Who we help

Cyber Security For Train Operators

You run fleets from several builders, of several ages, under regulations that treat them all the same. We protect new and legacy fleets with the same software, on hardware you already have, with the evidence your auditors ask for.

Your challenges

The Problems Operators Bring Us

A compliance deadline with a fleet attached

NIS2 and its national transpositions apply to your fleet as it is today, not as it will be after the next refurbishment. Regulators expect risk management and incident reporting across every fleet you operate.

Fleets that were never designed for this

Rolling stock from five builders across three decades, with systems that will never receive another vendor patch. You cannot replace them, and you are still accountable for them.

No rail-literate security team

Your security team may need specialist support interpreting on-board systems and rail protocols. Clear fleet context helps analysts investigate the alerts that matter.

No appetite for new boxes

New on-board hardware means design authority approvals, weight, power, and possessions. A retrofit programme that needs depot visits per train may never get scheduled.

Evidence, not assurances

Your auditors and your board both ask the same question: how do you know? You need reporting that shows what is on the fleet, what changed, and what was done about it.

Procurement that outlives suppliers

Your assets run for 30 years. A security supplier that disappears in year 4, or drops support in year 8, creates the same gap you started with.

How we fit

What This Looks Like On Your Fleet

Detection without new hardwareDelta is about 25 MB of software running on hardware you already have. Northern's fleet was covered by remote installation, with no observed impact on TCMS operation.
Legacy systems you cannot patchDelta baselines each system's normal behaviour and alerts on change. Monitoring is the compensating control for systems that will never see another patch.
One picture across mixed fleetsEcho and Dashboard give one view of asset status, configuration and alerts across every builder and fleet type. More than 700 data points per train in the Northern deployment.
Analysts without a SOCOur managed service provides alert review, reporting and engineering support at the agreed cadence. Your own SOC can take the feeds instead, or alongside.
Compliance evidenceReporting mapped to NIS2, TS 50701 and IEC 62443, with alert history, baseline changes and asset state retained as audit evidence. See the standards mapping.
Fleet rollout that scalesValidate on train one, then apply the approved baseline fleet-wide as a golden snapshot. This significantly reduces subsequent per-train learning and tuning.
Proof

Northern Did This Ahead Of Its NIS Deadline

A new digital fleet secured before delivery, and existing fleets retrofitted to the same standard. Remote installation covered every train, with no service disruption.

"RazorSecure's products are an effective part of our security in depth approach. We consider their solutions to be unique and ideally suited to work in a distributed and often isolated environment."

Marc Silverwood · Digital Trains Project Manager, Northern
Read the case study

Every train covered

Remote installation across Northern's new and retrofitted fleets, with no service disruption.

700+ data points

Monitored per train across the Northern fleet, feeding one operational picture.

Beyond Northern

Across all our customers: 1,000+ trains protected over 23+ distinct fleets, in production service since 2018.

Every train covered, without new hardware

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products