Skip to main content
Category

R&D

Cybersecurity in Rail

🚆 The Urgent Need for Cybersecurity in the Railway Industry

The railway sector is undergoing a significant digital transformation, integrating advanced technologies to enhance efficiency and passenger experience. However, this increased connectivity has also expanded the attack surface, making rail systems more susceptible to cyber threats.

Recent Cybersecurity Incidents

  • In March 2025, Ukraine’s state-owned railway company, Ukrzaliznytsia, experienced a major cyberattack that disrupted both passenger and freight transport systems. The attack compromised their IT infrastructure, forcing passengers to revert to manual ticketing methods.

  • Experts have warned that Scotland’s railway network is ill-prepared for sophisticated cyberattacks. The transition from mechanical to digitally-controlled signaling systems has introduced vulnerabilities, as highlighted by recent incidents affecting Transport for London and major stations like Glasgow Central and Edinburgh Waverley.

  • In October 2022, Danish train operator DSB experienced widespread cancellations after a critical test environment managed by Supeo disrupted essential system interfaces. The investigation revealed that a single point of failure triggered a cascade across multiple systems. The root cause was traced to a third-party supplier, whose associated risks had not been adequately evaluated.
  • In August 2023, a cyber incident in Poland resulted in the transmission of emergency stop messages that halted 20 trains. The disruption had a ripple effect on surrounding services and took six hours to resolve. The attack exploited the VHF train radio system—an unencrypted, open channel that was easily accessible. Poor assumptions were made about its vulnerability, and documentation was readily available to potential attackers.
  • Then in December 2023, another incident in Poland saw a denial-of-service issue caused by a malfunction in supply chain software. Although the train manufacturer recognized cyber threats, the software underperformed and lacked sufficient monitoring. The problem was worsened by multiple system interfaces that increased exposure to potential attacks.

Industry Challenges

1. Expanding Threat Surface and System Complexity
Rail systems are becoming highly interconnected, with digital signaling, communications, and control systems all relying on shared infrastructure. This connectivity increases exposure to cyber threats, where a single compromised system can cascade across operations. Yet, many existing systems were never designed with cybersecurity in mind.

2. Fragmented Standards and Regulatory Overload
Despite the presence of standards like IEC 62443 and TS 50701, rail operators face challenges in applying them consistently. The abundance of overlapping international, national, and industry-specific guidance can be difficult to interpret, leading to inconsistent implementation and regulatory fatigue.

3. Skill Gaps and Lack of Cross-Disciplinary Awareness
Cybersecurity expertise in the rail sector remains limited. Many organizations lack both the resources and the specialized knowledge to assess and secure complex OT environments. Engineers often don’t see cybersecurity as part of their role, and security teams may not fully understand rail-specific systems.

4. Interface and Integration Risks
Modern rail applications like Traffic Management Systems and Driver Advisory Systems depend on multiple data sources—many of which are unsecured or poorly understood. Ensuring cyber assurance across these interfaces requires better coordination, monitoring, and threat modeling.

5. Cultural and Operational Resistance to Change
Cybersecurity is still not fully integrated into rail engineering practices. Legacy mindsets, siloed departments, and a focus on safety over security often delay the adoption of secure-by-design principles across the system lifecycle.

🛡️ CyRail AI: The Future of OT Cybersecurity in Rail

At CyRail, we are leading the charge in transforming how rail operators approach cybersecurity with our AI-powered platform. CyRail is more than just a tool — it’s an intelligent co-pilot designed to safeguard rail operations and infrastructure against the growing cyber threats that are plaguing the industry.

What CyRail AI Does

🚀 Harnesses the Power of AI for Real-Time Protection
CyRail leverages advanced AI to not just analyze data, but to actively safeguard critical systems. As the railway sector embraces digital transformation, CyRail offers a proactive approach to cybersecurity, ensuring resilience and continuous operation.

🔒 Compliance-Driven Security
Our AI is trained on some of the most complex cybersecurity frameworks, including:

  • IEC 62443

  • TS 50701

  • NIS2

  • Upcoming IEC 63452 (2025)
    This ensures every recommendation and action is compliant with rail-specific standards, keeping your systems secure and aligned with evolving regulations.

📄 Automates Documentation
CyRail goes beyond just monitoring for threats; it creates and evaluates your cybersecurity documentation:

  • Auto-generate tailored documentation for your rail projects

  • Evaluate existing documents against compliance standards

  • Suggest improvements in plain language, making it easy for non-experts to understand

🛡️ Real-Time Threat Monitoring
CyRail’s live threat database keeps you informed of:

  • Emerging vulnerabilities in the rail sector

  • Sector-specific risks

  • Actionable responses linked directly to your system documentation

🤖 Acts as Your Cybersecurity Assistant
CyRail AI acts as an intelligent assistant, helping your team navigate complex cybersecurity challenges with ease. Whether you’re asking about best practices for OT and IT segregation or applying cybersecurity frameworks, CyRail provides context-specific responses and uses retrieval-augmented generation (RAG) to ensure accuracy.

