Rail cybersecurity is entering a new phase as regulation, digital safety, artificial intelligence and operational resilience become increasingly interconnected.
For much of the past decade, railway cybersecurity has been discussed primarily as a question of protecting networks, operational technology and critical infrastructure against attack.
That description is no longer sufficient.
Across the UK, Europe and North America, cybersecurity is becoming inseparable from railway safety, rolling-stock procurement, software assurance, regulatory compliance, data governance, artificial intelligence and supply-chain accountability.
The key question is shifting from:
How do we protect the railway from cyberattack?
to:
How do we demonstrate that increasingly digital, interconnected and AI-enabled railway systems remain safe, secure and resilient throughout their operational lives?
That change has significant consequences for railway operators, infrastructure managers, regulators, manufacturers, rolling-stock owners, systems integrators and technology suppliers.
It will also provide the central context for the 13th Annual Rail Cybersecurity Summit, taking place on 9–10 March 2027 at The Cumberland Hotel, Marble Arch, London. Join regulators, railway operators and cybersecurity leaders at the 13th Annual Rail Cybersecurity Summit, 9–10 March 2027 in London. View the programme and registration details.
The UK: digital risk is becoming a railway safety issue
One of the most significant developments in Britain is the Office of Rail and Road’s increasing focus on what it describes as digital safety.
In its latest annual report on health and safety across Britain’s railways, ORR states that digital and software-related risks are increasing as railway systems become more integrated and dependent on operational technology.
Although awareness is growing, ORR says that approaches are still developing and are not yet consistently embedded across the sector. In particular, digital and OT risks need to be integrated more fully into Safety Management Systems, with clear processes for identifying and controlling risks arising from software failure and system interaction.
This is important because it moves the discussion beyond conventional cybersecurity governance.
A railway organisation may have an information-security policy, a CISO, penetration testing and incident-response procedures. However, that does not necessarily demonstrate that software behaviour, system interfaces, configuration changes and cyber-related failures have been incorporated into the organisation’s safety case and operational risk controls.
ORR plans to publish its first Digital Safety Strategy and a new Strategic Risk Chapter during 2026. These are intended to clarify expectations as advanced digital systems become more prevalent across the railway.
This raises several practical questions:
- When does a cybersecurity weakness become a railway safety risk?
- Who owns the risk where safety engineering, software, OT and cybersecurity responsibilities overlap?
- How should software changes be assessed after a system has entered service?
- What evidence will inspectors expect to see within the Safety Management System?
- How should operators assure technology supplied and maintained by third parties?
The creation of Great British Railways will make these questions even more significant. ORR is already preparing to assess GBR’s future safety authorisation, while stressing that organisational reform must not weaken safety management or blur accountability for shared risks.
AI enters the regulatory and safety landscape
Artificial intelligence is moving quickly from experimentation into operational and regulatory use.
ORR published its Safe AI Innovation Action Plan in May 2026. It intends to clarify safety risks and regulatory expectations for AI and explore how AI can support interoperability authorisations, regulatory analysis and earlier identification of emerging issues. ORR has also indicated that it may explore approaches such as regulatory sandboxes.
The railway industry will therefore need to confront questions that extend beyond general AI governance.
For example:
- Can an AI-generated recommendation influence a safety-critical maintenance decision?
- How should railway organisations validate the data used to train or operate an AI system?
- What controls are required to detect model drift or changing system behaviour?
- How should human oversight work when AI is used at scale?
- Who is accountable when an algorithm supplied by a third party informs an operational decision?
- Can an AI system be modified continuously while the railway safety case assumes stable, validated behaviour?
ROGS remains broadly technology-neutral, but ORR has acknowledged that additional guidance may be required to support the adoption of digital and AI tools within railway safety systems.
The challenge is therefore not simply whether rail should use AI. It is how AI-enabled systems can be introduced without weakening traceability, assurance, competence or human accountability.
Cybersecurity is being built into rolling-stock procurement
The UK Department for Transport published dedicated guidance on cybersecurity in passenger rolling-stock procurement in March 2026.
