IN the short history of cybersecurity in railway environments, security and safety objectives have often been at odds with each other, only finding common ground when a security incident such as trespassing causes a safety issue.
Unfortunately, cybersecurity incidents in the transport sector are occurring more frequently and can no longer be ignored. The potential for cyber attacks to damage revenue and jeopardise public trust and even national security is significant, with transport now one of the top five most targeted sectors in the European Union (EU).
The European Union Agency for Cybersecurity (Enisa) Threat Landscape report published in 2025 found that transport accounts for 7.5% of total cyber attacks analysed. Reporting metrics from the EU’s Network and Information Security (NIS) Directive also show that in 2024, 12% of incidents with significant impact occurred in the transport sector. In the United States, last month the Federal Railroad Administration (FRA) issued a railway operating technology cybersecurity safety alert, requesting that operators in the United States prepare for the escalation of cyber attacks.
Railways present an attractive target for cyber criminals motivated by financial gain, geopolitics, and self-interest, with the rail sector viewed as offering a high return on investment for budget-conscious cyber criminals.
Cyber attacks no longer only affect security, but the safety and continuity of rail operations. Due to the prevalence of legacy systems, and lack of encryption on critical communications networks, vulnerabilities are easily exploitable and, in some cases, require an investment of less than $US 35 to execute. Railways are a high-visibility target, and are attractive for lower-skilled actors like hacktivists aiming to communicate a political or social message. Attacks perpetrated by nation-state actors aiming to degrade or disrupt the transport network can also have a far-reaching impact on national logistics and supply chains.
Cybersecurity challenges and safety impact are increasingly intermeshed by the convergence of information technology (IT) and operational technology (OT) that has compounded the degradation of cybersecurity in both IT and OT environments. IT describes computer systems which manage data and communications, often found in a railway’s corporate network. IT security is primarily focused on managing confidentiality, integrity, and availability to protect information.
OT refers to the systems which monitor or control physical processes and equipment and which are located onboard rolling stock, lineside, or elsewhere in the operational environment. Even railways with the most modern technical equipment can have OT elements dating back to the 1980s, further complicating their management.
Cybersecurity in OT is a relatively new field of study and tends to react to new threats whereas IT security benefits from decades of defensive practices. While the interconnectedness of IT and OT systems increase the ease of access for system operators and administrators, it expands the attack surface by sharing vulnerabilities across operationally disparate systems. The 2017 WannaCry infection of German Rail (DB) demonstrates a key example of the risk shared between IT and OT environments.
WannaCry, ransomware with ties to a North Korean criminal gang, infected an outdated Windows XP system within the company’s corporate network. The ransomware, designed to self-replicate, spread across the DB network, rooting itself in passenger information displays, CCTV systems, and ticketing machines. While train control systems continued to function normally, the disruption demonstrates how lax security in one part of an IT network affects OT-adjacent systems that impact passenger services. Globally, the WannaCry ransomware campaign spread to more than 200,000 computers in 150 countries, with evidence of infections still occurring today.
Recent attention to OT vulnerabilities is reflected in the now regular publication of alerts evaluating these weaknesses. While vulnerability disclosure improves defence readiness, it also amplifies weaknesses in safety-critical systems.
In 2024, researchers from the University of Birmingham in Britain performed a cryptographic analysis of ERTMS and the three protocols used by the system: GSM-R, GSM, and EuroRadio. While vulnerabilities in GSM-R and GSM have been known for many years, the project discovered a new vulnerability in EuroRadio, which allows a capable threat actor to send unauthenticated stop signals to trains in service.
Exploitation of vulnerabilities in OT systems result in a real, measurable impact on continuity of operations and safety protocols. Cyber attacks by nation-state actors often follow the trend of heightened global tensions, preceding traditional warfare. Lessons learned from recent conflicts must be considered in defending rail networks. In 2023, the Polish rail network was targeted by Russian supporters protesting against Polish support for Ukraine. This attack occurred directly on the railway’s OT systems and affected 20 passenger and freight trains, halting operations for several hours. Due to the lack of encryption on critical communications, this attack can be replicated with a cheap software-defined radio and minimal knowledge of GSM cellular technology.
