Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

For more information on companies in this article

Related Content

  • 'Don't go from lockdown to gridlock', warns UITP
    July 29, 2020
    Coronavirus offers chance to rethink how we want to move about our cities, suggests report
  • Australian road pricing, road funding needs more debate
    January 31, 2012
    Everyone in the road transport industry in Australia is talking road pricing - everyone, that is, except the politicians. Christine Keyes reports. At the end of 2008, Australia's road transport industry was wringing its collective hands, unable to raise more than $100 million from an individual bank for any Public Private Partnership (PPP). The A$750 million Peninsula Link project, announced by the Victoria Government in March 2009, was the first road project in the country to be put out to market as an ava
  • FTA seeks to increase oversight of transit systems
    August 17, 2015
    The US Department of Transportation (USDOT) is seeking to increase oversight of the nation's public transportation systems after a spate of issues on the Washington, DC, Metrorail system and other subways have raised questions about US transit safety. The USDOT’s Federal Transit Administration (FTA) has proposed a rule to establish a Public Transportation Safety Program under its new safety oversight authority established by the Moving Ahead for Progress in the 21st Century Act. The proposed rule would
  • Gridsmart creates cybersecurity division
    May 11, 2018
    Gridsmart Technologies has formed a cyber security group to help transportation industry technology and infrastructure partners build security programmes for their organisations. The Gridsmart Information Security and Threat Intelligence Division (ISTI) will provide vulnerability and threat assessments and tailored security strategies to private companies, state and municipal Departments of Transportations and other groups working to enhance their technical infrastructure. ISTI, led by cyber security