Solutions

Knowing what is really on your trains

Maintaining inventory and configuration

Keeping your rail network secure requires a comprehensive understanding of every asset – not just where your trains are, but also details of on-board IT and OT systems. Railway asset discovery helps address this challenge by uncovering blind spots and enabling efficient configuration management. Managing hundreds of these systems across a complex network requires a modern approach, and a railway asset discovery tool provides the precise insights needed to achieve it.

Solution

Two products share the work. Echo discovers the assets on each vehicle and reports their status and configuration in near real time, helping you identify drift when data reaches shore. Digital Maintenance Gateway (DMG) controls how those configurations change: named engineers, multi-factor authentication, and a full audit trail for every update. Together they give you one current record of the fleet and a controlled way to change it.

Echo: gaining near-real-time visibility and control

Configuration management and anomaly detection Echo identifies configuration mismatches and anomalies in your systems, so you can close security gaps quickly and keep digital assets performing as intended.

Investigating configuration mismatches helps reduce the risk of security-related operational failures.

Fewer faults, less downtime Echo reports device availability and performance in near real time, helping engineers identify the systems that need investigation.

Availability monitoring helps teams investigate faults before they affect passenger services.

Maintenance and reporting across the fleet Echo shows the whole fleet or a single asset. Reports cover performance and trends, so maintenance decisions are based on current data.

Performance and trend data help optimise maintenance effort and operating costs.

Digital maintenance gateway (DMG): secure and efficient updates

Eliminate service laptops and USBs DMG replaces dedicated service laptops and USB sticks, allowing one field engineer and remote specialists to work across several units during a maintenance shift.

This improves labour efficiency and can reduce field-maintenance costs.

Secure remote access and user control Local and remote access use individual authentication and can use multi-factor authentication, with the same audit trail. This removes anonymous access to systems reached through DMG.

Attributable access reduces insider risk and strengthens accountability.

Audited and traceable activity DMG gives you a secure, audited way to update systems, which supports compliance with standards such as IEC 62443. Every maintenance action is logged, so each change is traceable.

Traceable records support compliance evidence and reduce audit preparation effort.

Reduced cyber vulnerabilities DMG isolates service laptops and removes USB use, so the risk of bringing malware or unauthorised applications onto your on-board systems falls.

These controls help protect critical on-board systems from malware introduced through maintenance equipment.

Start with a fleet inventory baseline

Scope an Echo discovery pilot across a sample of vehicles. Agree the monitored systems and data sources, then establish an inventory and configuration baseline for the wider rollout. Discuss an Echo pilot.

Architecture

How this fits The Secure Train

Secure Train is the wider rolling stock architecture behind these challenges: enforced zoning, passive detection, secure maintenance, asset visibility and one operational picture.

Explore Secure Train

Plan the controls together

Map the fleet’s requirements to network boundaries, detection coverage and maintenance access. Secure Train shows how those controls fit together.

Related challenges

See all challenges

Separating critical on-board networks

Network segmentation that protects both new and legacy fleets.

Detecting threats before they spread

Continuous monitoring that detects threats early.

Controlling maintenance and insider access

Controlled maintenance access and audit records that reduce insider risk.

Meeting NIS2 and TS 50701 obligations

What TS 50701, IEC 62443 and national rules require, and how to meet them.

Connecting legacy fleets safely

How to secure older fleets that were built before cyber security standards existed.

Inventory & configuration, fleet-wide

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products