talking
POINT
THE VULNERABLE SYSTEMS BEHIND OUR RAIL NETWORKS
As rail networks become increasingly connected, operators must balance the benefits of digital innovation with the growing cybersecurity risks facing critical infrastructure. In this thought leadership article, David Hope, Regional Vice President of APJ for Nozomi Networks, explores the vulnerabilities created by ageing operational technology systems and explains why rail operators must take a proactive approach to cyber resilience.
A ustralia’ s rail networks carry millions of passengers and billions of dollars in freight each year, yet many of the operational technology( OT) systems that keep trains running safely are decades old.
This creates significant cybersecurity vulnerabilities. Systems designed in the 1970s and 1980s were never built to withstand today’ s sophisticated, increasingly AI-enabled cyberattacks. Most rail signalling and control systems were also developed long before cybersecurity became a priority and were never intended to be connected to wider networks or the Internet. services, halting more than 20 trains and exposing weaknesses in legacy radio systems.
A similar attack occurred in Taiwan on April 5, 2026, when a 21-year-old student exploited a cryptographic flaw in Taiwan High-Speed Rail’ s TETRA network. Using consumer-grade softwaredefined radio equipment and handheld radios, the student sent a forged alarm signal that forced four trains travelling at speeds of up to 300 km / h to make emergency stops for 48 minutes. Like the Polish incident, the attack relied on outdated cryptographic keys and authentication rather than advanced hacking techniques.
David Hope, Regional Vice President of APJ for Nozomi Networks
However, connecting these systems has delivered major operational benefits. Integration with IT environments, cloud platforms and third-party vendors enables remote monitoring and control, real-time traffic management, automatic obstacle detection and even direct communication between trains. Operators can now manage industrial processes remotely, reducing travel costs and improving emergency response times.
The downside is that these legacy systems are now connected to networks without having cybersecurity built into their foundations. In many cases, integration has outpaced security, creating additional entry points that threat actors can exploit to access critical systems and data.
Australia has so far avoided major attacks on its rail infrastructure, but international incidents demonstrate the risks. In 2022, pro-Russian groups targeted railway signalling systems across Europe, including Poland’ s rail network, which plays a key role in transporting NATO supplies into Ukraine. Using a simple radio command rather than a sophisticated cyberattack, the attackers triggered emergency stops across both passenger and freight
Australia’ s metropolitan and freight rail operators use many of the same types of legacy systems, meaning they are not immune to similar threats. While Australia is geographically isolated, its strategic alliances and intelligence partnerships could make its critical infrastructure an attractive target.
Recognising these risks, the Security of Critical Infrastructure( SOCI) Act was expanded in 2022 to include transport. Operators must register critical assets, maintain detailed operational information and develop risk management programmes covering cyber, physical, supply chain and personnel threats.
However, compliance alone is unlikely to be enough. Rail operators should also maintain comprehensive inventories of OT assets, including train control systems, building systems and IoT devices, enabling continuous monitoring across their networks. Taking these additional steps will improve visibility of potential threats before they disrupt operations, because the challenge is no longer whether an attack is possible, but how effectively operators can detect and respond when one occurs.
The downside is that these legacy systems are now connected to networks without having cybersecurity built into their foundations.
WWW. INTELLIGENTCISO. COM 19