International Security Journal hears exclusively from Jorge Aldegunde, Global Head of Railway Services at DNV about railway cybersecurity.
It should come as no surprise that we now live in a digital world.
Digitalisation and automation have changed almost every aspect of how we live, travel and work, bringing widespread efficiencies and making the transfer of information easier than ever before.
In line with this, it has driven a step change in how industries manage both safety and security, helping to solve old problems, but also opening the gates to a suite of new threats that need to be combated.
The rail sector is no different.
Here, cybersecurity has become a critical consideration alongside traditional safety measures for passengers, staff and infrastructure, meaning data and digital systems must be as closely protected as the people and cargo being transported.
As rail systems become increasingly digitalised, they will face a wider range of threats than previously experienced, with dangers ranging from targeted ransomware and supply chain attacks to insider sabotage and remote exploits.
The cyber-landscape is constantly evolving, and operators must remain vigilant if they are to stay ahead of bad actors, ensuring that both Information Technology (IT) and Operational Technology (OT) systems are not compromised.
Cybersecurity must become a continuous process
Security assessments delivered by assurance partners during the early phases of a new project, or when a system is being upgraded, can be useful tools, but they can only go so far.
It is a snapshot in time, not a catch-all safeguard. Rail safety has long relied on a static model, where standards and assessments remain broadly valid over time because the underlying risks shift only gradually.
This, however, is changing as we progress through the new era of digital risk.
The static approach is being replaced by a much more digitally aware mindset, one that promotes a culture of continuous monitoring, adaptation and response.
In practice, this means the work of an assurance partner cannot stop once a system is signed off and operational.
Security products must be maintained and patched on an ongoing basis.
Newly disclosed vulnerabilities need to be assessed for their potential to be exploited, and addressed before they can be.
Operators must also have a clear plan for what happens when, not if, an attack succeeds, and they must have a sense of how quickly a system can be isolated, how operations may continue in the interim and how normal service can be restored.
Cyber-resilience, in this sense, is as much about the speed of recovery as it is about preventing a breach.
The stakes of getting this wrong are considerable.
An operator that invests in a thorough security compliance exercise during a project’s capital phase, only to let that vigilance lapse once the system is live, risks having done the work for nothing if security measures become outdated.
Turning cyber-risk into operational resilience
Adopting a continuous approach also allows operators to treat digital transformation as an ongoing opportunity rather than a recurring risk to operations.
New automation, new digital services and system upgrades no longer need to trigger a fresh cybersecurity and safety review from scratch.
Instead, they can be absorbed into a live, evolving risk picture, one that is built to keep pace with the system it protects rather than to describe it at a single moment in time.
DNV plays an active role in supporting rail customers to manage cyber-risk and stay ahead of looming threats.
Our global network of rail specialists helps organisations identify weaknesses in networks, assets, applications and control systems by using penetration testing, vulnerability scanning and threat modelling techniques to uncover exploitable risks and guide remediation based on criticality and cost-benefit analysis.
One recent example is DNV’s selection to provide specialised cybersecurity services for the Santiago de los Caballeros monorail system in the Dominican Republic, covering safety-critical railway systems including signalling, train control, rolling stock and power supply.
We also support clients to stay in line with local, national and international regulations and standards.
It has been encouraging to see policy moving in the right direction and pushing operators to take on a more rigorous approach to digital safety, but it does not come without complexity.
Driving the new approach with regulation
This ongoing need for cybersecurity assurance is increasingly being reinforced by regulation and international standardisation efforts.
Regulations such as the EU’s Cyber Resilience Act (CRA) are set to introduce mandatory cybersecurity requirements for products with digital elements, creating new obligations across the rail value chain.
The CRA creates a requirement for products used in Europe to be kept secure against threats throughout their operational life including patches, updates and taking steps to address vulnerabilities.
For the rail sector, however, this poses a distinct challenge.
Trains and the associated infrastructure are not replaced on a regular basis and may remain in service for substantial periods of time.
Operators must take time to assess how these requirements apply to older, already-deployed systems, while new systems need to be designed from the outset with full lifecycle management and resilience in mind.
International frameworks such as IEC 62443, a globally recognised series of standards covering the security of Industrial Automation and Control Systems (IACS) and OT, and IEC TC 9, which is responsible for the international standardisation of electrical equipment and systems used in railways, offer useful reference points for what implementing and maintaining that security should look like.
These sit alongside other horizontal, cross-sector regulations addressing cybersecurity obligations for companies operating in critical infrastructure, as well as separate legislation governing conformity assessment processes.
However, each was designed to apply broadly across industries, rather than with rail’s own layered structure of systems, subsystems, components and products in mind.
To address this, and give the rail sector a common cybersecurity framework, DNV is working with collaborators from more than 20 countries to develop the first dedicated international standard for rail systems: IEC 63452.
Expected to be publicly available in early 2027, the standard will set out comprehensive, full-lifecycle cybersecurity requirements for both new and legacy rail systems, covering the entire IEC TC 9 scope.
The new standard builds on established railway cybersecurity practices in Europe such as TS 5070, which provides a structured and lifecycle-oriented approach to managing cybersecurity risks in railway applications.
IEC 63452 uses this specification as a baseline and adapts principles from established frameworks including IEC 62443 to provide operators with a clearer route to meeting regulatory requirements while defending against emerging threats.
In practice, the benchmark will mandate a unified risk-based framework for rail operators to protect OT, including signaling, passenger Wi-Fi and rolling stock, against cyber-attacks throughout the entire lifecycle of the rail product.
Preparing rail systems for the future
Compliance and readiness for frameworks such as this will be a necessity, so those that act early to prepare will be best placed to navigate this new landscape smoothly.
Expert advice can help bridge that gap, preventing operators who believe they are secure on day one of compliance with policy from finding themselves exposed on day two.
The threat environment in this industry is more dynamic than it has ever been, and those that embrace a lifecycle approach to security, rather than treating it as a box to be ticked once, will be the ones best placed to keep pace with the evolving threats rail operators face.
Keeping rail cybersecurity on track requires vigilance, adaptation and continuous monitoring.
Much like the railway itself, it is a journey, not a destination.
