Cybersecurity in Rail Transport – What Does It Mean in Practice?
Cybersecurity in the railway sector does not have a single universal definition. This is due to the diversity of organisations that make up the rail system. Michał Młotek, Deputy Director of the Office for the Protection of Classified Information and Defence Affairs at Polish State Railways (PKP), explains the practical dimension of this issue.
The expert points out that each part of the railway sector views the passenger from a different perspective. Infrastructure managers focus primarily on elements related to the operation of the railway network, station operators concentrate on the safety of people using these facilities, while rail carriers are responsible for passengers during their journeys. As a result, cybersecurity measures must be tailored to the specific nature of each organisation’s activities.
“We no longer look solely at systems; we look at the impact of systems on people,” emphasises Michał Młotek, highlighting a shift in the way cyberspace is perceived, with people placed at the centre. This means moving beyond an approach focused exclusively on technology and infrastructure towards understanding how digital systems affect the safety, comfort and day-to-day experience of users.
Michał Młotek’s remarks demonstrate that effective cybersecurity in the railway sector requires an individual approach tailored to the needs of different areas of the industry. Protecting IT systems remains important, but what matters most is understanding how their operation translates into the safety and experience of passengers, as well as everyone involved in rail transport.