Skip to main content

Embracing the Future: Unpacking the New IEC 63452 Railway Cybersecurity Standard






Unpacking the New IEC 63452 Railway Cybersecurity Standard


Embracing the Future: Unpacking the New IEC 63452 Railway Cybersecurity Standard

Published on:

The introduction of the IEC 63452 standard next year will represent a crucial update in the realm of railway systems cybersecurity. This standard will replace the current Technical Specification, TS 50701, enhancing and expanding the framework to better address today’s cybersecurity challenges within the railway industry.

Detailed Cybersecurity Framework

IEC 63452 introduces a more specific cybersecurity framework designed for railway applications. It emphasises continuous monitoring and cybersecurity assurance, allowing railway operators to respond more effectively to changing threats. The standard organises vulnerability management in a structured way, ensuring timely identification and mitigation of security vulnerabilities to protect critical infrastructure.

Cybersecurity in Railway Systems

Enhanced Risk Management

IEC 63452 offers detailed methodologies for risk assessment, advancing beyond the broader guidelines of TS 50701. It includes classification of different areas within the railway system based on their security needs, facilitating targeted and efficient security measures.

Integration of Safety and Security

IEC 63452 integrates the management of safety and security considerations, encouraging a combined approach to engineering these aspects to improve overall system integrity and reliability. The standard promotes measurable security measures providing a framework to evaluate security effectiveness. In continuation of the approach and improving it.

High-Speed Train with Cybersecurity Elements

The standard provides a comprehensive approach to managing cybersecurity within railway systems, adhering to the guidelines of IEC TC 9 and applicable across all relevant sectors within the railway industry.

It integrates the requirements from the IEC 62443 series, which are specifically designed for cybersecurity, and adapts these for the railway application domain. This includes a detailed application of cybersecurity standards and instructions on interfacing these standards with the general reliability, availability, maintainability, and safety (RAMS) lifecycle as outlined in the IEC 62278 series.

The standard ensures synchronization among various stakeholders by defining their responsibilities and presenting the security assumptions clearly. It also outlines how these cybersecurity protocols can be applied to other lifecycle processes.

Compliance with IEC 62443-2-1:2010 is maintained, providing security models, concepts, and a risk assessment process specifically tailored for the railway sector. This approach helps identify and manage residual risks associated with security threats to a level that is acceptable for railway operators and infrastructure managers.

The primary goal of the standard is to offer support and guidance for protecting critical aspects of railway Systems under Consideration (SuC) such as safety, operations, financial interests, reputation, regulatory compliance, and social stakes against cyber-attacks and the unintended consequences of configuration or maintenance activities.

Additionally, the standard provides guidance on cybersecurity assurance during the build phase of SuCs and offers recommendations for security management during the operational and maintenance phases.

It is important to note that while the standard provides a robust framework for cybersecurity and its integration with safety, it does not set forth any specific safety requirements or constraints on safety cases for railway systems. Instead, it guides on how cybersecurity measures relate to safety protocols.

Lifecycle Management

The standard provides comprehensive guidelines that span the entire lifecycle of railway systems, from installation to decommissioning. This approach ensures that cybersecurity is an integral part of every stage in a system’s lifecycle, enhancing the long-term sustainability and security of railway operations.

Future Implications

The adoption of IEC 63452 is a useful step towards addressing the complex cybersecurity issues currently facing the railway industry. By establishing a robust framework that incorporates risk management, and integrates safety and security throughout the system’s lifecycle, IEC 63452 aims to set a new standard for railway cybersecurity globally.


Digital Transit Limited Leverages Key Funding to Elevate Cybersecurity Practices






Digital Transit Limited’s Cybersecurity Initiatives


Digital Transit Limited Leverages Key Funding to Elevate Cybersecurity Practices

Published on:

Digital Transit Limited, a UK-based company at the forefront of Artificial Intelligence technology development, has recently secured two critical sources of funding aimed at significantly enhancing its cybersecurity framework. Already holding the Cyber Essentials qualification, Digital Transit Limited is poised to elevate its cybersecurity measures to the next level with the Cyber Essentials Plus certification through the Funded Cyber Essentials Programme run by IASME and funded by the National Cyber Security Centre (NCSC).

