METRO Magazine Logo
MenuMENU
SearchSEARCH

How Transit Agencies Can Stay on Track with Cyber Security

Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

by Ken Keiser
September 29, 2017
How Transit Agencies Can Stay on Track with Cyber Security

 

5 min to read


Cyber security of trains, trolleys, and subways is an important national priority.
An organization’s information technology (IT) group is usually charged with maintaining digital assets and defending the loss of confidential information.

However, IT may ignore the cyber security ecosystem of the operational technology (OT) (the mechanical and electrical systems that control the rolling stock) side of the agency. The threat to these systems is growing.

Ad Loading...

Trains and subways rely on industrial control systems (ICSs) to keep them moving. However, ICS devices sometimes have features with inherent vulnerabilities. These devices may have Wi-Fi capability vulnerable to malware intrusion, and while transit agencies may not be using these features, they are still lurking in the background, ready to be exploited by bad actors.

Often, IT and OT teams work together, but differences between IT and OT priorities and culture become apparent. Availability — making the transit system run on time — is the prime directive of operation. IT often lacks understanding that a very small gap in availability is unacceptable in the OT environment.

Vulnerability Awareness
The lack of awareness of the vulnerabilities that have snuck into the OT world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving. Weak authentication, abuse of access authority, and the prevalence of removable media — often ignored by control engineers in the transit system — are threat vectors that allow intrusion into the transit authority’s OT equipment. In addition, transit systems often rely on legacy devices that have long lifecycles compared to IT appliances and PCs. Unfortunately, legacy systems don’t have cyber security features. This lack of integrated product security must be compensated for by a holistic program within the transit system.

So far, most transit systems have been lucky. But there are real-world examples of breaches. In 2008, a Polish train was remotely diverted to another track by a 14-year-old boy with a radio transmitter and a knowledge of the train system he gained by hanging out around the tracks.

We have found in our role as cyber security assessors that OT managers have often emphatically announced that their area is “air-gapped” and thus invisible to bad actors. These managers may be overlooking several issues, including:

Ad Loading...
  • Their OT area may include an overlooked historian that moves data from the OT equipment to another business unit.

  • USB ports are present that allow anyone with a memory stick to close this air-gap.

  • Employees may harbor malware in their cell phones, USB devices, or laptops, all of which can come in freely through their gate.

  • Transit agencies should realize there are real vulnerabilities in their OT domain and take steps to improve security defenses.

Improvement Hurdles
Why are transit agencies slow to make improvements? In addition to different OT and IT cultures, a major hurdle to improving transit cyber security is that transit agencies are often divided into silos of responsibility. For example, the electrical power group may have different ICS equipment than the communication and signals group, which has different systems than the dispatch area. This situation prevents a holistic approach to protecting the system.

The lack of awareness of the vulnerabilities that have snuck into the world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving.

Here are some of the steps successful agencies take for a more holistic approach to cyber security:

1. Provide leadership.
The board of directors or CEO of the transit agency must lead the charge for change to a culture in which cyber security is important and rewarded on the OT side.

Ad Loading...

2. Be aware of OT.
IT management should realize the importance (and uniqueness) of the OT space.

3. Start a task force.
A group made up of IT and OT departments solves the issues of misunderstanding and inertia, and communication between groups fosters success in any cyber security initiative.

4. Pick a standard.
There are a few good base standards for cyber security. The IT world uses ISO 27000 series standards, but some other standards have more of an OTperspective. The NIST (National Institute of Standards of Technology) Framework for Improving Critical Infrastructure Cyber security provides a roadmap and is free from the Department of Commerce.

5. People. Process. Technology.
The hard work of cyber defense involves multiple depths and includes physical devices or software as well as domains that the OT group alone cannot always change. Things like people and processes must be addressed.

6. Provide governance.
The task of continuous improvement is one of the most important but overlooked topics when discussing cyber security defenses. An institutional effort is necessary to ensure the cyber security of the OT side of transit agencies, remembering that cyber security is ever-changing and evolving. Intelligent adversaries are attacking your system and finding new vulnerabilities all the time. This fact requires constant countermeasures in IT and OT to keep up with the changes in environment. IT is familiar with this drill, but the personnel in dispatch, positive train control, or other OT areas are often unaware of how to do this.

