Rail Transport: Critical Infrastructure on the Boundary Between Cyber and Physical

11. mája 2026

In August 2023, something happened on the Polish railways that until then had belonged to the realm of scenarios, not reality. Unknown actors abused the radio system for emergency stopping (radio-stop) and transmitted a signal that brought more than 20 trains to a halt in various regions of the country. The attack required no access to digital systems and no sophisticated malware. A radio transmitter and knowledge of publicly available tones were enough. It was a demonstration of why rail transport ranks among the most complex categories of critical infrastructure. It brings together older analogue and radio technology with contemporary IT and OT systems, and each of these layers has its own vulnerabilities.

The Slovak rail system


The Slovak rail system has three main actors. Železnice Slovenskej republiky (ŽSR), as the infrastructure manager, administers approximately 3,580 kilometres of track, signalling and safety systems, traffic control workplaces and communication networks. Železničná spoločnosť Slovensko (ZSSK) operates passenger transport. Železničná spoločnosť Cargo Slovakia (ZSSK Cargo) operates freight transport, which is strategically important for the transit between Ukraine, the EU and the countries of Western Europe.


It is precisely rail freight transport that has acquired a new strategic dimension since February 2022. The Slovak railway has become one of the principal routes for the transport of humanitarian and military aid to Ukraine, for the export of Ukrainian grain and for the logistical support of defence cooperation within NATO. This shift has transformed the railway infrastructure from a domestic transport service into a cross-border strategic corridor.


Layers of vulnerability


Rail transport has four layers at which it may encounter an attack. The first is the signalling and safety layer, which encompasses onboard train protection systems, fixed signals, automatic train operation and GSM-R radio communication systems. The European Rail Traffic Management System (ERTMS), which is being gradually rolled out on Slovak lines, brings modernisation, but also new digital dependencies.


The second is the traffic control and command layer, which encompasses traffic control workplaces, train operation control systems and integration with neighbouring operators. The third is the commercial and administrative layer, including reservation systems, ticket sales, freight logistics systems and integration with customs and border systems. The fourth is the physical infrastructure of tracks, bridges, tunnels and junction stations, the disruption of which can have a direct physical impact on the safety of operations.


Attacks on railways in recent years have affected each of these layers. The cyber attack on Britain’s Network Rail in September 2024 through Wi-Fi networks in stations. The ransomware attack on the Italian operator Trenitalia in March 2022, which disabled ticket sales at stations. The physical sabotage of DB Netz fibre-optic cables in Germany in October 2022, which paralysed northern Germany for several hours. Ukrainian railway Ukrzaliznytsia has been facing virtually continuous cyber and physical attacks since 2022, which it has withstood thanks to the exceptional improvisational capability of its personnel.


Regulatory framework


Rail transport is classified under Act No. 367/2024 Coll. on Critical Infrastructure within the transport sector, as one of the 11 sectors of critical infrastructure. Act No. 366/2024 Coll. (the transposition of NIS 2) places railway infrastructure managers and carriers among the entities providing critically important services. To these are added specific rail regulations, in particular EU Regulation 2016/796 on the European Union Agency for Railways (ERA) and Regulation 2023/1230 on the common safety method for cybersecurity in the rail sector.


In July 2024, ENISA, jointly with ERA, published guidelines for the cybersecurity of ERTMS, which set out minimum requirements for the protection of signalling systems, identity management, network segmentation and the management of vulnerabilities in supply chain components. Decree of the National Security Authority No. 227 of 2025 supplements these requirements with the Slovak regulatory context.


Three practical priorities


For operators in the rail sector, three practical priorities emerge. The first is segmentation between operational systems (signalling, traffic control, GSM-R) and corporate IT, including the management of remote access by suppliers to OT environments. The second is the management of vulnerabilities specific to rail components with a long life cycle, where firmware and operating systems are updated on a timescale of years, not months. The third is cross-border coordination with operators in neighbouring countries, in particular in the context of transit between the EU and Ukraine, where a failure on one side has an immediate impact on the other.


