Rail cybersecurity is moving into a very different phase.

For much of the past decade, the industry’s cybersecurity conversation has focused on protecting operational technology, segmenting networks, securing legacy systems and improving visibility across increasingly complex railway environments.

Those challenges have not disappeared. But the railway itself is changing.

Connected rolling stock, digital signalling, remote maintenance, cloud platforms, software-defined systems, satellite and mobile communications, artificial intelligence and increasingly complex technology supply chains are creating a railway that is more interconnected than ever before.

The cybersecurity question is therefore becoming much broader.

It is no longer simply: How do we protect the railway network?

It is increasingly: How do we maintain safe and resilient railway operations when so much of the technology we depend upon is interconnected, externally managed or outside our direct control?

That question will sit at the centre of the 13th Annual Rail Cybersecurity Summit, taking place in London on 9–10 March 2027.

Rail cybersecurity is becoming a question of dependency

Modern railway operations depend on a growing ecosystem of technology providers, communications networks, software platforms, rolling-stock systems and digital services.

An operator may remain accountable for delivering a safe and reliable railway while elements of the technology supporting that railway are designed, maintained, updated or operated by multiple external organisations.

That creates a fundamentally different cybersecurity environment.

The security boundary can now extend from traditional rail operational technology into onboard systems, telecommunications providers, cloud infrastructure, satellite connectivity, software suppliers and remote support environments.

The challenge is not only preventing cyber intrusion.

Rail organisations increasingly need to understand which digital services are operationally critical, what happens when those services are unavailable or compromised, which organisations control them and how railway operations continue safely under degraded conditions.

This shift from system security towards operational resilience will be one of the defining themes for railway cybersecurity in 2027.

AI changes both sides of the cybersecurity equation

Artificial intelligence is rapidly becoming part of the cybersecurity discussion across critical infrastructure.

Rail organisations are beginning to consider how AI can improve monitoring, anomaly detection, incident investigation, predictive maintenance and operational decision-making.

But the same technology can also change the capability of attackers.

Automated reconnaissance, increasingly sophisticated social engineering, AI-assisted vulnerability discovery and autonomous attack techniques could significantly increase the speed at which cyber threats develop.

At the Rail Cybersecurity Summit 2027, Dimitri van Zantvliet, Director Digital Resilience / CISO at Nederlandse Spoorwegen (NS), will examine the relationship between cybersecurity and artificial intelligence and how rail organisations should prepare for increasingly autonomous cyber threats.

The important question for railway organisations is therefore not simply whether to use AI.

It is how intelligent technologies can be introduced while maintaining appropriate governance, human oversight, safety assurance and resilience.

The connected train creates a new cybersecurity boundary

Rolling stock is becoming a connected digital platform.

Modern trains increasingly communicate with infrastructure, depots, maintenance systems, operational platforms and external networks. Passenger systems, diagnostic systems, remote monitoring, software updates and onboard applications are creating continuous flows of information between the train and the wider railway ecosystem.

The arrival of technologies including 5G, FRMCS, satellite communications and Low Earth Orbit connectivity will expand those possibilities further.

But increased connectivity also creates new dependencies.

At the 2027 Summit, Marc Silverwood, Onboard Systems Manager at Northern Trains, and Gavin McAuley, Onboard Systems Compliance Manager, will explore this issue through the session:

The Connected Train: Who Controls the Data?

The discussion will examine onboard connectivity, satellite and LEO communications, encryption, data sovereignty, supplier dependency and the increasingly complex question of who controls railway information as it moves between trains and external technology environments.

Connected trains illustrate the wider challenge facing the industry.

Digital transformation creates enormous operational opportunities, but every new connection also creates a relationship that must be understood, governed and protected.

Railway safety and cybersecurity are converging

One of the most important changes taking place across the sector is the increasingly close relationship between cybersecurity and railway safety.

Software is now embedded throughout railway operations.

Digital signalling, train control, rolling-stock systems, maintenance platforms, communications infrastructure and operational decision-making increasingly depend on interconnected digital technologies.

