The Surface Transportation Board regulates freight rail rates, oversees railroad mergers, and adjudicates disputes over who gets to run trains through whose backyard. It is a small, obscure independent agency that most Americans have never heard of and will never have reason to contact. It is also, according to its own contracted auditor, an agency that cannot hold onto basic cybersecurity discipline for more than twelve consecutive months.
Every year since at least 2017, the Department of Transportation’s Office of Inspector General has hired Williams Adley & Company to run STB through the federal government’s standard information security checkup, the one required by the Federal Information Security Modernization Act. Every year, the verdict has been the same word, ineffective. What makes the fiscal year 2026 report interesting is not that STB failed again. It is that STB had, for one brief shining reporting period, actually started to look like it was getting its act together, and then visibly did not.
A Small Agency’s One Good Year
To understand FY2026’s regression you first have to see the year it regressed from. The FY2025 audit reads almost warmly by federal oversight standards. Williams Adley wrote that STB “made improvements, since the previous reporting period” and closed five of nine outstanding recommendations. Identity and access management jumped to a calculated 3.67, edging into “Managed and Measurable” territory, the top tier the government considers genuinely effective. STB’s business impact analyses, the documents that are supposed to tell an agency which systems it absolutely cannot afford to lose, went from Level 3 to Level 4. Contingency plan testing for its two core systems, the General Support System and the Dynamic Case Management System, actually happened, complete with after-action reports. Management’s own response practically glowed, welcoming an audit that showed the program “continues to improve, year over year.”
None of that survived contact with FY2026.
The Metrics That Fell Off a Cliff
The new report documents four specific reporting metrics that regressed in maturity level from the prior year, not stagnated, regressed. Business impact analyses fell from Level 4 to Level 2. Contingency plan testing fell from Level 3 to Level 2, because STB simply did not run the required annual exercises for any of its three in-scope systems this time, not the General Support System, not the case management platform, not even its Amazon Web Services environment. Cybersecurity risk management strategy dropped from Level 3 to Level 2 because two of four sampled Risk Acceptance Forms, the paperwork documenting known vulnerabilities STB has formally decided to live with, expired without anyone bothering to renew, reassess, or justify them. And identity authentication for ordinary, non-privileged users cratered from Level 4 all the way to Level 2.
That last one is worth sitting with, because it is not an abstract maturity-model score, it is a paperwork failure with a name, the Personal Identity Verification exception process. STB employees are supposed to log in using PIV cards, the standard federal smart-ID credential mandated since a 2004 Bush-era directive. Some employees get exceptions, for legitimate reasons like a malfunctioning card or a pending new-hire issuance. Auditors sampled seven such exceptions. Four had no documented justification for being on the list at all. Three belonged to users who had working PIV cards and valid certificates the whole time, meaning STB’s own systems knew these people didn’t need an exception and left them on it anyway. This is not a resourcing problem in the abstract sense STB’s management response keeps invoking. It is a report nobody ran.
STB’s Own Explanation, and Its Limits
To its credit, STB does not dispute any of this. Managing Director Rachel Campbell’s response concurs with all four new recommendations and does not contest a single finding, which is more candor than some agencies manage. The explanation offered, repeated almost verbatim across domain after domain in the report, is resource constraints, budget reductions, limited personnel, competing workload demands. Auditors accepted this at face value and built it directly into the recommendation language itself, asking STB to “evaluate the impact of resource constraints” rather than simply fix the underlying control.
There is something almost structurally convenient about that framing. A recommendation to study your own resource constraints and develop an action plan is not the same as a recommendation to actually restore PIV enforcement or run a contingency test. It buys another reporting cycle. It is worth noting that STB’s Data Protection and Privacy, Configuration Management, and Incident Response domains all held roughly steady this year, meaning the agency did not lose ground everywhere, only in the specific places where somebody has to remember to do a recurring task on a calendar. Inventory maintenance stayed strong; supply chain risk management stayed flat and mediocre at Level 2 for two straight years, the one condition that has been open long enough it barely counts as news anymore.
Nine Years Is a Long Time to Draft an Architecture Document
The most damning artifact in either report is not a new finding at all. It is recommendation 2021-1, first issued in fiscal year 2021, calling on STB to develop an enterprise architecture that actually incorporates information security into its planning. It was still open in FY2025. It is still open in FY2026. STB’s own target completion date for finally addressing it is now June 30, 2029, eight years after the recommendation was written, for a document. Recommendation 2024-9, about implementing federal logging requirements, took a different and stranger path to closure: the underlying OMB memorandum it was based on got rescinded and replaced by newer guidance before STB ever complied, so Williams Adley simply marked it closed as moot. STB didn’t fix the problem. The problem changed definitions out from under it.
Put the two years side by side and the shape of the story becomes obvious. This is not an agency in crisis, and it is not an agency that has never tried. It is a small regulator with a demonstrably competent core, evidenced by real jumps in maturity when it applies itself, that cannot sustain that application from one fiscal year to the next once attention moves elsewhere. The PIV exception list did not get worse because someone at STB made a bad decision. It got worse because nobody checked it. For an agency whose entire regulatory mission rests on making sure railroads keep their paperwork current and their safety obligations honored, there is a certain grim symmetry in watching it fail the same test on itself, twice in two years, in opposite directions.