Ad Loading...

7. Think outside the box.
OT engineers must think like a hacker to realize the vulnerabilities they have around them. Who best to defend a signaling system than signal engineers?

Related: ITS America forms transportation-focused cybersecurity task force

These steps will help any transit agency get ahead of the cyber threats to its operations. Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

Subscribe to Our Newsletter

More Security and Safety

Photo of disaster in neighborhood near a highway
Security and Safetyby Alex RomanApril 30, 2026

How the Motorcoach Industry Supports Disaster Response and National Preparedness

Fred Ferguson, president and CEO of the American Bus Association (ABA), discussed how the industry prepares for emergencies, the growing recognition of motorcoaches as critical infrastructure, and steps operators can take to strengthen disaster readiness.

Read More →
DART light rail and transit bus.
Security and Safetyby StaffApril 29, 2026

Dallas Area Rapid Transit Strengthens Safety with Expanded Security Presence

The approved contract modification will increase funding for transit security officer services to a total not-to-exceed amount of $32.1 million, ensuring a continued and visible security presence across DART’s buses, trains, stations, and facilities.

Read More →
Trains at railroad crossings
Security and Safetyby StaffApril 27, 2026

USDOT Invests $1.1B to Enhance Safety Infrastructure at Railroad Crossings

Every year, more than 2,000 incidents and 300 fatalities occur at railroad crossings nationwide. 

Read More →
Ad Loading...
Siemens and LK Comstock photo for Fulton-Liberty Lines
Security and Safetyby StaffApril 27, 2026

NYC’s Fulton–Liberty Lines Get Digital Signal Upgrade from Siemens and L.K. Comstock

The Siemens CBTC System, Trainguard MT, in compliance with New York Subway Interoperability Interface Specifications, enables trains to run as close as 90 seconds apart, using next-generation signaling and continuous communication to keep operations moving seamlessly.

Read More →
SEPTA Transit Police officers
Security and Safetyby StaffApril 21, 2026

Report: Crime on Philadelphia's SEPTA Continues to Drop

According to the new quarterly data, there were double-digit reductions in five of the eight serious crime categories, including aggravated assaults and robberies.

Read More →
A product grouping image of the AngelTrax Vulcan Series VX4AI All-in-One MDVR and V1284HC MDVR
Technologyby StaffApril 8, 2026

AngelTrax, City of Freeport Partnership to Enhance Fleet Safety

The project, finalized on February 12, provides the city with two different configurations of high-definition cameras to outfit 16 buses in the Pretzel City Area Transit fleet.

Read More →
Ad Loading...
Two ABQ RIDE buses
Security and Safetyby StaffApril 1, 2026

ABQ RIDE Launches ‘Drive Safe, Ride Safe’ Campaign to Strengthen Internal Safety Culture

The 12-month initiative focuses on staff engagement, training, and reducing preventable incidents.

Read More →
frontrunner bus
SponsoredApril 1, 2026

Breaking Accessibility Barriers with the Low Floor Frontrunner Minibus

Accessible transit isn’t a feature—it’s a responsibility. This whitepaper explores how the Low-Floor Frontrunner is redefining mobility with a breakthrough design that removes barriers, empowers riders, and delivers measurable operational advantages for agencies. Discover why this next generation minibus is setting a new standard for inclusive transportation.

Read More →
PSTA, City of Dunedin, and Congresswoman Anna Paulina Luna during a check ceremony for restoration of the Dunedin Pier
Security and Safetyby StaffMarch 31, 2026

PSTA, City Officials Receive Money to Repair Hurricane Ravaged Pier

The funds will specifically reconstruct the portion of the pier used by PSTA’s Clearwater Ferry, creating a permanent dock for the ferry service, which serves as an important transportation and tourism link to other Pinellas County communities.

Read More →
Ad Loading...
A blue and white graphic with Safety Vision's logo and text reading "Report Shows Growing Impact of AI-Powered Video."

AI Video Systems Emerging as Core Safety Infrastructure, Safety Vision Report Finds

Between accident prevention and insurance savings, new research outlines how transportation fleets are leveraging intelligent video and telematics technologies.

Read More →