The digital transformation of the transport sector, and especially the railway sector, is advancing on a particularly complex infrastructure. New digital solutions must coexist and integrate with electromechanical systems that can be up to 40 years old, geographically distributed and connected to an extensive supply chain.

At the same time, systems such as ERTMS (European Rail Traffic Management System) and ETCS (European Train Control System) are becoming the backbone of European railway signaling, bringing cyber risk increasingly closer to essential transport systems for train control.

This evolution occurs in a context of increasing exposure. ENISA’s 2025 threat landscape report highlights that transport was the second most attacked sector in Europe, concentrating around 7.5% of recorded cybersecurity incidents. Furthermore, recent DDoS attacks against European railway operators and software vulnerabilities affecting rolling stock show that the risk is real and tangible.

An incident in a railway environment can not only impact the circulation and reliability of trains carrying thousands of passengers, but can also cause disruptions throughout the network, with consequent economic loss and possible regulatory sanctions.

Nine priorities to strengthen railway resilience

Drawing on insights from its EMEA rail industry experts, Fortinet identifies nine priority areas:

  1. Manage IT/OT convergence. The increasing connection between corporate systems, operational control environments, onboard systems and passenger services increases the potential points of compromise. Operators need visibility over their entire infrastructure and jointly manage IT and OT risks.
  1. Protect legacy systems. Some rail technology remains operational for decades and was not designed with cybersecurity in mind. Segmentation, monitoring and application of risk-based controls are especially relevant as your modernization progresses.
  1. Integrate operational security and cybersecurity. Common controls in enterprise environments can cause latency, instability, or affect certifications of critical systems. Therefore, they must be adapted to the specific conditions of the railway and undergo continuous testing.
  1. Manage third-party and supply chain risk. Manufacturers, signaling and telecommunications providers, integrators and maintenance teams form a broad ecosystem over which operators do not always have complete control.
  1. Protect remote and field access. Essential for the maintenance and diagnosis of geographically distributed networks, they also constitute possible intrusion routes. Identity control, third-party permissions, segmentation and session management take on special importance here.
  1. Prepare for the transformation of telecommunications. The migration from GSM-R to FRMCS, based on higher bandwidth 5G and IP communications, will enable more advanced and data-driven operations, but will also expand the attack surface and add new challenges related to identity, virtualization and network monitoring.
  1. Respond to a growing threat environment. As it is a strategic infrastructure, the sector must be prepared against different threats, including sophisticated attacks by states.
  1. Adapt detection and response to the railway environment. Aggressive scanning or containment actions can interfere with OT operations. Monitoring must be passive, take into account the operational context and preserve the security of operations even in degraded situations.
  1. Overcome governance fragmentation. Cyber ​​risk affects engineering, operations, telecommunications, security and management. The challenge is to achieve shared and coordinated responsibility, also connecting the railway regulatory and cybersecurity frameworks.