The Secure Train
A practical architecture for rolling stock cyber security: enforced zoning, passive detection, secure maintenance and one operational picture across the whole vehicle.
Secure the train as a connected system
Modern rolling stock is a connected ecosystem, not a set of isolated devices. Secure Train gives operators, train builders and asset owners a clear model for protecting the complete onboard environment.
The architecture combines RazorSecure products with partner capabilities from Westermo and EKE Electronics, bringing together network segregation, onboard intrusion detection, secure maintenance access, switch-based visibility and MVB monitoring.
Start with visibility, grow into enforcement
Secure Train does not require every fleet to buy the same stack. Use the elements that fit your risk, budget and vehicle constraints.
Visibility without the footprint
Use Delta, Echo, Dashboard and switch-based monitoring to see what is happening across onboard systems without adding unnecessary new hardware.
Stronger control and auditability
Add Security Gateway, Digital Maintenance Gateway and MVB monitoring when your risk assessment calls for enforced zone boundaries and controlled maintenance access.
Where each capability fits
Security Gateway
Enforces separation at network boundaries and filters traffic between onboard zones.
Boundary enforcement →Delta
Passively monitors hosts, segments and deeper onboard feeds for anomalous activity.
Detection layer →Digital Maintenance Gateway
Controls maintenance access and software update activity through one audited path.
Maintenance layer →Echo
Tracks asset availability, status and configuration across onboard and wayside systems.
Asset layer →Dashboard
Brings alerts, assets, baselines and evidence into one operational view.
Operating layer →Standards alignment
Maps the architecture to IEC 62443 zones and conduits, TS 50701 and the direction of IEC 63452.
Compliance mapping →Four capabilities that define Secure Train
Monitored traffic
Visibility across onboard networks, including MVB/CAN where the right feed exists, not only the main gateway.
Enforced zoning
Segmentation that reduces lateral movement between passenger, comfort, TCMS and safety-related zones.
Secure maintenance
Named users, agreed time windows, controlled software updates and records that are usable in an audit.
Configuration control
Baseline changes, asset drift and unauthorised activity made visible across the fleet.
Designed in from day one, or adopted fleet by fleet
For train builders, Secure Train is a framework for bid-ready cyber architecture and assurance evidence. For operators and asset owners, it is a retrofit path that can start with visibility and expand into enforcement when the risk case supports it.

