Managed services & lifecycle

Managed Rail Cyber Security Services

Where analyst support is included in the service, our rail specialists review and triage fleet alerts and provide contextual reporting. The managed service includes weekly analyst reviews and monthly reports and review calls. Update responsibilities and escalation arrangements are agreed for each deployment.

Managed detection

Full monitoring without needing a full SOC

Optional analyst review & triage

Detection runs continuously on the vehicle. Where analyst support is contracted, RazorSecure reviews and triages alerts using experience developed across 3,200+ rail vehicles while retaining a deployment-specific baseline for each vehicle.

Your SOC, our feed

Already run security operations? Take CEF and REST API feeds into your SIEM/SOAR and use Dashboard as the rail-specific lens. A co-managed model is also available where contracted.

Fewer, better alerts

Baseline-driven detection focuses on deviations from your fleet's normal behaviour rather than matches to generic signatures. Reducing false positives is an explicit design goal.

How a fleet goes live

From First Workshop To Full Fleet

1 · ScopeArchitecture workshop against your fleet, risk assessment and target security levels, typically alongside your TS 50701 / IEC 62443 work.
2 · Validate on train oneWe deploy on a single unit and validate against agreed test cases. Acceptance testing is completed alongside train manufacturers and operators and is designed to demonstrate zero impact on on-board systems.
3 · Roll out by snapshotThe approved train-one baseline becomes a golden snapshot applied fleet-wide, significantly reducing subsequent learning periods and fleet-wide tuning.
4 · Operate & evolveContinuous on-vehicle detection, weekly analyst reviews, monthly threat reports and review calls, and baseline updates managed as controlled changes whenever your fleet configuration changes.
Service scope

Agreed For Each Deployment

Weekly analyst reviews and monthly reporting are standard managed-service commitments. Continuous automated detection is a product capability; staffed support normally operates Monday–Friday with a next-business-day response. Hosting, availability and escalation arrangements are defined in the service agreement.

Alert reviewWeekly analyst reviews as standard; escalation follows the agreed service process.
ReportingMonthly threat reports and review calls as standard.
AvailabilityPlatform availability and resilience targets defined in the service agreement.
SupportTypical support is Monday–Friday with a next-business-day response. Escalation routes and named contacts are confirmed during onboarding.
Hosting & dataCloud or on-premises deployment according to the approved architecture, data-residency requirements and service agreement.
Lifecycle

Support For The Life Of The Asset

Product-specific update controls

Update delivery and rollback depend on the product and host architecture. Security Gateway supports A/B partitioning and safeguarded rollback; other update responsibilities are defined in the contracted scope.

Systems you cannot patch can still be protected

Rolling stock carries systems that will never see another vendor patch. Continuous monitoring is the compensating control: you may not be able to fix it, but you will know the moment its behaviour changes.

Long-term commitment

Rail assets can remain in use for decades. Delta can support the full 30-year-plus life of a train, while Security Gateway is designed to stay in service for 15 years. We plan component refresh and ongoing support around the fleet: in continuous production service since 2018, with support, spares strategy and obsolescence management scoped into every contract.

Vulnerability handling

A published responsible disclosure process and managed security updates across the installed base: supplier obligations under the EU Cyber Resilience Act, already in practice.

Detection that never sleeps, analysts who know rail

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products