Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

For more information on companies in this article

Related Content

  • GMV brings Spain’s regional public transport together
    July 25, 2024
    Spanish government plans to bring better connectivity to the country’s rural areas
  • Public transport operators implement passenger safety systems
    December 4, 2012
    Operators of public transport systems are arming themselves with sophisticated systems of technology to ward off terrorism threats to passenger safety. David Crawford reports. City transportation authorities worldwide are looking more keenly than ever for mass transit solutions to overcome traffic congestion and manage commuter flows. As they do so, concerns over passenger security are driving development of new technologies for terrorist incident detection, response and emergency passenger evacuation. The
  • Infrastructure spending is an investment in economic recovery
    January 20, 2012
    Transportation funding is caught in the crossfire as the President calls for infrastructure investment and a reinvigorated Republican majority in the House pushes back on federal spending. Andrew Bardin Williams reports. Every few months some politician or pundit declares that the country is on the verge of making the most important political decision in a generation. The 2006 mid-term election; the 2008 Presidential election; the passing of the stimulus bill; healthcare reform; the mania surrounding Tea Pa
  • Is the US economic stimulus programme working?
    January 30, 2012
    In this third installment in a series of articles exploring the impact of the US economic stimulus programme on the ITS industry, Pete Goldin reports on the ongoing debate in Congress about American Recovery and Reinvestment Act. A debate continues to rage in the US Congress and in the media about the effectiveness of the American Recovery and Reinvestment Act of 2009 (ARRA), and especially the timeliness of the ARRA payments. Some of the arguments seem somewhat partisan in origin while others point out fla