Skip to main content

Rail signalling system ‘could be liable to hacking’

A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned. Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up. "However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about
April 27, 2015 Read time: 2 mins
A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned.

Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up.

"However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about it. Safeguards are going in, in secret, but it's always possible to get around them," he said.

ERTMS uses a computer in the driver's cab to control the speed and movement of the train, whilst taking account of other trains on the railway. Although still operating under the umbrella term of ERTMS, 5021 Network Rail says it is creating its own traffic management system to optimise performance.

Network Rail said it acknowledges the threat. A spokesman said "We know that the risk [of a cyber-attack] will increase as we continue to roll out digital technology across the network. We work closely with government, the security services, our partners and suppliers in the rail industry and external cyber security specialists to understand the threat to our systems and make sure we have the right controls in place."

Related Content

  • Monitoring and transparency preserve enforcement's reputation
    July 30, 2012
    What can be done to preserve automated enforcement's reputation in the face of media and public criticism? Here, system manufacturers and suppliers talk about what they think are the most appropriate business models. Recent events in Italy only served to once again to push automated enforcement into the media spotlight. At the heart of the matter were the numerous alleged instances of local authorities and their contract suppliers of enforcement services colluding to illegally shorten amber signal phase tim
  • Michigan researchers show how easy it is to hack trucks
    August 5, 2016
    Cybersecurity researchers have already shown how easy it is to hack a Jeep Cherokee and take control of its brakes and steering, resulting in a recall for the vulnerability to be corrected. At the Usenix Workshop on Offensive Technologies conference next week, a group of University of Michigan researchers plan to demonstrate how trucks, which have also begun adding similar electronic control system, can be vulnerable to hacking. They plan to show how the openness of the SAE J1939 standard used across
  • Kapsch granted approval for first GSM-R system in Poland
    May 27, 2014
    The President of the Polish Office of Rail Transportation (UTK) has granted approval for the operation of the Global System for Mobile Communications - Railway (GSM-R) system implemented by Kapsch CarrierCom on route E30 on the Bielawa Dolna–Węgliniec–Legnica route. The authorisation recognises, for the first time in Europe, that implementation of the GSM-R system has been completed in compliance with the European Union’s new Technical Specifications for Interoperability (TSI) for the control-command an
  • Developments in security for wireless communications networks
    July 20, 2012
    David Crawford looks at new developments in security for wireless communications networks. Wireless communications - including mobile phone links - are well recognised as a key transport technology. They are low-cost, easily installed, well supported by the wider IT industry and offer the protocols of choice for much metropolitan area networking on which transport applications can piggyback.