Solutions

Controlling maintenance and insider access

Mitigating insider threats

Secure access for engineering staff, maintenance staff and third-party contractors is vital for train cyber security and the protection of critical rail networks. Unlike external attackers, maintenance staff and suppliers pose a different challenge: they have legitimate access to critical rail infrastructure. That access creates the potential for insider threats, intentional or accidental. So operators need strong access controls, activity monitoring, and secure remote access procedures.

Solution

Insiders do not break in; they log in. So the controls must work on legitimate access, and RazorSecure addresses this with two train cyber security products. Digital Maintenance Gateway (DMG) makes every maintenance session attributable: named engineers, unique credentials, multi-factor authentication, agreed time windows, and an audit record of every session. Echo compares collected configuration data with the approved state, helping engineers investigate unplanned changes. Visibility is near real time when connected, with store-and-forward during disconnection.

Digital maintenance gateway (DMG): secure access and user monitoring

Eliminates risky access points DMG removes two common malware entry points: service laptops and USB sticks. It provides one secure access point for maintenance tasks instead.

Reducing these malware entry points helps lower the risk of operational downtime.

Strong authentication and user tracking Named credentials and multi-factor authentication support local and remote access. Recorded sessions and audit logs support investigation, accountability and reporting.

Session evidence supports cyber resilience and legal or regulatory reporting.

Controlled remote access DMG restricts remote access to authorised engineers. Each engineer gets limited permissions, for specific assets, during pre-approved timeframes. This reduces the potential for accidental or malicious actions.

Restricted permissions help reduce disruption from human error or deliberate misuse.

Echo: configuration visibility

Near-real-time system visibility Echo gives you a central view of device availability and collected system configurations. Comparing the approved state with observed changes helps engineers investigate potential mistakes or unauthorised activity.

Configuration evidence helps teams investigate possible insider activity and mismatches quickly.

Configuration evidence for access reviews Compare observed configuration changes with the authorised maintenance record. DMG controls maintenance access; Echo supplies configuration evidence for investigation.

Comparing maintenance records with observed changes supports investigations into potential insider misuse.

Anomaly detection finds what insiders change Echo detects configuration mismatches and identifies problematic assets. Engineers use that evidence to investigate and plan remediation; Echo does not automatically close vulnerabilities.

Architecture

How this fits The Secure Train

Secure Train is the wider rolling stock architecture behind these challenges: enforced zoning, passive detection, secure maintenance, asset visibility and one operational picture.

Explore Secure Train

Plan the controls together

Map the fleet’s requirements to network boundaries, detection coverage and maintenance access. Secure Train shows how those controls fit together.

Related challenges

See all challenges

Separating critical on-board networks

Network segmentation that protects both new and legacy fleets.

Detecting threats before they spread

Continuous monitoring that detects threats early.

Meeting NIS2 and TS 50701 obligations

What TS 50701, IEC 62443 and national rules require, and how to meet them.

Knowing what is really on your trains

A live inventory of every device and configuration on every train.

Connecting legacy fleets safely

How to secure older fleets that were built before cyber security standards existed.

Managed access, full auditability

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products