Monday, August 3, 2026

Short Takes – 8-3-26 - Federal Register Edition

Notice Updating and Expanding Guidance on Safe Development and Deployment of Automated Driving Systems. NHTSA notice of availability. Summary: “NHTSA intends to issue comprehensive, updated guidance supporting the safe development and deployment of automated driving systems. The last agency guidance was published in 2017, titled Automated Driving Systems 2.0: A Vision for Safety (ADS 2.0). For this initiative, NHTSA will draw on its internal expertise and public feedback gathered through ongoing stakeholder engagement. NHTSA intends to release draft guidance documents on individual topics (or chapters) as they are available. The public is invited to comment on each chapter through this open docket. After reviewing public comments, the agency plans to consolidate all chapters into a final updated guidance document. The public comment period is open for one year and may be extended as necessary.” 

AV Framework Updates and Request for Comments on Interim Guidance. NHTSA notice of updates. Summary: “In April 2025, DOT and NHTSA announced a new automated vehicle framework designed to prioritize safety, promote innovation, foster American ingenuity, and remove regulatory barriers to the advancement of automated driving system technologies. This notice furthers NHTSA's implementation of this framework by requesting public comment on interim guidance for commercial deployment exemptions for automated vehicles. This notice also summarizes NHTSA's other recent activity relating to the AV Framework. 

Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats. FCC final rule. Summary: “In the Report and Order, the Federal Communications Commission (the FCC or the Commission) seeks to preserve the public's trust in the Emergency Alert System (EAS) by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation's adversaries. 

Review - S 4395 Introduced – TRIA Reauthorization

Back in April, Sen McCormick (R,PA) introduced S 4395, the Terrorism Risk Insurance Program Reauthorization Act of 2026. This is a ‘clean’ reauthorization bill that extends the program through December 31st, 2034, and makes similar extensions of the federal recoupment dates. No new funding is authorized by this bill.  

I can find no legislation in the 118th Congress that would appear to be similar to S 4395. There is, however, a bill introduced in the House this session that would appear to be similar, HR 7128, the TRIA Program Reauthorization Act of 2026. That bill was introduced by Rep Flood (R,NE) in January of 2026. The House Committee on Financial Services held a business meeting later in January that included a markup of HR 7128. Four amendments were offered and rejected by the Committee, which subsequently approved alternative language by a voice vote. On June 29th, 2026, the House took up HR 7128 under the suspension of the rules process and passed the bill by a bipartisan vote of 373 to 15 (all Nay votes were from Republicans). No action has yet been taken in the Senate. 

Moving Forward  

McCormick is a member of the Senate Banking, Housing, and Urban Affairs Committee to which this bill was assigned for consideration. More importantly, there are 34 cosponsors ranging from Sen Scott (R,SC; Committee Chair) to Sen Schumer (D,NY). This makes it likely that the Committee could consider S 4395. The big question for this bill will be if members withhold support for this clean reauthorization while holding out to make changes to the program. 

With program termination one year away, it is not likely that there would be sufficient political pressure to move this bill forward under regular order this session. The bipartisan support for this bill may allow for passing this legislation under the Senate’s unanimous consent process, but Sen Paul (R,KY) might be expected to object to such a move. 


For more information on the provisions of this bill, including a commentary on cyber coverage and Iranian water systems attacks, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4395-introduced-tria-reauthorization - subscription required. 

Looking Back – 12-16-21 – Log4Shell, do Something Now

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 16th, 2021, Reader Comment – Log4Shell Do Something Now, jumped into the list. This post looked at some of the response issues related to the Log4 vulnerabilities. These vulnerabilities were the first time (and looking back, the only time) that the OT vendor community jumped on a 3rd party vulnerability with any sort of unanimity. That response was both quick and flawed; to be fair, a combination that is frequently seen in emergency situations. 

The problem was that there was no problem. The world did not end. There were no massive takeovers of vulnerable systems. The OT world chugged along pretty much the same as it did before Log4Hell. I am afraid that the lesson learned can be summed up in a phrase I learned many years ago (damn, close to 40 now) that I learned in French Commando School; “No sweat, no safety.” 

We can see this reflected today in the industry response to the Iranian (probably) water system hacks of last month; “What? Me Worry?” Nothing crashed and burned; product was still delivered, no safety issues, and you want water facilities to change their operating scheme? “Bother me next week.” 

NOTE: With me taking the weekends off now, more of these older posts are showing up in analytical data on Monday’s, I will continue to use these posts for Monday morning fodder if they have some relevancy to current conditions. 

 
/* Use this with templates/template-twocol.html */