Skip to main content

Illinois DoT and Cybrbase collaborate on lower-cost cybersecurity

Six of the state's smaller, rural transit agencies will take part in pilot project
By Adam Hill June 2, 2025 Read time: 2 mins
Smaller transit agencies are "routinely left out of the cybersecurity conversation" (© Phuttaphat Tipsana | Dreamstime.com)

Illinois Department of Transportation (IDoT) is to pilot a group-based cybersecurity vulnerability assessment across six small, and mid-size, rural Illinois transit agencies.

IDoT will work with transportation infrastructure cybersecurity firm Cybrbase with these local agencies, which often have relatively few staff and limited budgets, and are "routinely left out of the cybersecurity conversation".

The pilot will examine where security risks might be and help to mitigate them before they compromise public safety, transportation systems and municipal operations.

The idea is to do this at a "significantly lower" cost than traditional cybersecurity audits, using Cybrbase’s proprietary NIST-CRR-based platform, which is powered by AI.

Cybrbase says it "aims not only to bolster local defences but also to serve as a model, showcasing how state-level transportation agencies, insurance risk pools, and transit agencies can work collaboratively with their local transit agencies to create a more resilient transportation ecosystem".

A recent Mineta Transportation Institute (MTI) study - Does the Transit Industry Understand the Risks of Cybersecurity and are the Risks Being Appropriately Prioritised? - revealed persistent cybersecurity gaps in transit agencies in general, but particularly in small and rural transit agencies across the US.

It noted that "many of these agencies are challenged by outdated technology, and limited resources—making them particularly susceptible to cyberattacks". 

Scott Belcher, senior advisor at Cybrbase, MTI research associate, and former CEO of ITS America, says: “As a transportation leader, IDoT is closely watched by other agencies around the nation who may not be aware that cybersecurity vulnerabilities exist among their transit agencies. This initiative is intended to close that gap.”

The local agencies in the pilot include Decatur Public Transit System, Piatt County Public Transportation, QC Metrolink, Reagan Mass Transit and Warren County Public Transportation.

Each of them will complete its assessment independently and confidentially, but is expected to share best practices across the cohort.

Related Content

  • May 14, 2018
    The rise of V2X: it’s time for ITS to put up the shields in cyberspace
    Traffic management has largely been shielded from the sort of malicious hacking that is commonplace in other industries – but with billions of connected devices in the world it won’t stay that way, warn internet experts Keith Golden and Brandon Johnson. Traditionally isolated from networks and the internet over most of its history, the traffic management industry has largely been shielded from malicious hacking and system intrusion that have become commonplace in other industries. However, as the rate of
  • February 10, 2025
    Nema releases comms standard for connected vehicles
    US body says it will ensure better communication for wireless safety messages
  • November 6, 2017
    SwRI investigates cybersecurity weaknesses in transportation management systems
    Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.
  • January 20, 2025
    Oxa joins Sunderland AV shuttle programme
    UK city initiative aims to show how AVs can connect people to key destinations