Connecting legacy fleets safely
Addressing outdated systems and security
Bringing obsolete on-board systems up to modern security standards is a major task for the rail industry. Legacy infrastructure was often designed with little built-in cyber security, and that creates vulnerabilities in railway network security. These outdated systems are hard to integrate with modern security protocols, and they are easy targets for attackers. The scale and complexity of rail networks make strong defences difficult to implement.
Solution
We protect legacy systems with two products. Delta provides host and network monitoring, with deployment selected for each platform. Network monitoring can cover legacy systems without installing software on those systems. Security Gateway, a Layer 7 firewall, separates the legacy systems into their own network zone and filters everything that crosses the boundary. Together they give legacy fleets a strong, adaptable defence and support compliance with the industry standards listed below.
Delta: threat detection for new and legacy systems
Flexible deployment even with outdated systems Delta's adaptable architecture supports virtual or software-only deployment on both new and legacy trains. This keeps hardware costs low and simplifies integration with existing infrastructure.
Segmentation can provide proportionate risk reduction, with network changes and deployment disruption assessed during design.
Threat detection and prioritisation Delta gives you a clear view of your entire network. It detects deviations from normal behaviour and supplies evidence for investigation, helping teams prioritise potentially significant operational risks.
Security teams can use this evidence to focus investigation on potentially significant operational risks.
Supporting compliance with industry standards We develop Delta in line with the EU NIS Directive, NIST SP 800-82, CLC/TS 50701, and IEC 62443 cyber security frameworks. This supports your compliance case for systems that cannot be upgraded.
A documented compliance case helps address regulatory risk.
Security gateway: simplified network segmentation
Network segmentation without redesigning the network Security Gateway is a Layer 7 firewall: it separates network zones and filters the traffic between them. It works on both new and legacy fleets.
Threat detection and monitoring Security Gateway filters traffic crossing zone boundaries and logs events for investigation. Pair it with Delta for intrusion detection within zones and Echo for configuration visibility.
Combining boundary logs, Delta detection and Echo configuration data helps teams investigate malicious activity and drift before service is affected.
Easy integration and long-term effectiveness Deploy it as software or as hardware. Integration is designed around the existing network and agreed routing requirements, helping control deployment and lifecycle costs.
Integration around the existing network and agreed routing requirements helps control total cost of ownership.
How this fits The Secure Train
Secure Train is the wider rolling stock architecture behind these challenges: enforced zoning, passive detection, secure maintenance, asset visibility and one operational picture.
Explore Secure TrainPlan the controls together
Map the fleet’s requirements to network boundaries, detection coverage and maintenance access. Secure Train shows how those controls fit together.
Related challenges
Separating critical on-board networks
Network segmentation that protects both new and legacy fleets.
Detecting threats before they spread
Continuous monitoring that detects threats early.
Controlling maintenance and insider access
Controlled maintenance access and audit records that reduce insider risk.
Meeting NIS2 and TS 50701 obligations
What TS 50701, IEC 62443 and national rules require, and how to meet them.
Knowing what is really on your trains
A live inventory of every device and configuration on every train.

