Separating critical on-board networks
New and legacy fleets
Connected passenger, comfort and critical systems create paths for attacks to spread. A defined security approach across old and new trains helps reduce exposure and the cost of managing each fleet separately.
A shared approach also reduces the work of managing each fleet separately.
Solution
We combine three products. Delta detects intrusions on each vehicle. Echo monitors the status and configuration of every on-board system. The EN 50155 Security Gateway separates the network into zones and filters the traffic between them. Together they give one set of controls, and one operational picture, across new and legacy fleets.
One operational picture helps teams assess fleet-wide risk and reduce incident-response effort.
Delta: intrusion detection for all
Proven in service Delta uses machine-learning models tuned on real rolling-stock traffic for railway threat detection. It runs in live rail networks today, protecting systems across different train classes.
See threats early, respond fast Delta monitors the network in real time across your entire fleet, so your team can respond fast to new threats.
Earlier investigation can help contain incidents before they affect service.
Flexible deployment Delta can deploy as software on compatible existing hardware. This can reduce equipment costs on new builds and retrofits while simplifying integration.
Compatible software deployments can reduce equipment costs on new builds and retrofits.
Echo: centralised monitoring fleet wide
One view of every fleet Echo shows the system health and configuration of your entire fleet in one view, so you can identify security risks early on both new and legacy systems.
Visualisation of on-board systems See every asset in every fleet. Status indicators show where changes are needed.
Improve system availability Echo detects availability and performance issues and reports collected device configuration in near real time when connected, so your engineers can fix the right faults fast.
Early fault identification helps engineers act before delays or vehicle withdrawals.
Security gateway: network segmentation
Works on legacy fleets Security Gateway is a Layer 7 firewall designed for rail. It simplifies network segmentation, limits the impact of a cyber attack and protects critical systems.
Protocol filtering between network zones Security Gateway filters traffic crossing zone boundaries on new and legacy trains. Pair it with Delta to monitor devices and traffic within the zones.
Long-term reliability for legacy infrastructure Security Gateway is designed for limited connectivity. It processes data at the edge, so boundary enforcement continues without a constant connection to shore, supporting service continuity.
Boundary controls support service continuity, with integration scoped to the existing network.
How this fits The Secure Train
Secure Train is the wider rolling stock architecture behind these challenges: enforced zoning, passive detection, secure maintenance, asset visibility and one operational picture.
Explore Secure TrainPlan the controls together
Map the fleet’s requirements to network boundaries, detection coverage and maintenance access. Secure Train shows how those controls fit together.
Related challenges
Detecting threats before they spread
Continuous monitoring that detects threats early.
Controlling maintenance and insider access
Controlled maintenance access and audit records that reduce insider risk.
Meeting NIS2 and TS 50701 obligations
What TS 50701, IEC 62443 and national rules require, and how to meet them.
Knowing what is really on your trains
A live inventory of every device and configuration on every train.
Connecting legacy fleets safely
How to secure older fleets that were built before cyber security standards existed.