Futuristic Train

Stepping Up to Cyber Essentials Plus

Cyber Threats in Futuristic City

The Cyber Essentials Plus certification offers a robust upgrade from the basic Cyber Essentials accreditation, providing an external validation of the company’s cybersecurity defences. This advanced certification ensures a higher level of security assurance, essential for protecting against common cyber threats such as hacking, phishing, and password guessing. The move not only boosts Digital Transit Limited’s defence mechanisms but also enhances customer trust and positions the company favourably within sensitive supply chains and government contracts.

  • Enhanced Cybersecurity: External testing of security measures for a higher assurance level.
  • Risk Management: Effective strategies to shield against prevalent cyber threats.
  • Customer Confidence: Demonstrates a serious commitment to cybersecurity.
  • Supply Chain Security: Meets the requirements for handling UK government contracts.
  • Insurance Incentives: Potential for lower insurance premiums due to recognized security standards.
  • Continuous Improvement: Promotes ongoing updates and enhancements to security practices.

Secure Innovation: A Groundbreaking Pilot Scheme

In addition to the cybersecurity upgrade, Digital Transit Limited is participating in the “Secure Innovation” pilot scheme, a groundbreaking initiative in collaboration with the National Protective Security Authority (NPSA), Innovate UK, and the NCSC. This scheme addresses the growing security threats faced by the UK’s emerging tech industry, offering a strategic approach to fortify security measures across various dimensions, including cyber, physical, personnel, and supply chain risks.

  • Comprehensive Security Enhancement: Implements vital security measures to protect assets.
  • Support Business Growth: Enhances the company’s security posture to attract investors and customers.
  • Encourage Compliance and Best Practices: Guides tech companies to adhere to stringent security standards.
  • Financial Support for Security Reviews: Provides part-funding, reducing financial barriers for startups.
  • Develop Security Skills: Builds internal security capabilities through professional guidance.
  • Continuous Improvement: Ensures the evolution of security practices with business growth.
Offshore Wind Farm at Sunset


Cybersecurity Innovate UK Competition Won by Digital Transit Limited

Cybersecurity Innovate UK Competition Won by Digital Transit Limited

Digital Transit Limited (DTL) are delighted to announce that they have won an Innovate UK competition. It is a 3-year project with our partners, the Institute of Railway Research (IRR) at Huddersfield University and Heron Technology in Singapore. Total project costs are around £500k to develop cybersecurity resilience in rail.

The project is entitled “Tools and Techniques for Operational Technology Cyber Security Compliance in the Railway”

DTL want to connect with railway regulators, operators, and systems integrators to get them involved. DTL want to establish a body of knowledge for this potentially daunting challenge the railway faces as critical infrastructure.

 

 

Diagram showing the interaction between cybersecurity regulations, standards, and OT/IT. Our project will help the railway navigate this system.

Digital Transit passes Cyber Essentials Assessment

Digital Transit passes Cyber Essentials Assessment

Digital Transit Limited have passed the Cyber Essentials (Montpellier) and have been re-certified for Cyber Essentials. The assessment is organised by the IASME Consortium using the certification body AMSA.

Cyber Essentials is an effective, UK Government- NCSC (National Cyber Security Centre) backed scheme that will help you to protect your organisation, whatever its size, against a whole range of the most common cyber attacks.

Digital Transit Limited are committed to ensuring world class cyber security in the railway industry. We offer a one-day workshop, or 6-week modular online course for engineers, managers and other rail decision-makers to learn about the new TS50701:2023 standard.

Get in touch for more information about our services and discover what we can do to help you.

DTL receive funding for Global Business Innovation Programme (GBIP) – Cybersecurity in Australia

DTL receive funding for Global Business Innovation Programme (GBIP) - Cybersecurity in Australia

Digital Transit Limited (DTL) has successfully received funding for the Global Business Innovation Programme (GBIP) Cybersecurity – Australia.