“Rail transport shows why the Act on Critical Infrastructure cannot be implemented solely from the perspective of IT security. The security risks for a train can take the form of phishing aimed at a traffic controller, the compromise of a software supplier, the jamming of a radio signal or the physical sabotage of a track. Functional resilience means seeing all these layers simultaneously and having an operationally rehearsed response for each of them,” states Ing. Tibor Straka, President of AKI SR.


The railway is a 19th-century technology that has become digital in the 21st century. It is precisely this layered character that makes it one of the most fascinating and most demanding sectors of critical infrastructure, and one that deserves systematic professional attention.


21. septembra 2026
On 16 September 2026, a test carried out in Norway demonstrated a new dimension of satellite navigation security. Europe’s Galileo system was tested under so-called spoofing conditions — a situation in which a receiver is fed a fake signal and may therefore receive incorrect information about its position.
21. septembra 2026
16. septembra 2026 sa v Nórsku uskutočnil test, ktorý ukázal nový rozmer bezpečnosti satelitnej navigácie. Európsky systém Galileo bol testovaný v podmienkach tzv. Spoofingu, teda situácie, pri ktorej je prijímaču podstrčený falošný signál a ten môže dostať nesprávnu informáciu o svojej polohe.
14. septembra 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles focusing on basic services under Act No. 367/2024 Coll. on Critical Infrastructure. This time, we look at a basic service that remains largely invisible to the public, yet its disruption can have an immediate impact on transport, industry and the wider economy – the operation of pipelines for the transportation of crude oil and fuels.
14. septembra 2026
Asociácia kritickej infraštruktúry SR pokračuje v sérii článkov venovaných základným službám podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Tentoraz sa venujeme základnej službe, ktorá zostáva pre verejnosť väčšinou neviditeľná, no jej výpadok môže mať veľmi rýchly vplyv na dopravu, priemysel aj fungovanie ekonomiky: prevádzkovaniu potrubí na prepravu ropy a pohonných látok.
8. septembra 2026
Several incidents in the space of a single week. And in one case, 4.2 GW of generation capacity was temporarily taken offline. Germany is dealing with a series of attacks on its electricity grid that highlights one important point: the target does not necessarily have to be the power plant itself.
8. septembra 2026
Niekoľko incidentov v priebehu jediného týždňa. A v jednom prípade dočasne vyradená výrobná kapacita 4,2 GW. Nemecko rieši sériu útokov na elektrickú sieť, ktorá ukazuje dôležitú vec: terčom nemusí byť samotná elektráreň.
5. septembra 2026
District heating and cooling are an important part of the energy infrastructure of cities and municipalities. Their role is not limited to providing thermal comfort; they create stable conditions for the functioning of households, public institutions, industry and other facilities. As energy systems become increasingly technologically complex, the importance of their reliability, preparedness and ability to respond to operational disruptions is also growing.
5. septembra 2026
Diaľkové vykurovanie a chladenie predstavujú významnú súčasť energetickej infraštruktúry miest a obcí. Ich úlohou nie je len zabezpečiť tepelný komfort, ale vytvárať stabilné podmienky pre fungovanie domácností, verejných inštitúcií, priemyslu a ďalších prevádzok. S rastúcou technologickou komplexnosťou energetických systémov zároveň rastie aj význam ich spoľahlivosti, pripravenosti a schopnosti reagovať na narušenie prevádzky.
2. septembra 2026
On Monday, 31 August 2026, a working meeting took place at the Ministry of Interior of the Slovak Republic with State Secretary of the Ministry of Interior Patrik Krauspe, Director General of the Crisis Management Section Jaroslav Kmeť, Naďa Trelová Sonogová from the Department of International Cooperation of the Ministry of Interior, and representatives of the Critical Infrastructure Association of the Slovak Republic (AKI SR).
2. septembra 2026
Na Ministerstve vnútra Slovenskej republiky sa v pondelok 31. augusta 2026 uskutočnilo pracovné rokovanie štátneho tajomníka MV SR Patrika Krauspeho, generálneho riaditeľa sekcie krízového riadenia MV SR Jaroslava Kmeťa, Nade Trelovej Sonogovej z odboru medzinárodnej spolupráce MV SR a predstaviteľov Asociácie kritickej infraštruktúry Slovenskej republiky (AKI SR).