aviation security sits under the Aviation Transport Security Act, not the SOCI CIRMP regime. The Transport Security Amendment (Security of Australia's Transport Sector) Act 2025 layers an all-hazards framework — including cyber — into ATSA's subordinate regulations over the next 12–24 months.
Rail signalling and PTC are IP-connected now
Signalling networks originally designed for air-gapped safety are now IP-converged. Positive Train Control, passenger information systems, and ticketing platforms share the same corporate connectivity assumptions as general IT — but carry safety-critical consequences.
Shared networks are the attack surface
Supply Chain 24/7: "Hackers are moving away from hitting individual companies and instead going after shared transportation networks." Freight booking platforms, port community systems, customs interchange systems — shared platforms with cascade reach.
Built for your situation
CIRMP cyber-hazard evidence for aviation and freight
NodeZero maps to your chosen CIRMP cyber framework — Essential Eight, NIST CSF, ISO 27001, AESCSF. Findings feed the Board-approved annual CIRMP report within 90 days of the end of the financial year.
Segmentation validation for rail and passenger systems
Segmentation Testing validates whether signalling and PTC networks are actually isolated from corporate IT; Web App Pentesting covers passenger-facing services, ticketing, and information displays.
Platform cascade testing for logistics tech
External Pentesting, Cloud Pentesting, and Web App Pentesting validate the exact shared-network attack surface Supply Chain 24/7 flagged — TMS, WMS, freight booking, port community systems, customs platforms.
Prepare for TSA Act 2025 and CIRMP annual reporting
Book an aviation, rail, or freight baseline mapped to your chosen CIRMP framework and the TSA Act 2025 cyber component