Our key areas of focus in:

  • OT Security Management in accordance with CLC/TS 50701
  • Implementation of the BAV CySec-Rail guideline
  • Cyber risk analysis for railway systems
  • Verification and validation of security measures
  • Training and Coaching
  • Cyber Resilience Act (CRA)

OT Security Management in accordance with CLC / TS 50701

OT security as part of a holistic systems engineering approach

OT security (Operational Technology Security) is a key component of modern railway systems. Security measures in operational technology serve to ensure the availability and integrity of systems, as well as the safety of people and equipment.

In the railway sector, cyber security requirements must be aligned with the specifications for functional safety, the RAM requirements (reliability, availability and maintainability), and the requirements for functionality and quality. The relevant standards are EN 50126, EN 50129, EN 50716, EN 50159, CLC/TS 50701 and the IEC 62443 series.

Thanks to its extensive experience in the interaction between rail vehicles, infrastructure and signalling systems, Enotrac supports operators, manufacturers and integrators in the introduction and implementation of OT security processes. Our services include OT risk analyses, the integration of cyber security into development processes, support with tendering and acceptance procedures, and supplier and interface management between OT and IT security.

In this way, we ensure that cyber security is integrated into railway projects from the outset and implemented in compliance with standards throughout the entire lifecycle.

Illustration der CySec Rail Richtlinie

Implementation of the BAV Cybersecurity for Railways Directive (CySec-Rail)

The requirements of the BAV CySec-Rail Directive present new challenges for operators, manufacturers and integrators.

Enotrac supports you with:

  • Interpreting regulatory requirements
  • Defining cyber security objectives
  • Carrying out cyber risk analyses
  • Developing security concepts
  • Integration into existing security documentation
  • Preparation for audits and acceptance tests

Our aim is to implement the requirements in a manner that is both compliant with standards and cost-effective.

Arbeit bei Enotrac als Ingenieur

Support for project owners and consultancy for operators

For infrastructure operators and transport companies, Enotrac carries out independent reviews of cyber security activities within projects.

This includes:

  • Review of supplier documentation
  • Tender support
  • Assessment of security concepts
  • Risk analyses
  • Support during acceptance testing and commissioning
  • Interface management between OT and IT security

In this way, we create transparency and reduce project risks.

Enotrac Engineers at work

Verification and validation of cyber security measures

Enotrac offers manufacturers and operators planning, management or support for verification and validation activities in projects involving safety-critical systems. This involves checking the required OT security documentation and ensuring alignment with functional safety.

Verification and validation are an essential part of the security evidence chain in accordance with TS-50701.

Our services include:

  • Planning of verification and validation activities
  • Review of security documentation
  • Verification and validation of TS-50701 compliance
  • Coordination between safety and security
  • Support with verification and approval procedures

This ensures that defined safety requirements are demonstrably met.

Enotrac Engineers at Work

Training, awareness-raising and coaching on cyber security in the rail sector

Cyber security in the railway sector requires not only technical expertise but also a deep understanding of railway-specific standards, processes and regulatory requirements. Enotrac supports operators, manufacturers and project teams with practical training, awareness programmes and personalised coaching on all aspects of safety and security. The training content covers the relevant standards and guidelines for the railway sector, including EN 50126, EN 50129, EN 50716, EN 50159, CLC/TS 50701, as well as regulatory requirements such as CySec-Rail and the Cyber Resilience Act. There is a particular focus on OT cyber security management and the secure integration of cyber security into the development, approval and operational processes of railway systems. The emphasis is on practical application, the establishment of effective security processes and the sustainable embedding of cyber security within the organisation. All training courses are tailored to the specific requirements and target groups of our clients.

Cyber Resilience Act (CRA)

Support with the implementation of the Cyber Resilience Act

The European Union’s Cyber Resilience Act (CRA) sets out new requirements for the cyber security of products containing digital components. Enotrac supports manufacturers and integrators in assessing and implementing these requirements in railway projects.

Our services include assessing the applicability of the CRA to your products, preparing the necessary supporting documentation, and planning and integrating the regulatory requirements into development and project processes. In doing so, we ensure that implementation is aligned with existing standards such as CLC/TS 50701, IEC 62443 and CySec-Rail.

Support with selected IT security topics

In addition to OT security, Enotrac also supports companies in the rail and mobility sector with selected information security issues.

Our focus here is particularly on the interfaces between IT and OT systems.

Our services include:

  • Cyber risk assessments
  • Support with regulatory requirements
  • Supplier management
  • Development of security governance structures
  • Awareness-raising and training programmes

In doing so, we focus on railway-specific challenges and integration into existing operational and infrastructure processes.

Why choose Enotrac for cyber security in the railway sector?

Enotrac combines in-depth railway know-how with sound expertise in cyber security, safety and OT security. Thanks to our experience in rolling stock, infrastructure and signalling projects, we support operators, manufacturers and integrators in implementing CySec-Rail, CLC/TS 50701 and the Cyber Resilience Act (CRA). As an independent partner, we support railway projects throughout their entire lifecycle and ensure the secure, practical and standards-compliant implementation of cyber security requirements.

Talk to our experts

FAQs on cyber security in the rail sector