In October, Dr Howard Parkinson will visit Sydney, Melbourne, and Adelaide to establish research and development, coordination and collaboration between Australia and the UK. The focus will be on railway Operational Technology (OT). The goal is to help develop a body of knowledge, tools, and techniques for this important and growing industry.

Further details regarding the GBIP scheme can be found on the Innovate UK website – https://www.innovateukedge.ukri.org/gbip

DTL are experts in OT Cybersecurity in Rail, and offer a one-day workshop, or 6-week modular online course for engineers, managers and other rail decision-makers to learn about the new TS50701 standard.

Get in touch for more information about our services and discover what we can do to help you.

CENELEC releases updated TS50701:2023 OT Railway Cyber Security Technical Specification

CENELEC releases updated TS50701:2023 OT Railway Cyber Security Technical Specification

CENELEC has just released TS50701:2023 with some significant changes. Digital Transit has already incorporated these into their Railway Cybersecurity OT courses.

TS50701 is a technical specification that adapts the cybersecurity industrial control standard IEC62443 to the railway for Operational Technology (OT). In railways, OT Technology includes reliability and safety critical systems such as signalling, SCADA, door systems, brakes, etc.

A critical issue is that IT and OT should be separated and that safety and cybersecurity have complementary goals but must be treated differently – though totally coordinated.

Interested in learning more? Get in touch for more information about our services and discover what we can do to help you.

Innovation for Machinery – Digital Transit Limited awarded £50K

Innovation for Machinery – Digital Transit Limited awarded £50K

Digital Transit Limited have been awarded £50K free support to develop and productize their cutting-edge rolling stock sensing devices. The award will utilise the expertise in engineering from the University of Huddersfield.

This further consolidates DTL’s existing research being done alongside the Centre for Efficiency and Performance Engineering, and the Institute of Railway Research.

I4M is funded by the UK Research and Innovation Strength in Places Fund (SIPF) as part of the AMPI innovation initiative.

Safety Critical Software in Rail Training – Update

We have updated our course to reflect the learnings from recently issued Rail Industry Standard RIS-0745-CCS Issue: One – Client Safety Assurance of High Integrity Software-Based Systems for Railway Applications which was developed to aid clients dealing with safety critical software after the Cambrian line wrong side failure.
We have also already added a short section on software design for cyber security (IEC62443 and TS50701) and how, for example, defensive coding is vital for cybersecurity
We have been providing training in for many years now against EN50128 and the newer EN50657 for rolling stock.
We also provide safety critical assessment services for up to SIL2 against EN50128 and EN50657

Nvidia Jetson Orin release.

Digital Transit Limited are excited about the release of NVIDIA’s newest Jetson Orin products, the Orin NX, the Orin Nano and the AGX Orin. The products which are being released this year and are a huge leap for AI for video analysis. Here at DTL we are developing our own software that utilises AI on the edge, in the fog and in the cloud. The new Jetson Orin technology will allow DTL to use more powerful and energy efficient models on the edge such as faster inference for our RailSight-Assist system. The new Orin technology is a large step in the progression of AI technology in regards to their performance. Compared to the Jetson Xavier range, the AGX Orin performs up to 8 times faster than the AGX Xavier and can deliver AI performance that can reach 275 Tensor tera operations per second (TOPS). This is a significant improvement over the AGX Xavier which performs at 30 TOPS and was only released in October 2018.

We are very excited about these new products from Nvidia as they will enable us to provide lower cost, energy efficient solutions to the rail industry.

Digital Transit Limited announces new office in Huddersfield.

Digital Transit Limited (DTL) are excited to announce that a new office will be opening in Huddersfield. The new office is located in the University of Huddersfield campus in the 3M Buckley innovation centre.

The 3M Buckley innovation centre is a centre of labs and offices for enterprises and innovative businesses from across the region. Future collaborations with University of Huddersfield and DTL will include innovative new projects in condition monitoring and, media production for DTL’s future courses in safety critical software, ERTMS and rail cyber security. DTL will also be collaborating with the Institute of Rail Research (IRR) which is a world-leading centre of railway safety and engineering.

The location of the 3M Buckley innovation centre is shown in the google maps below.

The author of the banner image: https://huddersfieldhub.co.uk/ Available here.