🔗 Seamless Integration
CyRail integrates effortlessly into your existing workflow:

  • Works with Enterprise Architect

  • Syncs with internal repositories

  • Uses your documentation templates
    This allows you to implement cybersecurity measures without disruption.

🎓 Empowering the Workforce with Training

Understanding that human errors are a significant risk factor in cybersecurity breaches, CyRail also offers built-in training programs. These resources help rail professionals understand best practices, compliance requirements, and how to handle emerging threats, all of which strengthen the organization’s cybersecurity posture.

🚄 Why Choose CyRail?

  • Speed: Reduce compliance work from weeks to hours, enabling faster decision-making.
  • Accuracy: Ensure your systems are aligned with the latest cybersecurity standards, even in the most complex environments.

  • Scalability: Whether you’re handling a single project or multiple systems, CyRail scales with you.

  • Education: Built-in training and workshops help staff stay ahead of the curve and integrate cybersecurity best practices into their daily operations.

🌐 The Bigger Picture

CyRail isn’t just a tool — it’s an intelligent, AI-driven co-pilot that helps navigate the increasingly complex world of rail operational technology. By integrating AI, cybersecurity, and industry-specific training, CyRail delivers a comprehensive solution that helps rail operators ensure safety, compliance, and operational continuity.

In a rapidly evolving digital landscape, CyRail empowers rail organizations to innovate with confidence, knowing that their critical infrastructure is protected.

🚀 Ready to Future-Proof Your Railway Cybersecurity?

CyRail is on the cutting edge of OT cybersecurity for the railway industry, and we’re getting ready to launch. If you’re looking for a smarter, AI-powered solution to safeguard your operations, stay ahead of the curve, and ensure compliance, CyRail is the answer.

👉 Sign up for our waiting list today and be the first to know when CyRail is released. Don’t miss out on the opportunity to revolutionize your cybersecurity strategy.

Sign Up Now for Early Access!

Contact
Digital Transit Limited


Email
info@digitaltransit.co.uk

Subscribe to receive new blogs

TOAD

Tram Overspeed Advisory Device

We’re excited to spotlight Kathryn Hurst, one of the engineers behind our tram overspeed advisory device, whose impressive work has secured her a place in the next round of the IMechE North Western Centre for the Future of Rail Presentation Competition. She has also been honoured with the prestigious Sir William A. Stanier FRS trophy. Her work is a key part of our collaboration with Blackpool Tramway.

The IMechE Future of Rail Presentation Competition is a programme designed to showcase young engineering talent within the rail industry. It offers a unique opportunity for early-career engineers and researchers to present their innovative projects, contributing to the future of railway technology.

In the North West regional round, three talented young researchers competed, each delivering a 15-minute presentation on their respective projects. Kathryn emerged as the winner, earning her place in the grand final in London, where she will compete against the other Railway Division centres for the grand prize.

Kathryn’s work on the Tram Overspeed Advisory Device will contribute to a proactive approach in improving tram safety, particularly on sharp corners with a high overturn risk. By collaborating with Blackpool Tramway, she has helped develop a system that alerts the driver when there is an overspeed risk, enhancing passenger safety.

Here at DTL, we couldn’t be prouder of Kathryn’s achievements and can’t wait to see her represent our company in the final competition.
Best of luck, Kathryn!

 

TOAD Background

Following the Croydon tram accident, the Rail Accident Investigation Branch (RAIB) made several recommendations to improve tram safety, with one focusing on speed reduction. The goal is to prevent accidents by automatically reducing tram speeds when approaching high-risk locations where derailment or overturning could occur.

One response to this recommendation is the implementation of an annunciator system on Blackpool’s heritage trams. This system provides visual and audible warnings to the driver if the tram exceeds safe speeds, particularly near risk-prone areas. The system helps drivers slow down in real-time, addressing RAIB’s recommendations and reducing risk.

By adopting such measures, tram operators, like those in Blackpool, demonstrate a proactive approach to tram safety, ensuring a safer future for passengers and drivers alike.

Requirements for the TOAD included:

  • Small and Simple to Install
  • Powered by the Tram’s 24v
  • IP65
  • A Speedometer
  • An Operational Indicator
  • An In-Cab Warning for overspeed

 

So we built – Prototype 1

The first prototype of the tram overspeed advisory device served as a proof of concept. Testing revealed key issues: the speed display updated too slowly, the combined buzzer and light were too quiet, and the wiring was messy, affecting reliability. To improve performance, we upgraded our main processor, as well as our GPS and SD card modules.

For the next prototype, the buzzer and light were separated for better sound output. Blackpool Transport requested the device connect to the tram’s transponder to detect how points were set, and code improvements were made for better geofence handling and data processing.

These insights informed the development of the next prototype with enhanced functionality and reliability.

 

        Prototype 1 design

Prototype 2 design

We made improvements – Prototype 2

Prototype 2 is ready for final testing, and DTL plan plan to:

  • Conduct a final batch of lab tests to confirm TOAD works as expected.

