Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

Related Content

  • June 25, 2012
    New research helps planners address California's air quality and urban sprawl controls
    The Mineta Transportation Institute has released a peer-reviewed research report, An Economic and Life Cycle Analysis of Regional Land Use and Transportation Plans. This study is the third in a series that applies a new form of spatial economic model to examine the economic effects, the distribution of those effects, and their implications for California's Assembly Bill (AB) 32 and Senate Bill (SB) 375 implementation. These bills are intended to significantly reduce greenhouse gases (GHG) and urban sprawl b
  • March 24, 2022
    Keeping an eye on cyberattacks
    Hackers love an open door and ransomware attacks on transit agencies are rising. Ben Spencer examines a report by Mineta Transportation Institute on keeping personal data safe
  • May 11, 2012
    Free report asks: can land ‘value capture’ help fund transit projects?
    The Mineta Transportation Institute in the US has released its newest research report, Decision Support Framework for Using Value Capture to Fund Public Transit: Lessons from Project-Specific Analysis. The research investigates the viability of land "value capture" (VC) to help generate revenue for transit provision. Five VC mechanisms are evaluated in depth, including tax increment financing (TIF), special assessment districts (SADs), transit impact fees, joint developments, and air rights. The report incl
  • May 14, 2018
    The rise of V2X: it’s time for ITS to put up the shields in cyberspace
    Traffic management has largely been shielded from the sort of malicious hacking that is commonplace in other industries – but with billions of connected devices in the world it won’t stay that way, warn internet experts Keith Golden and Brandon Johnson. Traditionally isolated from networks and the internet over most of its history, the traffic management industry has largely been shielded from malicious hacking and system intrusion that have become commonplace in other industries. However, as the rate of