Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

For more information on companies in this article

Related Content

  • EU steps up efforts to tackle cyber threats
    July 7, 2016
    The Commission has launched a new public-private partnership with the non-profit European Cyber Security Organisation (ECSO) on cyber-security that is expected to trigger US$2 billion (€1.8 billion) of investment by 2020. This is part of a series of new initiatives to better equip Europe against cyber-attacks and to strengthen the competitiveness of its cyber-security sector. The EU plans to invest US$500 million (€450 million) under its research and innovation (R&I) programme Horizon 2020, with the rema
  • Incentive schemes target single occupancy commuters
    October 14, 2016
    Andrew Bardin Williams looks at state-run schemes to encourage green transportation habits with raffles, gift cards, competitions and frequent traveller points. The societal benefits of green transportation are obvious: less congestion, cleaner air and healthy economy. Equally the advantages for individuals are pretty clear too: a healthy lifestyle, freedom of movement and the feeling of being a part of something greater than oneself.
  • MaaS: 'It's been much easier to convince politicians than we expected'
    August 11, 2021
    As she leaves the Mobility as a Service sector, Piia Karjalainen explains why the user must continue to be the focus – and why we haven’t yet even seen half of the innovations available 
  • $7bn funding from FHWA for US infrastructure resilience
    August 8, 2023
    Money will be available for highway and transit projects to mitigate climate change effects