Monday, August 3, 2026

Review - S 4395 Introduced – TRIA Reauthorization

Back in April, Sen McCormick (R,PA) introduced S 4395, the Terrorism Risk Insurance Program Reauthorization Act of 2026. This is a ‘clean’ reauthorization bill that extends the program through December 31st, 2034, and makes similar extensions of the federal recoupment dates. No new funding is authorized by this bill.  

I can find no legislation in the 118th Congress that would appear to be similar to S 4395. There is, however, a bill introduced in the House this session that would appear to be similar, HR 7128, the TRIA Program Reauthorization Act of 2026. That bill was introduced by Rep Flood (R,NE) in January of 2026. The House Committee on Financial Services held a business meeting later in January that included a markup of HR 7128. Four amendments were offered and rejected by the Committee, which subsequently approved alternative language by a voice vote. On June 29th, 2026, the House took up HR 7128 under the suspension of the rules process and passed the bill by a bipartisan vote of 373 to 15 (all Nay votes were from Republicans). No action has yet been taken in the Senate. 

Moving Forward  

McCormick is a member of the Senate Banking, Housing, and Urban Affairs Committee to which this bill was assigned for consideration. More importantly, there are 34 cosponsors ranging from Sen Scott (R,SC; Committee Chair) to Sen Schumer (D,NY). This makes it likely that the Committee could consider S 4395. The big question for this bill will be if members withhold support for this clean reauthorization while holding out to make changes to the program. 

With program termination one year away, it is not likely that there would be sufficient political pressure to move this bill forward under regular order this session. The bipartisan support for this bill may allow for passing this legislation under the Senate’s unanimous consent process, but Sen Paul (R,KY) might be expected to object to such a move. 


For more information on the provisions of this bill, including a commentary on cyber coverage and Iranian water systems attacks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4395-introduced-tria-reauthorization - subscription required. 

Looking Back – 12-16-21 – Log4Shell, do Something Now

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 16th, 2021, Reader Comment – Log4Shell Do Something Now, jumped into the list. This post looked at some of the response issues related to the Log4 vulnerabilities. These vulnerabilities were the first time (and looking back, the only time) that the OT vendor community jumped on a 3rd party vulnerability with any sort of unanimity. That response was both quick and flawed; to be fair, a combination that is frequently seen in emergency situations. 

The problem was that there was no problem. The world did not end. There were no massive takeovers of vulnerable systems. The OT world chugged along pretty much the same as it did before Log4Hell. I am afraid that the lesson learned can be summed up in a phrase I learned many years ago (damn, close to 40 now) that I learned in French Commando School; “No sweat, no safety.” 

We can see this reflected today in the industry response to the Iranian (probably) water system hacks of last month; “What? Me Worry?” Nothing crashed and burned; product was still delivered, no safety issues, and you want water facilities to change their operating scheme? “Bother me next week.” 

NOTE: With me taking the weekends off now, more of these older posts are showing up in analytical data on Monday’s, I will continue to use these posts for Monday morning fodder if they have some relevancy to current conditions. 

Friday, July 31, 2026

Chemical Transportation Incidents – Week of 6-27-26

Reporting Background 

See this post for explanation, with the most recent update here (removed from paywall). 

Data from PHMSA’s online database of transportation related chemical incidents that have been reported to the agency. 

Incidents Summary  

• Number of incidents – 544 (521 highway, 16 air, 7 rail, 0 water) 

• Serious incidents – 8 (6 Bulk release, 2 evacuation, 0 injury, 0 death, 2 major artery closed, 2 fire/explosion, 29 no release)  

• Largest container involved – 33,980-gal DOT 112J340W Railcar {Butane See Also Petroleum Gases, Liquefied} Overloaded and overpressure due to ambient heating. 

• Largest amount spilled – 500-gal DOT 111A100W1 Railcar {Ammonium Nitrate, Liquid (Hot Concentrated Solution)} Corrosion hole in tank and liner. 

• Total amount reported spilled in all incidents – 3163.5-gal 

NOTE: Links above are to Form 5800.1 for the described incidents. 

Most Interesting Chemical: Pyrethroid Pesticide, Liquid Toxic: Pyrethroid Pesticide, Liquid, TOXIC is an insecticidal liquid consisting either of a single pyrethroid or a mixture of pyrethroids or a solution of such a pyrethroid or mixture dissolved in a organic solvent having a flash point exceeding 100°F. A pyrethroid pesticide is a substance possessing the terpenoid structure and insecticidal properties that are characteristic of the pyrethrins. The pyrethrins are terpenoid esters that are obtained from flower heads of the chrysanthemum and related species or by synthesis. The most prominent are pyrethrin I (C21H28O3) and pyrethrin II (C22H28O5 ) which are the major active ingredients in pyrethrum powder. Both of these compounds are water-insoluble oily liquids. The insecticide/carrier mixture is toxic by inhalation, ingestion, and skin absorption. (Source: CameoChemicals.NOAA.gov).  


Review - PHMSA in the Federal Register – 7-31-26

 Today, DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) published 17 actions in the Federal Register. These actions refer to Federal Register publications from April 24th, 2026; not all of the actions published on that day were addressed in today’s Federal Register. They include: 

  • Direct final rule (DFR) withdrawals (2),  
  • DFR date confirmations (15).  

Direct Final Rule Withdrawals  

When DOT direct final rules are issued, that issuance is subject to the ‘adverse comment’ exception found in 49 CFR 190.339(c). If an adverse comment is received on the DFR within the comment period, in the case of these two DFR’s June 23rd, 2026, then the DFR will be withdrawn and the responsible agency will decide whether to proceed with a revised DFR, initiate a more conventional rulemaking, or abandon the process completely. 

The two DFR withdrawals published today were:  


For more information on the DFR date confirmations, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/phmsa-in-the-federal-register-7-31 - subscription required. Free subscribers will receive email copies of that post tomorrow. 

Personal Note: The Chief Counsel, Keith Coyle, listed in each of these rulemaking notices is, to the best of my knowledge, not related to me. 

 
/* Use this with templates/template-twocol.html */