Consulting · Railways

Cybersecurity for signalling, rolling stock and the systems that keep trains moving.

Rail cybersecurity has to sit alongside safety assurance, not compete with it. We work to TS 50701 and IEC 62443 in environments where availability and safety integrity are non-negotiable — signalling, interlocking, depot systems, stations and rolling stock.

TS 50701
Railway cybersecurity
IEC 62443
IACS foundation
EN 50126
RAMS alignment

Standards in scope

  • CLC/TS 50701

    Railway applications — Cybersecurity

  • IEC 62443

    Industrial automation and control systems security

  • EN 50126

    RAMS — Reliability, availability, maintainability and safety

Standards

Rail-specific requirements, built on the IEC 62443 foundation.

TS 50701 adapts IEC 62443 for the railway context and connects it to the safety lifecycle. We work the two together so cybersecurity evidence lands in a form your safety assurance process can actually accept.

CLC/TS 50701

Railway applications — Cybersecurity

The railway-sector application of industrial cybersecurity principles: system definition, zoning for rail architectures, risk assessment and the interface between cybersecurity and safety assurance.

How we support you

  • System definition and railway asset inventory
  • Zone and conduit model for signalling and station systems
  • Rail-context cybersecurity risk assessment
  • Security requirements apportioned across suppliers
  • Cybersecurity case aligned to the safety case
  • Interface with RAMS and safety authority expectations
IEC 62443

Industrial automation and control systems security

The underlying series that TS 50701 builds on — used here for zone and conduit risk assessment (3-2), system security levels (3-3) and supplier product requirements (4-1, 4-2).

How we support you

  • IEC 62443-3-2 risk assessment for rail subsystems
  • Target security level allocation per zone
  • SL-A versus SL-T verification
  • Supplier secure development assessment (4-1)
  • Component capability review (4-2)
  • Security programme design for the operator (2-1)
EN 50126

RAMS — Reliability, availability, maintainability and safety

The rail lifecycle framework cybersecurity has to align to, so that security controls are introduced without undermining availability or safety integrity commitments.

How we support you

  • Cybersecurity activities mapped to RAMS lifecycle phases
  • Impact analysis of security controls on availability
  • Change and configuration control alignment
  • Evidence structured for assurance review
  • Operational and maintenance security procedures
  • Cross-discipline workshops with safety teams
Services

Where we typically get involved.

The same seven services run across every practice, so you can compare scope without re-learning the menu.

Risk assessment

Structured risk assessment to identify what can actually go wrong, how likely it is, and what it would cost you.

Advisory & consulting

Strategy, governance and architecture guidance shaped around your operating model rather than a template.

VA-PT & security testing

Vulnerability assessment and penetration testing, scoped so that testing never threatens availability.

Compliance & audit readiness

Gap analysis, evidence assembly and internal audit so the first challenge to your evidence is not the assessor's.

Implementation support

Turning designs into deployed controls — segmentation, hardening, access control and monitoring.

Security operations

Continuous monitoring, detection and incident response support suited to the environment's constraints.

Training & capability

Building internal capability so the programme keeps running after the engagement ends.

Where we get involved

Typical engagements.

TARA & risk assessment

Structured threat and risk assessment across signalling, interlocking, SCADA and station systems, with results expressed in operational terms.

Architecture & segmentation

Zone and conduit design for trackside, depot, station and control centre networks, including remote maintenance access pathways.

Rolling stock security

On-board network review, train-to-ground communication security and supplier security requirement definition for new build and retrofit.

Tender & supplier assurance

Cybersecurity requirements for tenders, supplier capability assessment and review of contractor-submitted security documentation.

Monitoring & operations

OT monitoring design for rail environments and incident response procedures that account for service continuity and passenger safety.

Assurance & audit support

Cybersecurity case preparation and support through internal, client and authority review.

Environments

Systems we work across

  • Signalling and interlocking systems
  • CBTC and train control systems
  • Station and tunnel SCADA
  • Depot and maintenance systems
  • Rolling stock on-board networks
  • Operations control centres
  • Passenger information and ticketing interfaces
  • Trackside telecom and transmission networks
Work products

What you receive

  • Railway asset register and system definition
  • Zone and conduit architecture with risk register
  • Cybersecurity requirements specification for suppliers
  • Gap assessment against TS 50701 and IEC 62443
  • Cybersecurity case aligned to safety assurance
  • Remediation and implementation roadmap
Consulting enquiries

Working on a rail cybersecurity submission?

Whether it's a new line, a resignalling programme or an operator-side security programme, tell us the scope and the assurance milestone you're working to.

Raise an enquiry otfuriouswarrior@svratechcyber.com