Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

For more information on companies in this article

Related Content

  • Ford and StreetLight Data combine on safety  
    October 16, 2020
    Collision data and travel patterns are overlaid to see where road improvements are needed
  • Road user charging - replacing the gas tax with a mileage based fee
    January 19, 2012
    Oregon Department of Transportation's James Whitty discusses his state's progress with VMT fee-based charging. Back in 2001, the state of Oregon stole a lead on the rest of the US when it decided to address the need to do something about the gas tax and its decreasing ability to fund highway construction and upkeep. Recognising that a dwindling pot of money could only shrink further as vehicles became more fuelefficient, Oregon's Legislative Assembly passed laws which led to the setting up, by the state's g
  • IRF takes politicians to task on road safety
    January 7, 2013
    The International Road Federation has issued a wake up call to government ministers, in the form of its Vienna Manifesto on ITS. Four years on from coming to a key decision on ITS, the International Road Federation (IRF) now faces a further question – how can it ensure its Vienna Manifesto on ITS achieves maximum impact? This is a challenge the organisation is not taking lightly. Issues the manifesto has been drawn up to address have become more acute in the time taken to publish it and are forecast to wors
  • Shared mobility data drives Inrix's interest in Ride Report
    November 15, 2023
    Firm helps cities launch and manage micromobility & car-share programmes