Cyber Security For Train Builders & OEMs
The tender requires cyber security, the SL targets are fixed, and the delivery date is unchanged. We supply the rail-native security subsystem: designed for IEC 62443 zones, validated in acceptance testing, and supported for the life of the fleet.
The Problems OEM Teams Bring Us
SL targets without re-engineering
The tender demands an IEC 62443 SL2 or SL3 zone target, but re-engineering every TCMS component to meet it would put the programme schedule and budget at risk. You need the target met at the architecture level.
Integration risk at acceptance
Any security component that touches the train network is a risk to your acceptance testing. It must prove that it cannot interfere with train control, and provide that proof within the customer's test schedule.
A compliance file to fill
TS 50701 assessments require evidence: zone models, monitoring, secure update processes and vulnerability handling. IEC PT 63452 is developing international work in the same area. Your customer's assessor will read the evidence.
CRA obligations landing on you
From December 2027 the EU Cyber Resilience Act applies to products with digital elements you place on the market, with reporting duties from September 2026. See our CRA guide.
Support measured in decades
Your customer expects the fleet supported for 30 years or more. Every subsystem supplier you choose becomes part of that promise.
Maintenance access at scale
New fleets ship with dozens of maintainable systems. Unmanaged service laptops and USB transfers no longer meet modern security requirements, often within the fleet's warranty period.
Designed Into Your Programme From The Start
| Zones & conduits, enforced | Security Gateway enforces the IEC 62443 zone model at network boundaries, supporting an SL3 zone target without re-engineering every TCMS component. In service with a major OEM on a new-build UK intercity fleet. |
|---|---|
| Detection that passes acceptance testing | Delta uses passive monitoring patterns and does not enforce or block train control traffic. It is supported by acceptance-test documentation and in-service evidence appropriate to the programme. |
| Runs on your hardware | About 25 MB of software on the platforms you already ship, including EKE-Trainnet train computers and EN 50155-certified Westermo switches. No new boxes, weight or power. |
| Managed maintenance access | DMG provides an audited maintenance-access layer: named engineers, multi-factor authentication, recorded sessions and a controlled five-stage update process. |
| Evidence for the compliance file | Standards mapping, monitoring records and secure update processes documented for TS 50701 assessments, while tracking relevant IEC PT 63452 developments. A technical workshop pack is available on request. |
| Life-of-fleet support | Product-specific update controls, obsolescence management and published vulnerability handling support long-lived rail programmes. |
Chosen By The People Who Build Trains
A public partnership with Siemens Mobility, and new-build programmes with major OEMs in the UK and Europe. Embedded partnerships with EKE-Trainnet and Westermo. In production service since 2018.
How OEM partnerships work
