On-board system protection
Continuous cybersecurity monitoring of the vehicle network, including safety-critical TCMS and the on-board side of ERTMS / GSM-R / FRMCS.
RailGuard Sentinel protects locomotives, multiple units, and trams by providing 24/7, real-time threat monitoring during operation and stabling.
RailGuard Sentinel is an on-board cybersecurity system that monitors vehicle network traffic. It identifies threats and vulnerabilities without disrupting critical operations. The system is designed to support compliance with applicable regulations and industry standards and was developed with Krakow University of Technology.
Continuous cybersecurity monitoring of the vehicle network, including safety-critical TCMS and the on-board side of ERTMS / GSM-R / FRMCS.
Threat detection, unauthorised access detection, and advanced anomaly analysis - both in traffic inside the vehicle and in vehicle-to-ground communication.
On-board deterministic algorithms provide real-time detection, while centrally hosted AI models deliver deeper analysis and correlation.
Applicable legal requirements, such as the Act on the National Cybersecurity System and the Cyber Resilience Act, complement technical standards for industrial automation cybersecurity: IEC 62443 (processes, risk, requirements) and IEC 63452 (railway-sector specifics).
This EU regulation introduces cybersecurity requirements for hardware and software products containing digital elements throughout their entire lifecycle. The Act obligates rolling stock solution manufacturers and suppliers to manage vulnerabilities, continuously identify security flaws (CVEs), and deliver regular updates. In practice, this means that every on-board system approved for operation must feature integrity control mechanisms, preventing the execution of unauthorized code or modified firmware.
The Act on the National Cybersecurity System divides organizations into essential and important entities. Railway operators are directly designated in the annex to the act as essential entities, requiring them to meet a comprehensive set of cybersecurity obligations. The Act requires operators to, among other things, conduct continuous, round-the-clock system monitoring, manage vulnerabilities, and promptly identify and report incidents. In practice, this creates a need to oversee both IT and OT environments, meaning implementing traffic monitoring, anomaly detection, and the identification of unauthorized communication attempts within vehicles.
The IEC 63452 standard defines specific cybersecurity requirements for rolling stock control systems and components. The standard focuses on the specifics of on-board networks, where the segregation of safety-critical control systems such as TCMS and signalling and communication systems (ERTMS / GSM-R / FRMCS) from passenger information systems is of paramount importance. Meeting the standard's requirements involves implementing advanced, continuous data transmission surveillance mechanisms capable of detecting anomalies in railway protocols while remaining fully passive and without affecting vehicle operational safety.
The IEC 62443 standard serves as the global foundation for industrial automation and control systems (IACS) security and directly targets component manufacturers, system integrators, and automation system owners, including railway operators and urban transit authorities. It defines secure software development lifecycle procedures, technical requirements for systems across various security levels, and comprehensively regulates risk management, vulnerability management, and continuous asset security monitoring.
TAP points and port mirroring keep safety-critical systems (TCMS, ERTMS, GSM-R, FRMCS) under watch without the risk of blocking vehicle traffic.
Mistral and Llama language models correlate scattered alerts into actionable incidents and help reduce false positives.
Algorithms flag sudden shifts in traffic patterns and communication attempts that on-board devices should never be making.
RGS finds vulnerabilities in rolling stock software as they are disclosed and scores them against CVSS 3.0, supporting compliance with the requirements of the Cyber Resilience Act (CRA).
Rogue devices are spotted the moment they connect, with diagnostic data from the attempt recorded for later analysis.
RGS visualises traffic flows, data volumes, ports in use, and communication protocols across the vehicle network.
The system continuously verifies the integrity and authenticity of operating systems and applications.
Operators are notified immediately when a component is modified, or when a certificate or digital signature expires or is revoked.
Every exchange of data with the outside world is logged, including the critical transfer of configuration files and firmware updates.
RGS-SCG sends an encrypted stream to the control centre. Alerts from across the fleet arrive in one place, and language models assemble scattered events into incidents a team can actually work with.
PTS supports organisations in the rail transport sector in building cybersecurity for rolling stock. RailGuard Sentinel is one of four services; the other three help you reach compliance with the rules and standards set out above.
PTS runs a joint research and development project on the RailGuard Sentinel system with the Faculty of Electrical and Computer Engineering at Krakow University of Technology. Academic expertise in automation security, set alongside the commercial experience PTS has on the railway market, produced an advanced solution built for rolling stock infrastructure.
As technology partner of the postgraduate course “Cybersecurity of Rail Transport Infrastructure” at Krakow University of Technology, PTS takes an active part in building the qualified workforce this market needs. The joint teaching programme gives students practical skills in protecting rail transport systems, matched to what the industry needs today.
Programme and admissions at WIEiK PK (in Polish)Do you have questions about RailGuard Sentinel or about the cybersecurity requirements that apply to rolling stock? Get in touch with our experts.