惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
I
InfoQ
B
Blog RSS Feed
D
Docker
GbyAI
GbyAI
N
Netflix TechBlog - Medium
Y
Y Combinator Blog
F
Fortinet All Blogs
P
Proofpoint News Feed
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
M
MIT News - Artificial intelligence
C
Check Point Blog
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
博客园 - Franky
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
Last Week in AI
Last Week in AI
L
LangChain Blog

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Where IT meets OT and railway cybersecurity gets harder -...
Mirko Zorz · 2026-06-24 · via Help Net Security

In this interview with Help Net Security, Jorge Aldegunde, Global Head of Railway Services at DNV, talks through what happens when old operational technology meets newer IT in monorail systems. He explains why open networks widened the attack surface, how teams decide whether to patch a signalling flaw without stopping trains, and who carries the liability.

Aldegunde covers regulation like CRA and NIS2, training veteran engineers to think about threat actors, and spotting intruders who have been inside for months. His main rule: manage your risks and plan for resilience, not perfection.

railway cybersecurity

Monorail control sits at the awkward seam between operational technology that was commissioned decades ago and the IT layer bolted on afterward. Walk me through a moment when those two worlds collided on your watch. What broke, and who in the room understood the problem first?

This may just as well go case by case. Our flagship project SDLC monorail is brand-new construction, so state of the art IT-OT applies. However, the point is well noted: railway applications would traditionally piggyback on vendor-specific SCADAS and dedicated communication systems (SDH-PDH).

Projects realized the benefit of employing IP-oriented networks (open standards, different vendors, lower costs). This broke the paradigm: open standards soon yielded open networks. SCADA systems became open and connected through middlewares, and data from public transport systems, stored in public / private clouds became available for users to build nice apps upon. This shift was further accelerated by condition-based maintenance and data-driven services, turning previously isolated assets into continuous data producers.

Last, but not least, AI came along. Attack surfaces and vectors multiplied. The key lesson is that the IT/OT boundary is no longer a boundary, it is an interface that must be actively managed.

A train cannot wait for a patch window the way an email server can. When you have a known vulnerability in a signalling or door-control component but cannot take the line out of service, what is the decision process, and who carries the liability if you choose to keep running?

The first step is whether the known vulnerability is exploitable and how. Then, secondly, assuming that it is, is the underlying risk-based approach towards the vulnerability (likelihood and impact).

From there, the decision branches. If a patch is available, the objective is to integrate it into planned maintenance windows without compromising operations, or if no patch is available, compensating measures must be considered, including network segmentation, monitoring or operational restrictions.

New horizontal regulation (CRA, NIS2) paves the way for accountability, and yet the issue remains adoption and stakeholder harmonization and clarity in complex railway contracts.

The real challenge lies in the integration layers, within components, subsystems and systems managed by different stakeholders. Responsibility is rarely concentrated in one entity. Back on the legislative front, there are ongoing working groups to help guide the implementation thereof and find the right trade-off with vertical regulation. This is far from perfect (take the example of the “expert guidance on implementation of CRA” – where there is still lack of consensus).

When you onboard a new operations engineer who has spent twenty years keeping trains moving and has never thought about threat actors, how do you change their instincts without insulting the expertise that keeps people alive?

This reminds me of the time RAMS (Reliability, Availability, Maintainability and Safety) came along and shifted the paradigm from silo engineering to a systems integration approach. Twenty years back such change seemed insurmountable – and now RAMS is railway ABC. Maybe this is a good angle of attack – railway cybersecurity practitioners usually come from “related” rail disciplines (safety, signalling, communications). As with any other paradigm change, it all starts with people, communication and awareness.

Solid, well-understood and widely adopted regulation must come as big enabler: we in DNV have a solid track record when it comes to applying IEC 62443 series and are part of the IEC 63452 PT. We are also active in the conformity assessment field by representing NB Rail (European association of RCABs – Railway Conformity Assessment Bodies) and participate in WG’s to adopt technical cybersecurity documents as “building blocks” for adoption in the TSI’s (Technical Specifications of Interoperability).

Suppose an attacker is already inside your network and has been for months. What signal in a monorail environment would you trust to tell you that, and what signal have you learned to ignore?

We would look for changes in OT traffic patterns (assuming these are known and controlled), undesired component behaviour or unavailability and uncontrolled configuration changes. Vigilance through systems (EDR, IDS, SIEM) is great, never underestimating processes at SOC level or the right training to railway staff. Plus, of course, rehearsing business continuity plans assuming worst-case scenarios.

Perhaps the latent threat is that where relaxation is perceived and awareness by rail staff (operations, maintenance, contractors) is little or diminishing. Much harm can also be caused by weak / uncontrolled supply chains – especially when these are shaped up as industrial SME’s that may struggle to find a business case to apply paradigms like “security by design”, “SBOM” or a lifecycle view to patch management.

If you had to hand your successor one hard-won rule that no certification course teaches, written on a single index card, what would it say?

Manage your risks. A risk-based approach is more than just a good start. Assume uncertainty principle inequation: attackers’ ability ≥ yours. Never assume that visibility equals control.

The objective is resilience. Systems must be able to operate safely even under degraded or uncertain conditions. In practical terms, this means combining:

  • Risk-based decision making
  • Continuous monitoring
  • Preparedness for worst-case scenarios

Ultimately, if we fail to prepare, we are simply preparing to fail.

Apply today: Simplify security management with CIS SecureSuite Platform