This means that cyber risk cannot always be treated as a separate information-security discipline.

The potential operational consequences of a cybersecurity incident need to be considered alongside engineering assurance, safety management, resilience and operational risk.

The 2027 speaker programme reflects that shift.

Dr Frank Werner of the Eisenbahn-Bundesamt (EBA) IT Security Taskforce will examine the relationship between railway safety oversight, cybersecurity and European regulation.

The current Summit programme also includes James Walker, Head of Digital Safety within the Railway Safety Directorate at the UK Office of Rail and Road, bringing the regulatory and digital-safety perspective directly into the discussion.

For operators, infrastructure managers and suppliers, this convergence will increasingly require cybersecurity teams, engineering teams, safety professionals and operational leaders to work together rather than managing cyber risk in isolation.

NIS2 moves the conversation from regulation to implementation

European cybersecurity regulation is also moving into a new phase.

For many organisations, the discussion around NIS2 is shifting from understanding the regulation towards demonstrating how cyber risk is actually governed and managed.

That raises practical questions around accountability, incident reporting, supply-chain risk, executive responsibility, resilience and cybersecurity governance.

Joseph Mager, Manager Cyber Governance at Nederlandse Spoorwegen, will share early experience and lessons from NIS2 implementation and examine what the new regulatory environment means for railway governance and cyber-risk management.

For rail organisations operating across European markets, regulatory compliance will increasingly intersect with procurement, engineering, software lifecycle management, supplier assurance and operational resilience.

The challenge will be turning regulatory requirements into measures that work inside real railway environments.

What must continue operating during a major cyber incident?

Perhaps one of the most important resilience questions is also one of the simplest:

What absolutely has to keep working?

Railway organisations operate extremely complex environments containing thousands of systems, services, assets and dependencies.

Trying to protect every system equally is neither realistic nor necessarily the best way to build resilience.

Tom Remberg, CISO at Bane NOR, together with Trond Eskild Tingstad-Stav from Traffic Management, will explore how the Norwegian infrastructure manager is defining its Minimum Viable Company.

The concept focuses attention on identifying the functions that must continue during severe disruption.

Understanding those critical functions allows organisations to prioritise cybersecurity investment, recovery planning, business continuity and operational decision-making around what the railway actually needs to remain operational.

That is an increasingly important shift.

Cyber resilience is not simply the ability to prevent an attack.

It is the ability to understand the impact of disruption, contain it, recover from it and continue operating safely.

Protecting critical infrastructure in an age of technological dependency

Opening the Rail Cybersecurity Summit 2027 will be Ciaran Martin CB, founding CEO of the UK’s National Cyber Security Centre.

Martin will examine the wider challenge of protecting critical infrastructure in an age of technological dependency.

It is a particularly relevant discussion for rail.

Railway organisations are simultaneously becoming more digital, more connected and more dependent on technology ecosystems that extend well beyond the traditional railway perimeter.

Understanding those dependencies—and determining how organisations remain resilient when they fail—is rapidly becoming one of the industry’s most important cybersecurity challenges.

Bringing the railway cybersecurity community together

The Rail Cybersecurity Summit returns to London for its 13th annual edition on 9–10 March 2027 at The Cumberland Hotel, Marble Arch.

The Summit brings together rail operators, infrastructure managers, rolling-stock manufacturers, technology suppliers, regulators, government stakeholders and cybersecurity leaders to examine the practical realities of securing increasingly connected railway environments.

The 2027 programme will explore artificial intelligence, connected rolling stock, digital safety, NIS2, operational resilience, supply-chain dependency, software assurance, remote access, asset visibility, incident response and the growing relationship between cybersecurity and railway safety.

For organisations responsible for operating, engineering, supplying or protecting modern railway systems, the conversation is moving beyond individual cybersecurity controls.

The question now is how the rail industry builds safe, secure and resilient operations across an increasingly interconnected digital ecosystem.

Explore the Rail Cybersecurity Summit 2027 programme and confirmed speakers.

Register for the Rail Cybersecurity Summit 2027 – London, 9–10 March.