Managed Rail Cyber Security Services
Where analyst support is included in the service, our rail specialists review and triage fleet alerts and provide contextual reporting. The managed service includes weekly analyst reviews and monthly reports and review calls. Update responsibilities and escalation arrangements are agreed for each deployment.
Full monitoring without needing a full SOC
Optional analyst review & triage
Detection runs continuously on the vehicle. Where analyst support is contracted, RazorSecure reviews and triages alerts using experience developed across 3,200+ rail vehicles while retaining a deployment-specific baseline for each vehicle.
Your SOC, our feed
Already run security operations? Take CEF and REST API feeds into your SIEM/SOAR and use Dashboard as the rail-specific lens. A co-managed model is also available where contracted.
Fewer, better alerts
Baseline-driven detection focuses on deviations from your fleet's normal behaviour rather than matches to generic signatures. Reducing false positives is an explicit design goal.
From First Workshop To Full Fleet
| 1 · Scope | Architecture workshop against your fleet, risk assessment and target security levels, typically alongside your TS 50701 / IEC 62443 work. |
|---|---|
| 2 · Validate on train one | We deploy on a single unit and validate against agreed test cases. Acceptance testing is completed alongside train manufacturers and operators and is designed to demonstrate zero impact on on-board systems. |
| 3 · Roll out by snapshot | The approved train-one baseline becomes a golden snapshot applied fleet-wide, significantly reducing subsequent learning periods and fleet-wide tuning. |
| 4 · Operate & evolve | Continuous on-vehicle detection, weekly analyst reviews, monthly threat reports and review calls, and baseline updates managed as controlled changes whenever your fleet configuration changes. |
Agreed For Each Deployment
Weekly analyst reviews and monthly reporting are standard managed-service commitments. Continuous automated detection is a product capability; staffed support normally operates Monday–Friday with a next-business-day response. Hosting, availability and escalation arrangements are defined in the service agreement.
| Alert review | Weekly analyst reviews as standard; escalation follows the agreed service process. |
|---|---|
| Reporting | Monthly threat reports and review calls as standard. |
| Availability | Platform availability and resilience targets defined in the service agreement. |
| Support | Typical support is Monday–Friday with a next-business-day response. Escalation routes and named contacts are confirmed during onboarding. |
| Hosting & data | Cloud or on-premises deployment according to the approved architecture, data-residency requirements and service agreement. |
Support For The Life Of The Asset
Product-specific update controls
Update delivery and rollback depend on the product and host architecture. Security Gateway supports A/B partitioning and safeguarded rollback; other update responsibilities are defined in the contracted scope.
Systems you cannot patch can still be protected
Rolling stock carries systems that will never see another vendor patch. Continuous monitoring is the compensating control: you may not be able to fix it, but you will know the moment its behaviour changes.
Long-term commitment
Rail assets can remain in use for decades. Delta can support the full 30-year-plus life of a train, while Security Gateway is designed to stay in service for 15 years. We plan component refresh and ongoing support around the fleet: in continuous production service since 2018, with support, spares strategy and obsolescence management scoped into every contract.
Vulnerability handling
A published responsible disclosure process and managed security updates across the installed base: supplier obligations under the EU Cyber Resilience Act, already in practice.