The guidance applies across heavy rail, metro, light rail, trams and open-access operations. It sets expectations for contracting authorities and suppliers throughout the asset lifecycle, including specification, design, assurance, maintenance and protection against hacking, misuse and malfunction.
This is a major development.
Railway cybersecurity can no longer be treated as a technical package to be added once a train has already been designed.
Cybersecurity requirements will increasingly influence:
- procurement specifications;
- architecture and system separation;
- supplier selection;
- remote-access arrangements;
- software support periods;
- vulnerability management;
- configuration control;
- contractual responsibility;
- obsolescence planning; and
- the acceptance of trains into operational service.
The commercial implications are substantial.
A train may remain in service for 30 or 40 years, while many of its digital components, operating systems and communications technologies will have much shorter support lives. Contracts must therefore address not only the security of a product at delivery, but also who will maintain, update, monitor and ultimately replace it.
Europe: NIS2 maturity meets railway operational reality
NIS2 recognises railway undertakings and infrastructure managers as essential entities within a highly critical transport sector.
ENISA has highlighted the sector’s increasing exposure as digital transformation connects IT, OT and external systems. It has also identified legacy infrastructure, third-party dependencies and the need to implement NIS2-aligned measures as continuing challenges for rail.
The 2026 ENISA NIS360 assessment found that the criticality of the railway sector had increased, partly because of its growing strategic role in military logistics and heightened cyber-threat exposure.
That geopolitical dimension should not be overlooked.
Railways do not merely carry commuters and commercial freight. They also support national resilience, cross-border supply chains and military mobility. This may make railway infrastructure, logistics systems and passenger-information platforms increasingly attractive targets for state-aligned actors, ransomware groups and hacktivists.
ENISA’s Cyber Europe 2026 exercise brought together more than 5,000 participants to test the European response to coordinated cyber incidents affecting railway and maritime infrastructure.
The railway scenario included interference causing cross-border trains to stop, ransomware affecting passenger and administrative systems, exposure of sensitive information and disinformation intended to intensify public pressure during the incident.
This demonstrates that cyber resilience cannot be measured solely by whether a SOC detects malware.
It also depends on:
- continuity of railway operations;
- cross-border coordination;
- decision-making under uncertainty;
- accurate passenger communication;
- technical and political incident escalation;
- recovery of operational systems;
- management of misinformation; and
- cooperation between regulators, operators and national authorities.
The Cyber Resilience Act changes product responsibility
The European Cyber Resilience Act introduces horizontal cybersecurity obligations for products containing digital elements.
The full regime applies from 11 December 2027, but its reporting obligations for actively exploited vulnerabilities and severe incidents begin on 11 September 2026.
Manufacturers will be expected to address cybersecurity throughout product design, development and support. Requirements include risk-appropriate security, secure-by-default configurations and placing products on the market without known exploitable vulnerabilities.
For railway technology suppliers, this creates immediate strategic questions:
- Which onboard and trackside components fall within the CRA?
- Who is legally considered the manufacturer where systems contain numerous integrated products?
- How will vulnerabilities be reported across the OEM, integrator, operator and component supplier?
- How will suppliers provide security updates for products deployed in safety-related environments?
- Can an update be installed without reopening safety assurance?
- How will operators manage equipment with longer operational lives than the supplier’s defined support period?
The CRA is particularly important because it shifts greater responsibility towards those who place digital products on the European market.
It also introduces meaningful commercial consequences. Enforcement can include substantial fines, product restrictions, withdrawals or recalls.
Railway procurement teams will therefore need to evaluate not only technical capabilities and purchase price, but also vulnerability-handling processes, software-maintenance commitments, product documentation and long-term supplier viability.
NIS2, CRA and railway safety cannot be implemented separately
Railway organisations now face several overlapping regulatory and assurance frameworks.
NIS2 primarily focuses on the resilience and governance of essential and important entities.
The CRA focuses on the cybersecurity characteristics and lifecycle responsibilities of products with digital elements.