Kill chain
The cyber kill chain describes the steps a threat actor will take from the inception of an attack to execution and impact. By better understanding how threat actors target and access rail infrastructure, we can begin to protect systems before safety is impacted.
In the reconnaissance phase, threat actors collect information about the technology, vendors, staff, and network exposure using publicly available sources and scanning tools. Initial access describes the common entry points leveraged by threat actors including phishing, using compromised credentials, and exploiting exposed services. Lateral movement is the ability of a threat actor to pivot from one network segment to another. A cyber attack might not require lateral movement to be successful, as seen in the 2023 attack on the Polish rail network. However, the pivot from IT to OT or vice versa increases the impact and effectiveness of the attack.
The impact is often the first recorded indication that a cyber attack is underway, leaving responders to react rather than prevent damage. Impact can take many forms including system inaccessibility due to ransomware, sensitive information leakage after data theft, or stoppage of operations, all of which incur significant damage to revenue and public trust.
Basic protection
The undeniable link between damaging cyber attacks and threats to safety requires special care to be taken in order to prevent and prepare for attacks. The cyber kill chain is not just a tool to characterise a cyber attack. It can be used to stop an attack before the impact is recognised, saving time and money and preventing safety incidents. If railways can limit public information about the technology they employ, the reconnaissance phase becomes more challenging for threat actors. If vulnerabilities are patched and employees are trained to identify and report phishing attempts, attackers will find it harder to successfully gain initial access.
Training all employees to prevent and identify cyber attacks is a key protection mechanism. However, annual cyber awareness training, an existing requirement for many transport companies and organisations, does not meet the demands of emerging, highly motivated threats. Instead, it is recommended that railways perform at least two types of cyber training: routine and just-in-time.
Routine training is delivered on a set schedule (such as annual training) to refresh employee knowledge and inform them of administrative and technological changes throughout the year. Just-in-time training is delivered when the context changes. For example, training should be provided for all new employees when technology significantly changes, or if a new threat is targeting infrastructure. This approach to training ensures that employees have a baseline knowledge of their responsibility to cybersecurity and that they are notified of specific indicators that may impact the way they interact with information systems.
As the cyber threat landscape changes, reviewing and incorporating actionable cyber intelligence into defensive mechanisms is paramount. European railways can elect to join industry-specific sharing communities like the Rail and European Rail Information and Sharing and Analysis centres (R-ISAC and ER-ISAC), both of which share relevant cyber threat intelligence.
Railways can help themselves by proactively identifying where their cybersecurity protection is adequate and where it is falling short. This can be accomplished by performing an objective internal review of all cyber vulnerabilities or contracting with a third party to undertake an objective assessment. During this review, auditors should evaluate current vulnerabilities and technology as well as assess the importance of each system and the impact of that system becoming unavailable during an attack. The results of such an evaluation can be used to tailor protection for existing infrastructure, targeting areas identified as at the highest risk of cyber attack.
There is growing recognition that cybersecurity protection starts during the procurement process. The “safety at all costs” mentality must be applied to cybersecurity. All OT systems, including health monitoring, should be considered as potential access points and targets for opportunist attackers.
The historical separation between safety and security issues is becoming increasingly difficult to justify in light of the impact of cybersecurity incidents. Any accident, incident, or disruption caused by a cyber attack must be treated as a safety issue to prevent harm to railway staff. As the rail network becomes more dependent on interconnected digital systems, cyber vulnerabilities can no longer be viewed as a concern isolated to IT systems. Recent incidents demonstrate that meaningful, low-cost improvements in cyber resilience can proactively address the growing risk to safe operations.
*Erin Plemons is director at the Center for Critical Infrastructure Protection (CCIP) and Ruben Peña is director of government surface transportation at Ensco. Both are based in Pueblo, United States.