Who we help

Cyber Security For Rail Infrastructure Managers

Your estate is thousands of assets spread along hundreds of kilometres: signalling-adjacent equipment, level crossings, station systems and telecoms cabinets. We monitor wayside infrastructure with the same product portfolio used across more than 3,200 rail vehicles.

Your challenges

The Problems Infrastructure Managers Bring Us

You cannot see the whole estate

Equipment installed over decades, by many suppliers, in cabinets you visit twice a year. The first question every audit asks is the one that is hardest to answer: what is connected right now?

NIS2 names you directly

Infrastructure managers are essential entities under NIS2 Annex I. Risk management, incident reporting and supply chain security are legal obligations with deadlines, not aspirations.

Connectivity you cannot rely on

Wayside sites have intermittent links, and central monitoring tools built for data centres fail quietly when the link drops. Gaps in monitoring become gaps in evidence.

Long-lived, unpatchable equipment

Interlockings, comms and station systems run for decades. Many cannot be patched without recertification, and some cannot be patched at all.

Contractors and remote access

Maintenance contractors connect to your assets with their own laptops and their own habits. Every unmanaged connection is an unaudited risk.

One team, many systems

Operational technology, telecoms and IT meet at the trackside, but the tools and teams that watch them rarely meet.

How we fit

The Same Products, Trackside

Know what is out thereEcho discovers and monitors assets by ICMP, SNMP and edge agents, vendor-agnostic, with configuration drift detection.
Detect change at remote sitesDelta runs at the edge, on-board and wayside, and baselines each system's normal behaviour. Detection keeps working when the link drops; events forward when connectivity returns.
Enforce zone boundariesSecurity Gateway separates OT zones at stations and trackside sites, with Layer 7 filtering and rail protocol support, deployed as hardware or software.
Control maintenance accessDMG replaces contractor laptops with authenticated, recorded, auditable sessions. One maintenance approach across vehicles and infrastructure.
Evidence for the regulatorDashboard keeps alert history, configuration state and baseline changes as audit-ready records, mapped to NIS2 and IEC 62443. Check your jurisdiction on the global regulations map.
Safety approvalsDelta uses passive monitoring patterns and does not enforce or block control traffic. Security Gateway is deployed inline only where boundary enforcement is required. We support your product acceptance process with documentation and test evidence.
A first step that fits one budget yearA scoped Echo discovery pilot across a sample of sites: deploy, discover what is actually connected, and end with an evidence pack you can show your regulator. Delta detection extends from there, where your risk assessment points.

Deployment scope

our detection and monitoring products are proven at fleet scale on rolling stock, and run wayside with the same software and the same rail engineering constraints: intermittent links, long asset lives, and equipment that cannot be patched. Delta's rail protocol analysis covers TRDP, MVB and CAN today; wayside coverage focuses on assets visible over IP and SNMP.

One view across distributed wayside assets

Talk to our engineering team

Bring us your network architecture and your asset registers, however incomplete. Our engineers will scope discovery, detection and an evidence plan from what you actually have.

Book a technical workshop Check your jurisdiction