Skip to main content

Transit 'unprepared' for cyberattack, says MTI

Four in 10 agencies do not have cybersecurity action plan in place, researchers find
By Adam Hill October 9, 2020 Read time: 2 mins
More than half of transit agencies ignore basic anti-hacking requirements (© Daniil Peshkov | Dreamstime.com)

Research from the Mineta Transportation Institute (MTI) has found that US transit agencies are not properly prepared for the potential havoc wreaked by hackers.

The report - Policy Recommendation to Enhance Surface Transit Cyber Preparedness – surveyed 90 transit agency technology leaders.

It uncovered a mismatch between approaches and attitudes: although 80% of agencies said they felt prepared, just 60% of those questioned actually have a cybersecurity preparedness plan.

This suggests complacency and a lack of readiness to face problems: MTI says most transit agencies “do not have many of the basic policies or personnel in place to respond to a cyber incident”.

This is particularly significant because the US Department of Homeland Security – which part-funds MTI - has designated the transportation as one of 16 critical infrastructure sectors whose disruption would have a debilitating effect on the country’s security.

MTI, based at San Jose State University, points out that resources to combat hack attacks are ‘scarce’ for transit agencies, which means “there needs to be a collaborative effort from the federal government, the industry, and agency leadership to establish, maintain and refine cybersecurity programmes”.

Researchers insist, however, that transit operators must adopt and implement minimum cybersecurity standards before receiving cash from the Federal Transit Administration (FTA).

The report found that more than half of agencies ignore “one of the most basic cybersecurity preparedness requirements” by failing to keep a log for longer than 12 months.

In addition, 36% do not have a cyber disaster recovery plan and 67% do not have a cyber crisis communications plan.

Help is at hand. The report’s principal investigator, Scott Belcher, says: “Fortunately, there is an abundance of information and tools, such as the Transportation Systems Sector (TSS) Cybersecurity Framework Implementation Guidance and accompanying workbook, available to public transit agencies to support a cybersecurity programme.”

For more information on companies in this article

Related Content

  • Rekor & AWS talk to DoTs: they said what?!
    October 30, 2023
    Rekor and AWS asked the US transportation industry what it was thinking. The US transportation industry didn’t hold back. Adam Hill picks over some robust findings
  • Number plate analysis tool from Tattile
    March 18, 2020
    Tattile has unveiled a software tool which it says enables users to aggregate and analyse data of all connected cameras in a given area.
  • Report highlights ways to make roads safer for pedestrians
    November 23, 2012
    A report released by the International Transport Forum (ITF) at the OECD highlights the role of national governments in improving pedestrian mobility and proposes twelve measures to create safer walking environments. The study, entitled Pedestrian Safety, Urban Space and Health, was prepared by a working group of transport experts and urban planners from nineteen countries and the World Health Organisation under the leadership of the ITF. The report comes to a number of conclusions, including the fact that
  • Russia invests in ITS technology
    May 11, 2012
    Russia’s transport systems are developing on a grand scale with ITS central to the plans, thanks in no small part to a recently relaunched ITS Russia. Jon Masters interviews the organisation’s chief executive officer Vladimir Kryuchkov Over coming years many of the biggest deployments of new technology for transport are likely to be seen in Russia. For a political and economic superpower, the world’s biggest country has only recently started to harness ITS for the good of its transport networks. But the sca