Cybersecurity
Railway Cybersecurity: Specific Challenges and a Regulatory Approach
Railway networks are becoming more connected and more exposed. An analysis of systems at risk, the regulatory framework and defence strategies for an often overlooked critical infrastructure.

Railway networks: from isolation to connectivity
For much of their history, railway networks operated on proprietary, isolated systems. Signalling ran on dedicated protocols, voice communications on separate networks, ticketing systems with no connection to the central network. That isolation was security by inertia.
Modernisation changed everything. The introduction of computerised control systems, the digitalisation of ticketing, onboard WiFi networks, real-time passenger information systems, remote control centres: every improvement in operational efficiency introduced new attack surfaces. Today a large railway operator runs IT/OT networks with a complexity comparable to that of a large industrial company, with the added variable of the mobility of trains.
Systems at risk: signalling, SCADA, ticketing, communications
Understanding railway risks requires distinguishing between systems with different operational impacts.
Signalling and movement control systems: these are the most critical systems of all. ERTMS/ETCS (European Train Control System), interlocking systems, switch commands: an attack on these systems is not a data loss, it is a physical safety risk. Redundancy and mechanical fail-safes exist precisely for this reason, but integration with management software introduces vulnerabilities that purely mechanical systems did not have.
Power management SCADA systems: electric traction depends on substations and power distribution systems controlled by SCADA. An attack that alters supply parameters or selectively disables substations can shut down entire lines.
Centralised operational systems: railway traffic control centres manage the entire network from centralised workstations. A compromise here has a multiplier effect across the whole system.
Passenger infrastructure: automated ticket machines, passenger information systems, controlled access points: less critical from a physical safety standpoint, but sensitive for service continuity and for the handling of personal data.
Onboard communications: modern trains have WiFi networks, infotainment systems and connections for predictive maintenance. If not properly segregated, these networks can become an entry point toward more critical systems.
The regulatory framework: NIS2 and sector standards
The NIS2 Directive includes railway transport among the essential sectors, which means stringent obligations for cyber risk management, incident notification and security measures for all significant operators in the sector.
In parallel, the European Union Agency for Railways (ERA) has developed specific guidelines for railway cybersecurity, and ENISA has published recommendations dedicated to the sector. At a technical level, the IEC 62443 standard applies to railway industrial control systems.
The distinctive feature of the railway sector is the coexistence of systems with very long life cycles (physical infrastructure remains in service for decades) and already highly developed safety requirements, which must now incorporate the cyber dimension without compromising existing certifications.
Attack vectors specific to railways
Some attack vectors are particularly relevant to the railway context:
Physical access to onboard systems: trains are semi-public environments. Maintenance connections, technical cabinets, WiFi systems: all surfaces accessible to anyone on board with malicious intent.
Third-party systems: railway maintenance involves a long chain of specialised suppliers. Every vendor access is a potential vector, and the management of these accesses in railway OT is often less rigorous than the risk would require.
Legacy interfaces with modern systems: historical signalling systems, integrated with modern software overlays for supervision, create interfaces that were not designed with security in mind.
Operational denial of service: not all attacks on railways aim to compromise data. Blocking ticketing systems during a high-attendance event, or degrading the performance of public information systems, are forms of attack with a real impact on the operator's reputation.
Building resilience: a zones and conduits approach
The IEC 62443 approach based on zones and conduits adapts naturally to railway architecture: zones correspond to distinct operational functions (signalling, power, passengers, maintenance), and conduits define the authorised communication channels between them.
The practical steps for a railway operator:
- Complete inventory of OT systems, with particular attention to legacy devices and undocumented maintenance connections.
- Risk assessment by function: not all systems have the same risk profile, and the prioritisation of investments must reflect this.
- Progressive segmentation: start by separating signalling systems from the rest of the OT network, then extend to the other zones.
- Third-party access management: implement just-in-time access for all vendors, with session recording and automatic revocation.
- Specific incident response plan: one that accounts for the operational constraints of the sector, including the need to maintain service during the incident response.
Railway security is a rapidly evolving domain. The integration between traditional safety and modern cybersecurity is the work of the coming years for the entire sector.
The MON5 angle
A railway network distributed over hundreds of kilometres, spanning signalling, traction substations and control centres, cannot be protected with tools designed for a single plant. MON5 was built for contexts like this: passive, out-of-band NDR sensors at traffic aggregation points, a multi-site architecture that consolidates the telemetry of stations and substations into a single view, without interfering with systems that have absolute availability requirements.
The platform also supports the IEC 62443 zoning described in this article, mapping the actual conduits between signalling, power and passenger networks, and produces evidence useful for the NIS2 obligations of operators in the sector. To understand where to start on your own network, the first step is an OT assessment.
Related articles

Cybersecurity
Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure
Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.
Cybersecurity
Port and Maritime Cybersecurity: Terminals, Intermodal Logistics and Onboard Systems
Ports and ships are complex, under-protected OT ecosystems: automated cranes, onboard systems, terminals and intermodal logistics. A map of risks and obligations for a critical sector that is often overlooked.
Cybersecurity
OT incident notification under NIS2: obligations, timelines and what to have ready before it happens
NIS2 sets tight deadlines for notifying significant incidents: 24 hours for the early warning, 72 hours for the detailed notification. In OT, being ready to meet them takes preparation that starts long before the incident.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2