Railway safety legislation focuses on the safe management and operation of the railway.
Interoperability requirements address the ability of systems to function safely and consistently across the European railway network.
These frameworks affect different organisations and different stages of the lifecycle, but they frequently concern the same systems.
ERA and ENISA have formalised their cooperation to help integrate cybersecurity into railway safety and interoperability frameworks, support NIS2 implementation and assess the relevance of European cybersecurity certification schemes to railway systems.
The industry therefore needs a more joined-up assurance model.
A component should not be considered secure under one process, safe under another and interoperable under a third without understanding the assumptions, dependencies and evidence shared between them.
Europe’s digital railway creates new data and interface risks
The new European Telematics Applications TSI entered into force on 2 March 2026.
It establishes a common framework for railway data sharing, introduces harmonised data formats and includes requirements concerning data quality, cybersecurity and the safe use of information for railway operations.
It also appoints the European Union Agency for Railways as the system authority for the digitalisation of rail communications.
The benefits of interoperable railway data are clear: improved capacity management, better traffic coordination, more efficient passenger services and greater integration across national networks.
However, increased data sharing also expands the number of interfaces, dependencies and trust relationships that must be managed.
Railway organisations will need to consider:
- who can access operational data;
- how data integrity is assured;
- what happens when shared information is inaccurate or unavailable;
- whether a compromised external participant can affect wider railway operations;
- how APIs and common platforms are monitored;
- how commercial data rights interact with safety and security obligations; and
- whether a common digital architecture creates concentration risk.
Legacy rolling stock remains one of the hardest problems
New trains can be designed with modern cybersecurity requirements in mind.
Existing fleets are much more difficult.
Many trains contain proprietary networks, specialist fieldbuses, unsupported software and components created before modern cybersecurity standards existed. They may also include maintenance ports, gateways and remote-access arrangements added during successive refurbishment programmes.
Replacing these assets immediately is rarely commercially or operationally realistic.
The industry therefore needs credible methods for:
- passive network monitoring;
- secure gateways;
- segmentation;
- compensating controls;
- configuration baselining;
- retrofit intrusion detection;
- vulnerability assessment;
- obsolescence management; and
- assurance that monitoring technology cannot interfere with safety-related communications.
This was reflected in the 2026 Rail Cybersecurity Summit presentation from EKE-Electronics on the monitoring of Multifunction Vehicle Bus communications.
The presentation examined potential denial-of-service, mastership hijacking, false-data injection and configuration-manipulation scenarios, while also explaining the constraints that make practical attacks difficult. It proposed passive, non-intrusive monitoring capable of identifying unknown devices, abnormal transmissions, configuration changes and unusual data behaviour.
The next step for the industry must be to move from theoretical attack scenarios into deployment evidence, operational case studies and measured outcomes from live or representative rolling-stock environments.
North America is moving towards mandatory cyber-risk programmes
In the United States, the Transportation Security Administration has used security directives to impose cybersecurity requirements on designated freight rail, passenger rail and transit operators.
TSA is also progressing its Enhancing Surface Cyber Risk Management rulemaking, which is intended to permanently codify cybersecurity requirements for the rail and pipeline sectors and address both IT and operational technology systems.
The significance of the American approach lies in its movement from temporary emergency directives towards lasting regulatory requirements.
This provides a valuable comparison with the European model.
Europe is building a layered framework through NIS2, product regulation, safety regulation and interoperability requirements. The US approach has been more directly driven by security directives and mandatory cyber-risk programmes for designated operators.
Both approaches ultimately raise similar questions about:
- asset identification;
- segmentation;
- access control;
- incident reporting;
- cyber-response planning;
- recovery of operational systems;
- executive accountability; and
- validation that security controls work in practice.
Automated inspection and AI are changing railway assurance
The US Federal Railroad Administration continues to develop automated and AI-supported inspection capabilities.
Recent FRA research used laser triangulation and deep convolutional neural networks to analyse railway track components and support assessments of track condition and buckling resistance.
