METRO Magazine Logo
MenuMENU
SearchSEARCH

How Transit Agencies Can Stay on Track with Cyber Security

Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

by Ken Keiser
September 29, 2017
How Transit Agencies Can Stay on Track with Cyber Security

 

5 min to read


Cyber security of trains, trolleys, and subways is an important national priority.
An organization’s information technology (IT) group is usually charged with maintaining digital assets and defending the loss of confidential information.

However, IT may ignore the cyber security ecosystem of the operational technology (OT) (the mechanical and electrical systems that control the rolling stock) side of the agency. The threat to these systems is growing.

Ad Loading...

Trains and subways rely on industrial control systems (ICSs) to keep them moving. However, ICS devices sometimes have features with inherent vulnerabilities. These devices may have Wi-Fi capability vulnerable to malware intrusion, and while transit agencies may not be using these features, they are still lurking in the background, ready to be exploited by bad actors.

Often, IT and OT teams work together, but differences between IT and OT priorities and culture become apparent. Availability — making the transit system run on time — is the prime directive of operation. IT often lacks understanding that a very small gap in availability is unacceptable in the OT environment.

Vulnerability Awareness
The lack of awareness of the vulnerabilities that have snuck into the OT world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving. Weak authentication, abuse of access authority, and the prevalence of removable media — often ignored by control engineers in the transit system — are threat vectors that allow intrusion into the transit authority’s OT equipment. In addition, transit systems often rely on legacy devices that have long lifecycles compared to IT appliances and PCs. Unfortunately, legacy systems don’t have cyber security features. This lack of integrated product security must be compensated for by a holistic program within the transit system.

So far, most transit systems have been lucky. But there are real-world examples of breaches. In 2008, a Polish train was remotely diverted to another track by a 14-year-old boy with a radio transmitter and a knowledge of the train system he gained by hanging out around the tracks.

We have found in our role as cyber security assessors that OT managers have often emphatically announced that their area is “air-gapped” and thus invisible to bad actors. These managers may be overlooking several issues, including:

Ad Loading...
  • Their OT area may include an overlooked historian that moves data from the OT equipment to another business unit.

  • USB ports are present that allow anyone with a memory stick to close this air-gap.

  • Employees may harbor malware in their cell phones, USB devices, or laptops, all of which can come in freely through their gate.

  • Transit agencies should realize there are real vulnerabilities in their OT domain and take steps to improve security defenses.

Improvement Hurdles
Why are transit agencies slow to make improvements? In addition to different OT and IT cultures, a major hurdle to improving transit cyber security is that transit agencies are often divided into silos of responsibility. For example, the electrical power group may have different ICS equipment than the communication and signals group, which has different systems than the dispatch area. This situation prevents a holistic approach to protecting the system.

The lack of awareness of the vulnerabilities that have snuck into the world blinds decision makers to the need to upgrade, patch, and secure many of the devices that keep a transit system moving.

Here are some of the steps successful agencies take for a more holistic approach to cyber security:

1. Provide leadership.
The board of directors or CEO of the transit agency must lead the charge for change to a culture in which cyber security is important and rewarded on the OT side.

Ad Loading...

2. Be aware of OT.
IT management should realize the importance (and uniqueness) of the OT space.

3. Start a task force.
A group made up of IT and OT departments solves the issues of misunderstanding and inertia, and communication between groups fosters success in any cyber security initiative.

4. Pick a standard.
There are a few good base standards for cyber security. The IT world uses ISO 27000 series standards, but some other standards have more of an OTperspective. The NIST (National Institute of Standards of Technology) Framework for Improving Critical Infrastructure Cyber security provides a roadmap and is free from the Department of Commerce.

5. People. Process. Technology.
The hard work of cyber defense involves multiple depths and includes physical devices or software as well as domains that the OT group alone cannot always change. Things like people and processes must be addressed.

