Skip to main content

Rail signalling system ‘could be liable to hacking’

A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned. Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up. "However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about
April 27, 2015 Read time: 2 mins
A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned.

Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up.

"However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about it. Safeguards are going in, in secret, but it's always possible to get around them," he said.

ERTMS uses a computer in the driver's cab to control the speed and movement of the train, whilst taking account of other trains on the railway. Although still operating under the umbrella term of ERTMS, 5021 Network Rail says it is creating its own traffic management system to optimise performance.

Network Rail said it acknowledges the threat. A spokesman said "We know that the risk [of a cyber-attack] will increase as we continue to roll out digital technology across the network. We work closely with government, the security services, our partners and suppliers in the rail industry and external cyber security specialists to understand the threat to our systems and make sure we have the right controls in place."

Related Content

  • October 27, 2016
    The downside of driverless vehicles
    Driverless cars will have a detrimental effect on congestion and security while the road safety benefits can be achieved sooner and cheaper using ADAS, argues Colin Sowman. Many Governments are consulting about the introduction of driverless vehicles and even running trials. As 70% or 80% of crashes are caused by human error, the promise of a crash-free future of driverless, self-driving or autonomous vehicles (call them what you will) is alluring, as are the claims of reduced congestion and lower emissions
  • May 9, 2022
    BlackBerry warns of hacking danger
    As connected vehicles inch towards becoming a common sight, there are concerns that they are ripe for hacking by malign actors. Alan Dron looks at BlackBerry’s 2022 Threat Report
  • July 14, 2023
    What Citizen Kane can teach transportation engineers
    Andy Boenau suggests that one of the most famous movies of all time might have lessons for our industry. And they’re all about not knowing things...
  • November 6, 2017
    SwRI investigates cybersecurity weaknesses in transportation management systems
    Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.