Cyber Security For Train Operators
You run fleets from several builders, of several ages, under regulations that treat them all the same. We protect new and legacy fleets with the same software, on hardware you already have, with the evidence your auditors ask for.
The Problems Operators Bring Us
A compliance deadline with a fleet attached
NIS2 and its national transpositions apply to your fleet as it is today, not as it will be after the next refurbishment. Regulators expect risk management and incident reporting across every fleet you operate.
Fleets that were never designed for this
Rolling stock from five builders across three decades, with systems that will never receive another vendor patch. You cannot replace them, and you are still accountable for them.
No rail-literate security team
Your security team may need specialist support interpreting on-board systems and rail protocols. Clear fleet context helps analysts investigate the alerts that matter.
No appetite for new boxes
New on-board hardware means design authority approvals, weight, power, and possessions. A retrofit programme that needs depot visits per train may never get scheduled.
Evidence, not assurances
Your auditors and your board both ask the same question: how do you know? You need reporting that shows what is on the fleet, what changed, and what was done about it.
Procurement that outlives suppliers
Your assets run for 30 years. A security supplier that disappears in year 4, or drops support in year 8, creates the same gap you started with.
What This Looks Like On Your Fleet
| Detection without new hardware | Delta is about 25 MB of software running on hardware you already have. Northern's fleet was covered by remote installation, with no observed impact on TCMS operation. |
|---|---|
| Legacy systems you cannot patch | Delta baselines each system's normal behaviour and alerts on change. Monitoring is the compensating control for systems that will never see another patch. |
| One picture across mixed fleets | Echo and Dashboard give one view of asset status, configuration and alerts across every builder and fleet type. More than 700 data points per train in the Northern deployment. |
| Analysts without a SOC | Our managed service provides alert review, reporting and engineering support at the agreed cadence. Your own SOC can take the feeds instead, or alongside. |
| Compliance evidence | Reporting mapped to NIS2, TS 50701 and IEC 62443, with alert history, baseline changes and asset state retained as audit evidence. See the standards mapping. |
| Fleet rollout that scales | Validate on train one, then apply the approved baseline fleet-wide as a golden snapshot. This significantly reduces subsequent per-train learning and tuning. |
Northern Did This Ahead Of Its NIS Deadline
A new digital fleet secured before delivery, and existing fleets retrofitted to the same standard. Remote installation covered every train, with no service disruption.
Read the case study"RazorSecure's products are an effective part of our security in depth approach. We consider their solutions to be unique and ideally suited to work in a distributed and often isolated environment."
Every train covered
Remote installation across Northern's new and retrofitted fleets, with no service disruption.
700+ data points
Monitored per train across the Northern fleet, feeding one operational picture.
Beyond Northern
Across all our customers: 1,000+ trains protected over 23+ distinct fleets, in production service since 2018.

