The content is structured into modules that progressively build participants’ understanding from cybersecurity fundamentals and regulatory context through to risk assessment, zones and conduits, control selection, OT monitoring, incident response and emerging trends such as AI, digital twins and continuous security validation. Practical workshops and scenario-based exercises are used throughout to support the application of cybersecurity principles within real railway project and operator contexts.
Course code: DNV-R-4
Learning Objectives:
- Understand the current cybersecurity threat landscape affecting railway and industrial control environments, including relevant incident trends and sector-specific risks.
- Recognise the key regulatory and standards frameworks applicable to railway cybersecurity, including NIS2, the Cyber Resilience Act, IEC 62443 and IEC 63452.
- Explain the relationship between cybersecurity, railway safety, operational resilience and the delivery of secure railway systems across the project lifecycle.
- Apply introductory cyber risk assessment principles to railway systems, including the identification of assets, threats, vulnerabilities, zones, conduits and OT segmentation needs.
- Understand how security levels and appropriate cybersecurity controls are selected and justified in line with recognised industrial cybersecurity standards.
- Identify practical approaches for OT monitoring, vulnerability management, access control, incident response and continuous security validation in critical railway environments.
- Participate in practical workshops and scenario-based exercises to apply railway cybersecurity concepts to realistic operator, project and assurance contexts.
Scope:
Session 1 (3 hours):
- Current threat landscape and trends in the railway sector. Examples of cybersecurity incidents in industrial and railway environments.
- Railway regulatory framework: Horizontal regulations: NIS2, CRA. Railway-specific regulatory and standardization framework: TSA, IEC 62443, IEC 63452, Europe's Rail System Pillar. Relationship between regulatory requirements, risk management, and technical controls.
- Safety and Cybersecurity. Cybersecurity activities and deliverables in the context of the V Model
Session 2 (3 hours):
- Introduction to Risk Assessment
- Risk assessment in IEC 62443 and IEC 63452. Initial risk assessment, definition of zones, conduits, and OT segmentation.
- Practical Workshop I: Initial risk assessment of a railway system. Zones and conduits.
Session 3 (3 hours):
- Detailed risk assessment according to IEC 63452.
- Determination of Security Levels and selection of security controls.
- Practical Workshop II: Detailed analysis, control selection, and presentation of results.
Session 4 (3 hours):
- SOC and OT monitoring
- Vulnerability management and patching strategies in critical environments
- Identity and access management
- Incident response
- Innovation and trends in Rail Cybersecurity
- Specialized solutions for railway environments: Asset Discovery and OT visibility
- Threat Intelligence
- Continuous security validation
- AI applied to railway cybersecurity
- Digital twins for cybersecurity
- Simulation Exercise "Rail Cyber Plan"
- Team-based role-playing exercise for cybersecurity management in a railway operator.
- Technical, operational, and business decision-making.
Duration: 4 intensive, 3-hour long sessions of advanced practitioner-led training, combining expert instruction, applied workshops, and scenario-based technical exercises. This course can be delivered in different formats depending on location and customer requests.
Entry requirements: This course is suitable for railway professionals, engineers, project managers, safety specialists, assurance personnel, operators, suppliers and other stakeholders who require an understanding of cybersecurity in railway and industrial control environments. No formal cybersecurity qualification is required; however, participants should have a basic understanding of railway systems, infrastructure, operations or project delivery. Prior awareness of safety, RAMS, systems engineering, signalling, rolling stock, infrastructure or operational technology environments would be beneficial.
Assessment: There is no formal assessment in this course
Certificate and validity: Participants who attend all 4 sessions will receive a certificate of attendance.
Delivery method: Delivered as either in-person or virtual, expert-led learning experience, the course combines specialist instruction, facilitated discussion, and applied workshop sessions to maximise practical value for participants. Alternative delivery formats can also be tailored to client requirements, audience profile, and cohort size.
Available dates: Course dates are available on request and can be scheduled to align with client demand, team availability, and preferred delivery timelines.