Who we help

Cyber Security For Train Builders & OEMs

The tender requires cyber security, the SL targets are fixed, and the delivery date is unchanged. We supply the rail-native security subsystem: designed for IEC 62443 zones, validated in acceptance testing, and supported for the life of the fleet.

Your challenges

The Problems OEM Teams Bring Us

SL targets without re-engineering

The tender demands an IEC 62443 SL2 or SL3 zone target, but re-engineering every TCMS component to meet it would put the programme schedule and budget at risk. You need the target met at the architecture level.

Integration risk at acceptance

Any security component that touches the train network is a risk to your acceptance testing. It must prove that it cannot interfere with train control, and provide that proof within the customer's test schedule.

A compliance file to fill

TS 50701 assessments require evidence: zone models, monitoring, secure update processes and vulnerability handling. IEC PT 63452 is developing international work in the same area. Your customer's assessor will read the evidence.

CRA obligations landing on you

From December 2027 the EU Cyber Resilience Act applies to products with digital elements you place on the market, with reporting duties from September 2026. See our CRA guide.

Support measured in decades

Your customer expects the fleet supported for 30 years or more. Every subsystem supplier you choose becomes part of that promise.

Maintenance access at scale

New fleets ship with dozens of maintainable systems. Unmanaged service laptops and USB transfers no longer meet modern security requirements, often within the fleet's warranty period.

How we fit

Designed Into Your Programme From The Start

Zones & conduits, enforcedSecurity Gateway enforces the IEC 62443 zone model at network boundaries, supporting an SL3 zone target without re-engineering every TCMS component. In service with a major OEM on a new-build UK intercity fleet.
Detection that passes acceptance testingDelta uses passive monitoring patterns and does not enforce or block train control traffic. It is supported by acceptance-test documentation and in-service evidence appropriate to the programme.
Runs on your hardwareAbout 25 MB of software on the platforms you already ship, including EKE-Trainnet train computers and EN 50155-certified Westermo switches. No new boxes, weight or power.
Managed maintenance accessDMG provides an audited maintenance-access layer: named engineers, multi-factor authentication, recorded sessions and a controlled five-stage update process.
Evidence for the compliance fileStandards mapping, monitoring records and secure update processes documented for TS 50701 assessments, while tracking relevant IEC PT 63452 developments. A technical workshop pack is available on request.
Life-of-fleet supportProduct-specific update controls, obsolescence management and published vulnerability handling support long-lived rail programmes.
Proof

Chosen By The People Who Build Trains

A public partnership with Siemens Mobility, and new-build programmes with major OEMs in the UK and Europe. Embedded partnerships with EKE-Trainnet and Westermo. In production service since 2018.

How OEM partnerships work
Acceptance-tested inside OEM programmes

Talk to our engineering team

Bring us the tender's cyber security requirements and your platform architecture. Our engineers will map the SL targets to an architecture, and the architecture to the evidence your compliance file needs.

Book a technical workshop See the standards mapping