Skip to main content

Rail signalling system ‘could be liable to hacking’

A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned. Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up. "However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about
April 27, 2015 Read time: 2 mins
A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned.

Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up.

"However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about it. Safeguards are going in, in secret, but it's always possible to get around them," he said.

ERTMS uses a computer in the driver's cab to control the speed and movement of the train, whilst taking account of other trains on the railway. Although still operating under the umbrella term of ERTMS, 5021 Network Rail says it is creating its own traffic management system to optimise performance.

Network Rail said it acknowledges the threat. A spokesman said "We know that the risk [of a cyber-attack] will increase as we continue to roll out digital technology across the network. We work closely with government, the security services, our partners and suppliers in the rail industry and external cyber security specialists to understand the threat to our systems and make sure we have the right controls in place."

For more information on companies in this article

Related Content

  • Ricardo to acquire international rail business
    April 20, 2015
    International engineering and technology company Ricardo has announced an agreement to acquire the business, operating assets and employees engaged in the businesses of LR Rail, from Lloyd's Register Group. The acquisition will be materially complete on or before 1 July 2015 and the business will operate as the core of a new international rail business within Ricardo and combined with Ricardo's existing rail industry expertise, to be branded Ricardo Rail. Current LR Rail managing director Paul Seller wi
  • Bhatt: 'Critical opportunity' for cybersecurity
    July 22, 2021
    ITS America CEO Shailen Bhatt tells US Senate funds are needed to 'manage vulnerabilities'
  • Drivewyze introduces notification service for truck drivers
    August 16, 2019
    US technology company Drivewyze has launched a notification service that issues an audible tone and visual alert when a truck approaches dangerous curves or low bridges. Brian Heath, CEO of Drivewyze, says the company’s rollover alerts, on targeted exit ramps and curves, are geo-fenced at 500 locations in 32 states. “We worked closely with our state partners to identify the areas that had higher incidences of rollovers, so our alerts offer an early warning to drivers to check their speed,” he adds. The
  • Hackers remotely control jeep
    July 22, 2015
    Two US security experts have demonstrated security flaws in a Jeep Cherokee by taking wireless control of its systems from ten miles away. Writing on technology website Wired, Andy Greenberg, who was driving the jeep at the time, tells how Charlie Miller and Chris Valasek first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. Greenberg says, “The most disturbing manoeuvre came when they