Public Transport Service

RailGuard Sentinel

RailGuard Sentinel protects locomotives, multiple units, and trams by providing 24/7, real-time threat monitoring during operation and stabling.

01 - Solution

Protection that keeps trains moving

RailGuard Sentinel is an on-board cybersecurity system that monitors vehicle network traffic. It identifies threats and vulnerabilities without disrupting critical operations. The system is designed to support compliance with applicable regulations and industry standards and was developed with Krakow University of Technology.

On-board system protection

Continuous cybersecurity monitoring of the vehicle network, including safety-critical TCMS and the on-board side of ERTMS / GSM-R / FRMCS.

Detection across the whole vehicle

Threat detection, unauthorised access detection, and advanced anomaly analysis - both in traffic inside the vehicle and in vehicle-to-ground communication.

Hybrid threat analytics

On-board deterministic algorithms provide real-time detection, while centrally hosted AI models deliver deeper analysis and correlation.

02 - Why now

Requirements you must implement

Applicable legal requirements, such as the Act on the National Cybersecurity System and the Cyber Resilience Act, complement technical standards for industrial automation cybersecurity: IEC 62443 (processes, risk, requirements) and IEC 63452 (railway-sector specifics).

01 / 04

Cyber Resilience Act (CRA)

EU regulation

This EU regulation introduces cybersecurity requirements for hardware and software products containing digital elements throughout their entire lifecycle. The Act obligates rolling stock solution manufacturers and suppliers to manage vulnerabilities, continuously identify security flaws (CVEs), and deliver regular updates. In practice, this means that every on-board system approved for operation must feature integrity control mechanisms, preventing the execution of unauthorized code or modified firmware.

02 / 04

Act on the National Cybersecurity System (NIS2)

Act · in force since 3 April 2026

The Act on the National Cybersecurity System divides organizations into essential and important entities. Railway operators are directly designated in the annex to the act as essential entities, requiring them to meet a comprehensive set of cybersecurity obligations. The Act requires operators to, among other things, conduct continuous, round-the-clock system monitoring, manage vulnerabilities, and promptly identify and report incidents. In practice, this creates a need to oversee both IT and OT environments, meaning implementing traffic monitoring, anomaly detection, and the identification of unauthorized communication attempts within vehicles.

03 / 04

IEC 63452

Technical standard · rolling stock

The IEC 63452 standard defines specific cybersecurity requirements for rolling stock control systems and components. The standard focuses on the specifics of on-board networks, where the segregation of safety-critical control systems such as TCMS and signalling and communication systems (ERTMS / GSM-R / FRMCS) from passenger information systems is of paramount importance. Meeting the standard's requirements involves implementing advanced, continuous data transmission surveillance mechanisms capable of detecting anomalies in railway protocols while remaining fully passive and without affecting vehicle operational safety.

04 / 04

IEC 62443

Technical standard · industrial automation

The IEC 62443 standard serves as the global foundation for industrial automation and control systems (IACS) security and directly targets component manufacturers, system integrators, and automation system owners, including railway operators and urban transit authorities. It defines secure software development lifecycle procedures, technical requirements for systems across various security levels, and comprehensively regulates risk management, vulnerability management, and continuous asset security monitoring.

03 - How it works

Nine things RGS never stops doing

01

Always-on OT and IT monitoring

TAP points and port mirroring keep safety-critical systems (TCMS, ERTMS, GSM-R, FRMCS) under watch without the risk of blocking vehicle traffic.

02

AI as a quiet analyst

Mistral and Llama language models correlate scattered alerts into actionable incidents and help reduce false positives.

03

Adaptive anomaly detection

Algorithms flag sudden shifts in traffic patterns and communication attempts that on-board devices should never be making.

04

Vulnerability scoring in CVSS 3.0

RGS finds vulnerabilities in rolling stock software as they are disclosed and scores them against CVSS 3.0, supporting compliance with the requirements of the Cyber Resilience Act (CRA).

05

MAC address monitoring

Rogue devices are spotted the moment they connect, with diagnostic data from the attempt recorded for later analysis.

06

Connection map of the vehicle

RGS visualises traffic flows, data volumes, ports in use, and communication protocols across the vehicle network.

07

Asset inventory and integrity

The system continuously verifies the integrity and authenticity of operating systems and applications.

08

Live software auditing

Operators are notified immediately when a component is modified, or when a certificate or digital signature expires or is revoked.

09

Control of outbound transfers

Every exchange of data with the outside world is logged, including the critical transfer of configuration files and firmware updates.

3D previews unavailable - device descriptions below
Vehicle

A multiple unit in service

3D previews unavailable - module description below
05 - Control centre

The RGS-CSIRT server room

RGS-SCG sends an encrypted stream to the control centre. Alerts from across the fleet arrive in one place, and language models assemble scattered events into incidents a team can actually work with.

Oversight
24/7
Impact on train operation
0
06 - Services

How we help secure rolling stock

PTS supports organisations in the rail transport sector in building cybersecurity for rolling stock. RailGuard Sentinel is one of four services; the other three help you reach compliance with the rules and standards set out above.

01 / 04

RailGuard Sentinel powered by AI

  • On-board system monitoring in the scope required by NIS2, the CRA and IEC 63452.
  • Identification of threats, vulnerabilities and unwanted activity.
02 / 04

IEC 63452 compliance audit

  • Compliance audit of on-board systems against IEC 63452 and IEC 62443.
  • CSMS (Cyber Security Management System) rollout for the ECM.
03 / 04

Cyber Resilience Act compliance

  • Rollout of a CRA compliance process.
  • Development and delivery of the documentation required by the CRA for on-board systems and components.
04 / 04

NIS2 compliance audit

  • Compliance audit against NIS2 as transposed into national law.
  • Support in putting the required technical and organisational measures in place.
07 - R&D partnership

Together with Krakow University of Technology

01 / 02

Research and development behind RGS

PTS runs a joint research and development project on the RailGuard Sentinel system with the Faculty of Electrical and Computer Engineering at Krakow University of Technology. Academic expertise in automation security, set alongside the commercial experience PTS has on the railway market, produced an advanced solution built for rolling stock infrastructure.

02 / 02

Training specialists for the cybersecurity sector

As technology partner of the postgraduate course “Cybersecurity of Rail Transport Infrastructure” at Krakow University of Technology, PTS takes an active part in building the qualified workforce this market needs. The joint teaching programme gives students practical skills in protecting rail transport systems, matched to what the industry needs today.

Programme and admissions at WIEiK PK (in Polish)
08 - Contact

Let's talk about protecting your fleet

Do you have questions about RailGuard Sentinel or about the cybersecurity requirements that apply to rolling stock? Get in touch with our experts.