Cyberattacks on rail and other transportation infrastructure are no longer a hypothetical scenario. Major railroads in the US, Europe and Asia have already been hit by cyberattacks .The combination of high vulnerability and the serious potential for damage, financial loss and even loss of life makes railways around the world the perfect target for both financially motivated criminal groups and hackers.

Railways at risk from cyberattacks
Although there are many variations, all modern railroads use computer systems to monitor and manage the physical machinery (operational technology) of the railroad operation. These operational technologies (OT) converge with IT networks, where they can easily be infected by malware. For most railroads, cybersecurity consists primarily of commercial security products such as simple firewalls and other government-approved antivirus tools. This is similar to the cybersecurity mechanisms in place in most small or medium-sized businesses, which are not critical to national security. This type of security may be adequate for some sectors, but it is nowhere near enough to keep a highly concentrated national critical transportation infrastructure safe from those who would wish to harm these structures. Many rail systems have already experienced cyber breaches ,whether they admit it publicly or not. Those who are lucky enough not to have experienced such attacks so far know that their time is running out.
Next-generation railway cybersecurity
In many ways, deploying next-generation safety systems on existing railways seems like an insurmountable task. The prevalence of and reliance on legacy systems, older equipment that is prohibitively expensive to upgrade , and the lack of visibility into what is happening at every end-point node pose a serious challenge, but it is one that the government cannot ignore.
Recently, a major metropolitan rail authority hired Cyberbit to implement a comprehensive cybersecurity solution capable of protecting over 150 stations and hundreds of kilometers. Within a few months, they were able to monitor the entire OT network, generating alerts about potential security threats and non-security related malfunctions.