FRA also operates automated track-inspection vehicles, including autonomous geometry cars and systems supporting risk analysis, condition assessment and maintenance planning.
These technologies may improve safety and enable earlier identification of defects, but they also introduce assurance questions.
An AI system may correctly identify thousands of defects and still create serious risk if it fails to detect a rare but critical condition.
Railway organisations will need evidence showing:
- how the model was trained;
- whether its data represent real operational conditions;
- how false negatives and false positives are handled;
- when a human inspection is required;
- how performance is monitored over time;
- how changes to the algorithm are approved; and
- whether the system remains effective across different infrastructure environments.
The assurance of AI-based inspection may therefore become one of the most important intersections between railway safety, data science and cybersecurity.
Canada is integrating safety and security oversight
Transport Canada merged its Rail Safety and Rail Security functions into a single Rail Safety and Security Directorate.
The stated purpose is to create a more integrated, proactive and risk-based approach to railway oversight, supported by stronger risk analysis and modernised programme delivery.
Canada is also updating its Railway Safety Management System Regulations and progressing work on enhanced train-control requirements.
The Canadian structure is worth watching because it brings railway safety and security closer together institutionally.
This reflects the broader international trend: digital systems make it increasingly difficult to draw a clean boundary between an operational failure, a safety-management weakness and a deliberate cyber incident.
The central challenge: assuring the whole railway system
The most important conclusion from these developments is that railway cybersecurity can no longer be managed by one department or one professional discipline.
The emerging regulatory environment requires collaboration between:
- cybersecurity;
- safety engineering;
- rolling-stock engineering;
- signalling and telecoms;
- procurement;
- legal and regulatory teams;
- software and systems engineering;
- operations;
- maintenance;
- data governance; and
- executive leadership.
The railway is a system of systems.
A vulnerability in an individual component may be manageable. The greater risk can arise from its interaction with other systems, maintenance processes, suppliers and operational decisions.
That means assurance must move beyond compliance checklists and isolated technical testing.
The industry must understand how systems behave together, how changes propagate across operational environments and how responsibility is maintained across organisations and throughout the asset lifecycle.
Rail Cybersecurity Summit 2027
These issues will form the backdrop to the 13th Annual Rail Cybersecurity Summit, taking place on:
9–10 March 2027
The Cumberland Hotel, Marble Arch, London
Confirmed contributors currently include:
Office of Rail and Road
James Walker
Head of Digital Safety
Railway Safety Directorate
Eisenbahn-Bundesamt
Dr Frank Werner
IT Security Taskforce
Nederlandse Spoorwegen
Dimitri van Zantvliet
Director Digital Resilience and CISO
Nederlandse Spoorwegen
Joseph Mager
Manager Cyber Governance
Ciaran Martin
Professor of Practice in the Management of Public Organisations
Blavatnik School of Government, University of Oxford
Founder and former CEO, UK National Cyber Security Centre
The programme, speaking opportunities and commercial partnerships are now being confirmed.
The 2027 programme will examine:
- ORR’s emerging digital-safety expectations;
- cybersecurity within Safety Management Systems;
- NIS2 and the Cyber Resilience Act;
- rolling-stock procurement and lifecycle assurance;
- the security of legacy and connected fleets;
- artificial intelligence and autonomous agents;
- supply-chain responsibility;
- railway data and interoperability;
- incident response and operational resilience; and
- the convergence of safety, security and software assurance.
The programme, speaking opportunities and commercial partnerships are now being confirmed.
Rail cybersecurity is entering a new phase.
The organisations that respond successfully will be those that stop treating cyber risk as an isolated technical problem and begin managing it as an integral part of railway safety, engineering, procurement and operational resilience.
Rail Cybersecurity Summit 2027
9–10 March 2027 | London
#RailCybersecurity #RailSafety #OperationalTechnology #CyberSecurity #ArtificialIntelligence #NIS2 #CyberResilienceAct #RollingStock #CriticalInfrastructure #DigitalSafety
