What happened?
A guest article by Christoph Tonnier, Director Technology Center at telent GmbH, published in Protector Magazin, addresses the growing cybersecurity challenge facing critical infrastructure (CI) in the transportation sector. The core message: the increasing convergence of IT and OT (Operational Technology) systems in rail operations, air traffic control, and the maritime sector is creating new opportunities for digitalization—but also new attack surfaces. Transportation networks must be able to fend off cyberattacks without protective measures themselves jeopardizing operations.
The Details
The article highlights a key distinction: while a cyber incident in classic IT primarily affects the confidentiality and integrity of data, operational technology must additionally maintain the availability of physical processes. An automated shutdown, considered a sensible protective response in IT, can jeopardize critical processes in OT environments—for example, if a railway crossing suddenly can no longer be reliably secured, or a control center becomes unable to act.
As a threat scenario, the article describes a (so far hypothetical) case: an attacker manipulates the control system of a railway crossing while a train is approaching, disabling barriers or signals. Early detection could enable countermeasures here before people are harmed.
On the regulatory side, the article references the IT Security Act 2.0 and the NIS-2 Directive, which require operators to secure their infrastructure according to the state of the art, remain capable of action during severe attacks, and provide evidence of this. This requires risk analyses, appropriate protective measures, and systems for attack detection.
According to the article, a particular operational hurdle is the long life cycles of OT systems: while IT components are usually replaced after just a few years, control components often run for decades. Many signal boxes, signaling systems, and control systems were built at a time when cybersecurity was not yet a design criterion—encryption and access controls are often missing in older protocols, and a complete replacement is usually not practical.
Concrete Protective Measures from the Article
- Facility-specific risk analysis as a starting point to assess realistic attack scenarios and their consequences
- Encryption methods depending on the technical environment: Layer 2 (MACsec), Layer 3 (IPsec VPN), or TLS-based protocols, provided the systems support this
- Network segmentation with clearly defined security zones and monitored transitions to limit the spread of an attack
- Separation of control levels and the office network—no direct accessibility
- Secure remote access, clear role and permission concepts, and continuous monitoring
- Structured vulnerability and patch management applied judiciously depending on system relevance
- Redundant communication channels in case a connection fails or is restricted for security reasons
Assessment
For the transportation sector as a critical infrastructure domain, the development described in the article is particularly relevant because cybersecurity here is directly linked to physical safety. Unlike in office communications, for example, a system failure in rail operations, tunnel control systems, or traffic management systems can endanger human lives. The article also references ransomware attacks on European rail operators and logistics providers as evidence that physical transport chains have long been in the crosshairs of digital extortionists. Geopolitical tensions, too, are said to increase the risk of targeted sabotage, while AI-supported attacks increase the speed and scalability of attacks.
Notably, the article states that classic IT security approaches—such as reflexive shutdowns in cases of suspicion—can be counterproductive in an OT context. Security and fallback layers must be designed so that even in the event of a disruption, a defined, manageable operational state is maintained.
Practical Tips
The following recommendations for operators of transportation infrastructure can be derived from the article:
- Protective mechanisms should be retrofitted into existing control and communication networks without altering their critical functions—a complete replacement of old OT systems is usually not realistic
- Regularly reassess architecture and configurations, as previous best practices may become outdated
- New protective measures must be tested under real operating conditions to rule out critical latencies or malfunctions
- Attack detection systems must be linked to clear response processes, as ransomware increasingly follows the pattern of "spy first, then threaten"
- Regularly practice emergency plans—documentation alone is not enough; procedures must also work under time pressure
- Operations, administration, security, and, where applicable, approval bodies should plan together from the outset to prevent overly restrictive security solutions from becoming too complex in daily operations
- Adopt a phased approach and evaluate each measure for its security contribution, impact on availability, and practical feasibility
Outlook
The article makes clear that network modernization and cybersecurity in the transportation sector can no longer be considered separately in the future. Secure IP networks, controlled migrations, segmented architectures, protected remote access, and continuous security monitoring should be planned together from the outset. Given tightened regulatory requirements under NIS-2 and the IT Security Act 2.0, operators must also be able to systematically demonstrate that their security measures do not impair stable operations—new or modified systems must be tested under defined conditions before being deployed in practice. The central message of the guest article: security that stops operations fails to achieve its goal just as much as a system that is easy to use but inadequately protected. What is needed is the right balance of protection, availability, and manageability.