METRO Magazine Logo
MenuMENU
SearchSEARCH

How Transit Agencies Can Stay on Track with Cyber Security

Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

by Ken Keiser
September 29, 2017
How Transit Agencies Can Stay on Track with Cyber Security

 

5 min to read


Cyber security of trains, trolleys, and subways is an important national priority.
An organization’s information technology (IT) group is usually charged with maintaining digital assets and defending the loss of confidential information.

However, IT may ignore the cyber security ecosystem of the operational technology (OT) (the mechanical and electrical systems that control the rolling stock) side of the agency. The threat to these systems is growing.

Ad Loading...

Trains and subways rely on industrial control systems (ICSs) to keep them moving. However, ICS devices sometimes have features with inherent vulnerabilities. These devices may have Wi-Fi capability vulnerable to malware intrusion, and while transit agencies may not be using these features, they are still lurking in the background, ready to be exploited by bad actors.

Often, IT and OT teams work together, but differences between IT and OT priorities and culture become apparent. Availability — making the transit system run on time — is the prime directive of operation. IT often lacks understanding that a very small gap in availability is unacceptable in the OT environment.

Vulnerability Awareness
The lack of awareness of the vulnerabilities that have snuck into the OT world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving. Weak authentication, abuse of access authority, and the prevalence of removable media — often ignored by control engineers in the transit system — are threat vectors that allow intrusion into the transit authority’s OT equipment. In addition, transit systems often rely on legacy devices that have long lifecycles compared to IT appliances and PCs. Unfortunately, legacy systems don’t have cyber security features. This lack of integrated product security must be compensated for by a holistic program within the transit system.

So far, most transit systems have been lucky. But there are real-world examples of breaches. In 2008, a Polish train was remotely diverted to another track by a 14-year-old boy with a radio transmitter and a knowledge of the train system he gained by hanging out around the tracks.

We have found in our role as cyber security assessors that OT managers have often emphatically announced that their area is “air-gapped” and thus invisible to bad actors. These managers may be overlooking several issues, including:

Ad Loading...
  • Their OT area may include an overlooked historian that moves data from the OT equipment to another business unit.

  • USB ports are present that allow anyone with a memory stick to close this air-gap.

  • Employees may harbor malware in their cell phones, USB devices, or laptops, all of which can come in freely through their gate.

  • Transit agencies should realize there are real vulnerabilities in their OT domain and take steps to improve security defenses.

Improvement Hurdles
Why are transit agencies slow to make improvements? In addition to different OT and IT cultures, a major hurdle to improving transit cyber security is that transit agencies are often divided into silos of responsibility. For example, the electrical power group may have different ICS equipment than the communication and signals group, which has different systems than the dispatch area. This situation prevents a holistic approach to protecting the system.

The lack of awareness of the vulnerabilities that have snuck into the world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving.

Here are some of the steps successful agencies take for a more holistic approach to cyber security:

1. Provide leadership.
The board of directors or CEO of the transit agency must lead the charge for change to a culture in which cyber security is important and rewarded on the OT side.

Ad Loading...

2. Be aware of OT.
IT management should realize the importance (and uniqueness) of the OT space.

3. Start a task force.
A group made up of IT and OT departments solves the issues of misunderstanding and inertia, and communication between groups fosters success in any cyber security initiative.

4. Pick a standard.
There are a few good base standards for cyber security. The IT world uses ISO 27000 series standards, but some other standards have more of an OTperspective. The NIST (National Institute of Standards of Technology) Framework for Improving Critical Infrastructure Cyber security provides a roadmap and is free from the Department of Commerce.

5. People. Process. Technology.
The hard work of cyber defense involves multiple depths and includes physical devices or software as well as domains that the OT group alone cannot always change. Things like people and processes must be addressed.

