Cyber Security For Rail System Suppliers
You supply the systems that make modern trains work: passenger information, connectivity, CCTV, HVAC, train computers. Your customers now ask what security is inside them. We give you a security capability you can ship inside your product.
The Problems Suppliers Bring Us
Security is now in your spec
Operators and OEMs push their IEC 62443 and TS 50701 obligations down the supply chain. Suppliers increasingly need evidence of monitoring, secure updates and vulnerability handling to support tender responses.
The CRA applies to your product
The EU Cyber Resilience Act covers products with digital elements: reporting duties from September 2026, full obligations from December 2027. Building the capability takes longer than the deadline suggests. See our CRA guide.
No room for another box
Your product runs on constrained, certified hardware. Adding a security appliance is not an option; security has to run inside what you already ship.
Security is not your core business
Building and maintaining detection, baselining and a vulnerability process in-house is a permanent cost that never differentiates your product.
Your customers want evidence
A security section in your bid needs more than intent: it needs a named, rail-proven component with in-service history your customer can check.
Long product lives
Your platform ships for years and stays in service for decades. Whatever security you embed must be maintained on the same horizon.
Rail-Proven Security, Inside Your Product
| Embed Delta in your platform | Typical deployed package about 25 MB; current native Linux profile uses 1 CPU core, about 128 MB RAM, about 50 MB binary disk plus local store-and-forward data, and under 3% CPU on a typical TCMS gateway. Delta can run on existing on-board platforms, including EKE-Trainnet® train computers and EN 50155-certified Westermo switches. |
|---|---|
| A partnership model that ships | EKE-Trainnet® embeds Delta for MVB-networked fleets, and RazorSecure has a strategic integration partnership with Westermo. Integration is a proven path, not an experiment. |
| Detection tuned to rail | Behavioural baselining with rail protocol analysis: TRDP over IP, and MVB and CAN where your hardware attaches to those buses. No signature database for you or your customer to maintain. |
| Updates & vulnerability handling | DMG supports code-signed software distribution from a wayside repository, synchronisation to the train and software validation. Update and rollback arrangements depend on the product and host architecture. Our disclosure process supports vulnerability handling. |
| A security story for your bids | Your product ships with named, in-service rail intrusion detection. Across the wider RazorSecure portfolio, our products protect more than 3,200 rail vehicles, supported by the standards mapping your customer's assessor will ask for. |
| The first conversation | Bring your platform specification: CPU, memory, operating system. An initial technical discussion assesses platform compatibility, integration work and licensing options. |
Suppliers Already Ship With RazorSecure Inside
EKE-Trainnet® embeds Delta for MVB train networks, type tested to EN 50155. Westermo switches can host Delta and Echo. Both integrations build security into existing rail platforms.
Partnership models