  • Install the device with the Blackpool Geofences file on a tram and test that overspeed alerts trigger correctly.

  • Leave the device running on a tram to collect data on routine operations and perform a final review of Prototype 2’s performance.

These steps will ensure the device can be fully updated for prototype 3 and be ready for deployment.

 

Impact of this work

The TOAD overspeed advisory device will work to proactively reduce overturn risk by providing real-time warnings to drivers. Its development demonstrates how innovation can improve existing transport systems, with Blackpool Tramway providing valuable collaboration.

 

Contact
Digital Transit Limited


Email
info@digitaltransit.co.uk

Subscribe to receive new blogs

REDGE

Resilient Energy Digital Grid Engine 🚀

As the world increasingly turns to renewable energy sources, the need for more efficient, reliable, and secure energy systems has never been greater. The REDGE: Resilient Energy Digital Grid Engine project is pushing the boundaries of what’s possible in energy management by integrating cutting-edge digital twin technology with advanced cybersecurity features. This pioneering effort is set to revolutionize how energy providers monitor, manage, and protect renewable energy systems, ensuring greater efficiency and resilience.

What is REDGE?

At the heart of the REDGE project is the development of a digital twin platform for energy systems. A digital twin is a virtual model that mirrors physical assets in real-time. In this case, the platform will create digital replicas of renewable energy infrastructure like wind turbines and solar panels. These digital twins will enable energy providers to monitor the performance of these systems in real time, track their health, predict potential issues, and make data-driven decisions to improve operational efficiency.

But the REDGE project takes things a step further by integrating advanced cybersecurity features directly into the digital twin framework. This innovative approach ensures that while these virtual models simulate physical operations, they also continuously analyze data for potential cybersecurity threats, allowing energy providers to detect and respond to vulnerabilities before they escalate into serious incidents.

Key Features of the REDGE Project

  1. Real-Time Monitoring & Predictive Maintenance: By simulating real-world energy assets, REDGE allows for real-time monitoring of the condition of turbines, solar panels, and other critical infrastructure. This constant surveillance helps energy providers quickly identify and address issues before they lead to costly failures or system downtime.

  2. Actionable Cybersecurity Insights: One of the most groundbreaking aspects of the REDGE project is its integration of cybersecurity into the digital twin technology. The platform uses AI-driven analytics and advanced algorithms to detect anomalies or potential threats in the system, ensuring that energy assets are not only physically secure but also protected from cyberattacks. In the event of a cybersecurity breach, the system can provide color-coded alerts to prioritize actions, enabling faster recovery and minimization of damage.

  3. Enhanced Resilience & Efficiency: The project aims to make renewable energy systems more resilient to both physical and cyber threats. By combining condition monitoring with continuous cybersecurity assessments, REDGE helps improve the overall efficiency and reliability of energy infrastructure. This ensures that energy providers can meet the rising demand for clean energy while maintaining the highest standards of security.

  4. Collaboration between Experts: The REDGE project is the result of a collaborative effort between Digital Transit Limited (DTL) and the University of Huddersfield. Combining DTL’s expertise in digital technology and cybersecurity with the University’s cutting-edge research in energy management has created a unique and powerful synergy that positions REDGE as a leader in the field of renewable energy technology.

What Sets REDGE Apart?

REDGE is not just about enhancing the performance of renewable energy assets; it’s about safeguarding them against a new generation of threats. As more critical infrastructure is connected to the internet and digital systems, the risk of cyberattacks grows. With REDGE’s innovative integration of cybersecurity monitoring directly into digital twins, energy providers can anticipate, identify, and neutralize threats in real time, ensuring the continuous operation of clean energy systems.

Impact on the Future of Renewable Energy

The outcomes of the REDGE project are expected to set new benchmarks for how technology is integrated into energy management. Not only will the project contribute to the sustainability of renewable energy systems, but it will also enhance their security and operational reliability. As energy infrastructures become increasingly digitized, the REDGE platform will provide a robust framework for maintaining both performance and security standards, positioning it as a critical tool for energy providers globally.

Furthermore, REDGE’s real-time insights will be essential for efficient recovery during a cybersecurity incident. By offering a prioritized “batting order” for corrective actions, REDGE ensures that the response is swift, organized, and effective, minimizing potential damage and downtime.

Conclusion

The REDGE: Resilient Energy Digital Grid Engine project is at the forefront of a new era in energy management—one that merges digital innovation with cutting-edge cybersecurity. By integrating digital twin technology with proactive cybersecurity measures, REDGE is making renewable energy systems more efficient, resilient, and secure than ever before. This project is not just an advancement in technology; it’s a step forward for the future of sustainable energy, ensuring that as we move towards a greener, cleaner energy future, we do so with safety, efficiency, and reliability at the core.

Stay tuned for more updates as the REDGE project continues to evolve and reshape the landscape of renewable energy systems.

Contact
Digital Transit Limited


Email
info@digitaltransit.co.uk

Subscribe to receive new blogs