6. Provide governance.
The task of continuous improvement is one of the most important but overlooked topics when discussing cyber security defenses. An institutional effort is necessary to ensure the cyber security of the OT side of transit agencies, remembering that cyber security is ever-changing and evolving. Intelligent adversaries are attacking your system and finding new vulnerabilities all the time. This fact requires constant countermeasures in IT and OT to keep up with the changes in environment. IT is familiar with this drill, but the personnel in dispatch, positive train control, or other OT areas are often unaware of how to do this.

Ad Loading...

7. Think outside the box.
OT engineers must think like a hacker to realize the vulnerabilities they have around them. Who best to defend a signaling system than signal engineers?

Related: ITS America forms transportation-focused cybersecurity task force

These steps will help any transit agency get ahead of the cyber threats to its operations. Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

Subscribe to Our Newsletter

More Security and Safety

Transit Leaders Gather for National Safety Summit
Security and Safetyby Alex RomanSeptember 16, 2026

Transit Agencies Highlight Safety Gains at National Summit

Leaders from 15 major transit systems shared crime-reduction results and safety initiatives while discussing the role of continued federal support.

Read More →
DART's light rail station at 8th and Corinth
Security and Safetyby Alex RomanSeptember 10, 2026

DART Launches Major Security, Fare Enforcement Initiative

The 90-day demonstration will deploy coordinated security teams at five light rail stations while testing controlled access and gathering data to guide future investments.

Read More →
RTD Launches All-in-One NextRide App
Technologyby Alex RomanAugust 26, 2026

RTD Launches NextRide App to Consolidate Trip Planning, Fares, Security Reporting

The app expands on RTD’s existing NextRide web application and allows customers to view real-time vehicle locations and service alerts, purchase and store digital fares, and access customer support.

Read More →
Ad Loading...
A blue and white graphic with technician hands working on an engine and text reading "TAPTCO Updates OSHA Compliance Training for Transit Maintenance."
Security and Safetyby Elora HaynesAugust 25, 2026

TAPTCO Updates OSHA Compliance Training for Transit Maintenance Operations

The revamped program addresses 26 OSHA standards for maintenance facilities, with TAPTCO pointing to training, documentation, and everyday shop hazards as continuing challenges for transit operations.

Read More →
An image of a doorway on a public transit vehicle with a yellow outline overlay.
SponsoredAugust 18, 2026

How VaporVision Adds Value to Transit Door Systems

Wabtec engineers explain how the system improves doorway detection, strengthens diagnostics and gives transit agencies and OEMs greater operating flexibility.

Read More →
An Amtrak Cascades Airo Trainset at a station.
Railby Alex RomanAugust 14, 2026

FRA Announces $5.3B in Rail Investments, Including $2B for Amtrak

Funding will support grade-crossing improvements, infrastructure upgrades, and new Amtrak equipment in 23 states.

Read More →
Ad Loading...
Layered Safety Strategies Take Hold in Chicago and Maryland
Security and Safetyby Alex RomanAugust 13, 2026

Chicago, Maryland Expand Non-Law-Enforcement Safety, Rider Support

The CTA and MTA are launching new programs aimed at de-escalation, crisis response, rider assistance, and greater transparency.

Read More →
AI Powers Bus Lane Enforcement
Technologyby Alex RomanAugust 12, 2026

LA Metro, City of West Hollywood, and Partners Advance Smarter Bus Lane Enforcement

The award-winning partnership combines AI-powered detection with human oversight to improve bus reliability, accessibility, and enforcement efficiency.

Read More →
A man speaks with two Los Angeles Metro Ambassadors.
Security and Safetyby Elora HaynesAugust 4, 2026

LA Metro Reports 57% Decline in Homelessness on Transit System Since 2024

The agency's latest homelessness count offers new data on how care-based services and cross-sector partnerships can complement traditional transit security strategies.

Read More →
Ad Loading...
An image of the white house with text overlayed reading "FTA Launches Transit Performance Dashboard."
Security and Safetyby Elora HaynesJuly 24, 2026

FTA Launches 'Transit Moves America' Dashboard to Highlight Agency Safety and Performance

The online dashboard transforms National Transit Database information into a public-facing resource that allows users to compare transit agencies on key operational and safety metrics.

Read More →