6. Provide governance.
The task of continuous improvement is one of the most important but overlooked topics when discussing cyber security defenses. An institutional effort is necessary to ensure the cyber security of the OT side of transit agencies, remembering that cyber security is ever-changing and evolving. Intelligent adversaries are attacking your system and finding new vulnerabilities all the time. This fact requires constant countermeasures in IT and OT to keep up with the changes in environment. IT is familiar with this drill, but the personnel in dispatch, positive train control, or other OT areas are often unaware of how to do this.

Ad Loading...

7. Think outside the box.
OT engineers must think like a hacker to realize the vulnerabilities they have around them. Who best to defend a signaling system than signal engineers?

Related: ITS America forms transportation-focused cybersecurity task force

These steps will help any transit agency get ahead of the cyber threats to its operations. Cyber security is not a goal but a well-planned, well-executed, and never-ending journey that must include operations professionals and information professionals working together for the good of the entire transit system.

Subscribe to Our Newsletter

More Security and Safety

Security and SafetyJanuary 22, 2026

Researchers Identify Top Risk Factors for Pedestrian-vehicle Crashes at Massachusetts Bus Stops

While their comprehensive analysis of bus stops focused on Massachusetts, the researchers are excited about the generalizability of the findings and application to other locations.

Read More →
SponsoredJanuary 19, 2026

3 New Ways Fleet Software Pays: ROI opportunities for modern fleet managers

Transit agencies depend on safe, reliable vehicles to deliver consistent service. This eBook examines how next-generation fleet software helps agencies move from reactive processes to proactive operations through automated maintenance, real-time safety insights, and integrated data. Learn how fleets are improving uptime, safety outcomes, and operational efficiency.

Read More →
CTA railcar in station.
Technologyby StaffJanuary 16, 2026

CTA Innovation Studio Expands Pilot to Reduce Smoke, Odors

The new filters include substantially more activated carbon than traditional HVAC filters, which is especially helpful in providing a better transit riding experience for vulnerable populations, particularly children, seniors, and people with chronic illnesses, according to the CTA.

Read More →
Ad Loading...
New MCTS Bus design.
Security and Safetyby StaffJanuary 16, 2026

Milwaukee Rolls Out New Measures to Enhance Bus Safety

MCTS officials said the new pilots are part of a broader commitment to improving the rider experience through proactive, visible safety strategies that balance enforcement with customer support.

Read More →
Transit signal priority and public transit agencies.
New Mobilityby Alex RomanJanuary 16, 2026

How AI is Redefining Transit Operations and Signal Priority

In a recent episode of METROspectives, LYT CEO Timothy Menard discusses how artificial intelligence, cloud connectivity, and real-time data are transforming traffic management, boosting bus reliability, and enabling system-wide transit optimization across cities.

Read More →
Security and Safetyby StaffJanuary 15, 2026

SEPTA Crime Rates Continue Downward Trend, Report Finds

In addition, Transit Police reported strides in stepped-up enforcement of fare evasion and quality-of-ride offenses.

Read More →
Ad Loading...

People Movement: Vontas Names New GM and Much More

METRO’s People Movement highlights the latest leadership changes, promotions, and personnel news across the public transit, motorcoach, and people mobility sectors.

Read More →
A overhead view of an LA Metro rail station platform.
Security and Safetyby StaffJanuary 13, 2026

LA Metro Launches Care-Based Public Safety Division

The new division brings ambassadors, outreach, and crisis response together to improve safety, coordination, and rider experience systemwide.

Read More →
Security and Safetyby Alex RomanDecember 23, 2025

Establishing Standards & Codes in Canada, with CSA’s Ana-Maria Tomlinson

In this latest episode of METROspectives, we explore the evolving role of transit standards, including how they're responding to emerging technologies, climate change, and the growing need for equity and sustainability.

Read More →
Ad Loading...
A an image of a CTA bus with text reading "FTA Warns Chicago to Strengthen Transit Safety Plan or Lose Millions in Funding."
Security and Safetyby StaffDecember 22, 2025

Federal Transit Administration Warns Chicago to Strengthen Transit Safety Plan or Lose Millions in Funding

USDOT found the Chicago Transit Authority’s safety plan insufficient to safeguard commuters on buses and rail, as crime on Chicago transit approaches a decade-high.

Read More →