Newsletter
Railway Insights for a better Future

Receive the latest news on the following topics:

  • Trends, news and expert contributions,
  • upcoming events,
  • studies, dossiers and company reports.

Subscribe to the RailMarketResearch Newsletter




    Current newsletter
    RMR Newsletter Research, developments and scientific insights in this issue.
    RailMarketResearch

    September 2026

    Dear reader,


    Rail is critical infrastructure. That statement appears in regulatory frameworks, policy documents, and security guidelines with regularity. What it means in practice, and how well the sector is actually prepared for cyber threats, is a different question.


    The threat picture has changed significantly in recent years. Digitalisation has connected systems that were previously isolated: signalling technology, operations control, passenger information, rolling stock diagnostics, ticketing. Each connection creates functionality. Each connection also creates an attack surface. The 2026 ENISA NIS360 assessment found that the criticality of the rail sector had increased, partly because of its growing strategic role in military logistics and heightened cyber-threat exposure across Europe.


    The regulatory framework is tightening in parallel. NIS2 classifies railway undertakings and infrastructure managers as essential entities with binding cybersecurity obligations. The new Telematics Applications TSI, which entered into force in March 2026, establishes requirements for data sharing, data quality, and cybersecurity in railway operations. The direction is clear: cybersecurity in rail is moving from voluntary best practice to enforceable standard.


    The gap between that regulatory direction and operational reality, however, remains significant in parts of the sector. Studies consistently point to uneven cybersecurity maturity, particularly in operational technology environments, where legacy systems, long update cycles, and supplier dependencies create structural vulnerabilities that are difficult to address quickly. The human factor adds to this: many incidents are not the result of sophisticated attacks, but of phishing, weak credentials, and insufficient security awareness across all levels of an organisation.


    This issue looks at current research addressing these challenges, from the systematic identification of attack vectors in the rail system to questions of how cybersecurity competence can be built and sustained across the sector.


    Best regards,

    Your RMR-Team

    Research Projects

    S5LECT - SatCom and 5G Link, Edge and CybersecuriTy

    Securing railway communications is becoming more complex as the sector moves from the closed, proprietary GSM-R system toward FRMCS, which is built on public 5G infrastructure and, in some scenarios, satellite connectivity. Opening railway communications to public networks brings significant operational advantages. It also introduces cybersecurity risks that purpose-built legacy systems were largely designed to avoid.


    S5LECT, funded under Horizon Europe by EUSPA and coordinated by SNCF Réseau, addresses this directly. The project develops a seamless handover solution between 5G terrestrial networks, satellite links, and GSM-R, with cybersecurity risk assessment and mitigation integrated throughout. Partners include Railenium, Hitachi Rail, Radiolabs, and CEIT. 


    The consortium studies the hybridisation of terrestrial and satellite communications for safety-critical railway applications, assesses the cybersecurity risks this hybridisation creates, proposes concrete mitigation solutions, and develops an innovative edge computing architecture to reduce latency in train control systems. A dedicated testing laboratory based on real systems and IP-level emulation has been developed to assess performance without requiring full-scale field tests.


    The project held its mid-term event in San Sebastián in October 2025. Total project volume: approximately €1.9 million, 100% funded by the EU. Duration: 30 months.


    QUDIS — Post-Quantum Cryptography for Railway Signalling and Control Systems

    The cryptographic methods that currently protect railway control and communications infrastructure were not designed with quantum computers in mind. As quantum computing capabilities advance, classical encryption methods face a long-term structural vulnerability: a sufficiently powerful quantum computer could break the cryptographic foundations on which today's railway security architectures rely. For infrastructure designed to operate for decades, this is not a distant concern.


    QUDIS addresses this directly. The project investigates how post-quantum cryptography can be implemented in the security architectures of Deutsche Bahn, with a particular focus on signalling and control systems. For the first time, quantum-resistant protection methods are to be introduced into railway operational technology. Since migrating cryptography in a system of this complexity can have direct operational consequences, the project sets out to research, analyse, and optimise the migration process comprehensively before any deployment — ensuring uninterrupted operations and making potential constraints plannable well in advance.


    The research team investigates and demonstrates the necessary post-quantum cryptographic methods and associated protocols, as well as the processes of crypto-agility, using railway-specific use cases as the basis for evaluation.


    Coordinated by DB Systel GmbH, the consortium includes genua GmbH, INCYDE industrial cyber defense GmbH, Hochschule RheinMain, Universität Regensburg, and Universität Konstanz.


    Total project volume: €2.76 million, of which €1.79 million is funded by the German Federal Ministry of Education and Research (BMBF). 

    Duration: July 2024 to June 2027.


    Planned Research Projects

    Evaluation of the potential of sector-specific cybersecurity profiles

    Cybersecurity standards such as ISO/IEC 27000, IEC 62443, and the railway-specific CLC/TS 50701 provide a comprehensive framework — but they are extensive, leave considerable room for interpretation, and make individual risk assessments costly. Germany's BSI IT-Grundschutz shows how standardised building blocks can simplify this: by bundling general requirements for typical processes and systems, it reduces the engineering effort for organisations applying it. No equivalent exists for the railway sector.


    A project commissioned by DZSF will evaluate whether railway-specific cybersecurity profiles could fill this gap. Drawing on the logic of BSI IT-Grundschutz and the precision of the EU-Rail System Pillar's generic system model, such profiles would define appropriate requirements and specifications for specific railway processes and components in a structured, reusable format. The project will determine how much these profiles could accelerate security engineering and simplify the secure operation of railway systems, and for which parts of the rail sector a comprehensive development of such profiles would be worthwhile.


    Results will be used to decide whether a full-scale development of railway-specific cybersecurity profiles is justified, and whether the concept is suitable as a sector-specific security standard (B3S) under German BSI law.


    Strategic growth

    Increase your market presence and generate qualified leads through in-depth market analysis, efficient process and innovation management, and targeted show marketing.


    Funding Opportunities

    Take advantage of government support programs such as INQA coaching to advance your corporate strategies with financial assistance.


    Digital excellence

    Comprehensive service management and professional IT security consulting enable you to optimize your business processes and protect your systems effectively.

    Contact Now

    If you have any questions, please do not hesitate to contact us at +49 431 90881145 or by e-mail at store@railmarketresearch.com.

    Featured Research Projects

    We want to connect researchers and interested parties from industry and business and promote the exchange of research results.


    If you are currently working on an exciting research project and would like to present it to a wider audience, please send us an e-mail.

    Reach out now

    Events in October

    October

    4 – 7

    APTA TRANSform Conference & Expo

    Chicago, USA

    October

    15

    TransCityRail South

    London, UK

    October

    20–22

    Persontrafik

    Stockholm, Sweden

    Inside RailMarketResearch

    Receive the latest news on the following topics:


    | Trends, news and expert contributions,

    | upcoming events,

    | studies

    Subscribe now!

    If you have any questions, please do not hesitate to contact us at +49 431 90881145 or by e-mail at store@railmarketresearch.com.

    A service of ASTRAN Business Consulting GmbH

    Am Kiel-Kanal 1 | DE-24106 Kiel | Tel: +49 431 90881145
    Web: railmarketresearch.com | Register: District Court Kiel HRB 14316 KI
    Privat-policy: railmarketresearch.com/privacy-policy/

    If you wish to unsubscribe from this newsletter, please send an email to
    store@railmarketresearch.com.

    © 2026 RailMarketResearch

    Our Partner
    Back to top of page