Engineering news

How to secure railways and other operational technology against cyber threats

Professional Engineering

(Credit: Shutterstock)
(Credit: Shutterstock)

Our systems have never been more connected – or at more potential risk. As increasing numbers of digital systems are introduced in rail, manufacturing, power and other engineering sectors, the cyber security threat is growing. AI is accelerating those risks.

Learn how to protect your operational technology at an upcoming IMechE training course, OT Cyber Security for Engineers. Next running in London on 19 November, the course will help attendees develop the confidence to engage with cyber security specialists, identify risks and ensure cyber security is considered at the right stages of a project.  

We spoke to course trainer Alex Bishop, whose main experience is in the railway industry. Here are five tips he gave to help you start to get to grips with OT cyber security.

Consider cyber security from the start

The stumbling block I see quite commonly with new railways and stations is people not having an understanding of what the cyber security manager’s current capabilities are and what their planned capabilities may be. Rail projects go on for a long time, so there are risks that a contractor will specify something the end user cannot actually manage.

Make sure that those who are going to be managing cyber security after the project is completed are involved in specifying the cyber security requirements throughout the project lifecycle.

Communicate clearly

About 80% of the work I do isn't the interesting technical work – it’s identifying different stakeholders, communicating with them and tailoring the message in a language that they understand.

You can get into a lot of very technical detail with cyber security, so it’s important not to use lots of acronyms and concepts people aren't familiar with. To actually be successful, you need to get various levels of stakeholders onboard and actually help them understand what it is you're trying to do and why you're doing it.

Develop your ability to communicate cyber security topics. Getting other people to help you communicate clearly is also very important.

Don’t just assess risk – act on it

Cyber security risk assessment is really important, but the implementation of controls to address that risk isn't always followed up in the right way.

This is a problem for two main reasons. The first is that it's quite difficult to do cyber security risk assessment well. The likelihood of a cyber security risk is based on different threat actors – so unless you're really informed, you’re just guessing at what is out there.

The second is the controls you have in place might suddenly need enhancing. You have to have a practical way forward. Make sure you're implementing a solid baseline of cyber security across all of your systems and assets.

Don’t treat cyber security as a separate task

One of the key ways to build defence in depth is understanding cyber security processes in all relevant industries – not just rail, energy and so on. Make sure that you're implementing cyber security in a way where it goes through entire organisations, interacting with processes on all relevant projects.

Accept that change happens

You've got to accept that changes happen in cyber security. The threat environment changes, especially during a long project. You might start off with an idea of what you want to do, then things change during delivery – new defensive technology will be developed, the threat environment may well change. You need to deliver the cyber security in a flexible way that accounts for that.

The cyber security we specify at the start of a 10-year project isn't going to be the cyber security that's needed at the end of a 10-year project.

IMechE’s OT Cyber Security for Engineers training course next runs in London on 19 November. Find out more, check for future dates and register on the course page.


Want the best engineering stories delivered straight to your inbox? The Professional Engineering newsletter gives you vital updates on the most cutting-edge engineering and exciting new job opportunities. To sign up, click here.

Content published by Professional Engineering does not necessarily represent the views of the Institution of Mechanical Engineers.

Share:

Professional Engineering magazine

Professional Engineering newsletter

A weekly round-up of the latest Professional Engineering news, straight into your inbox.

Log in and opt in to receive PE Weekly

Related articles