{"id":2424,"date":"2024-01-26T15:13:00","date_gmt":"2024-01-26T15:13:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/saudi-arabia-boosts-railway-cybersecurity-partnership"},"modified":"2024-01-26T15:13:00","modified_gmt":"2024-01-26T15:13:00","slug":"saudi-arabia-boosts-railway-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/26\/saudi-arabia-boosts-railway-cybersecurity\/","title":{"rendered":"Saudi Arabia Boosts Railway Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5c3d4e7c53f0b0fd\/65b3b5d8ba1594040a06dc73\/hejaz_railway_celcinar_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Saudi Railway Company (SAR) has announced a partnership with &#8220;sirar by stc&#8221; to bolster the cybersecurity of its critical transit network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The agreement comes against a backdrop of heightened concerns about the cybersecurity of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/rail-cybersecurity-is-a-complex-environment\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">rail transport networks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in general, part of the country\u2019s critical national infrastructure and the target of not-infrequent attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rail networks rely on a combination of IT and operational technology (OT) components that rely on multiple suppliers and diverse technologies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.stc.com.sa\/content\/stcgroupwebsite\/sa\/en\/media-center\/press-release\/press-release-detail.html?id=strategic-collaboration-between-sirar-by-stc-sar\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, sirar by stc said, &#8220;[We], specializing in comprehensive cybersecurity services, will provide advanced solutions to safeguard SAR&#8217;s extensive railway network, contributing to the safety and security assurance of travel and cargo transport across the Kingdom.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sirar by stc did not immediately respond to Dark Reading&#8217;s request for comment on priorities for its work with SAR, or whether or not it will use internationally-recognized cybersecurity assurance standards as a guide.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">SAR is responsible for managing 4,500 kilometers of railway networks in Saudi Arabia. Its ambitious &#8220;Land Bridge&#8221; project aims to connect Saudi ports from the Arabian Gulf to the Red Sea as part of a strategy to make the country a transport and logistics hub for the region, promoting sustainable development while reducing greenhouse gas emissions.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Departure Board<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Railways face the challenge of aligning legacy tech with the latest innovations: introducing <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/transportation-industry-s-7-most-wanted-security-skills\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">IoT signaling<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and communications technology increases operational efficiency. But operational benefits from modern technologies comes with the downside of increasing the attack surface of networks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, many systems, such as those for switching tracks and tracking train locations \u2014 often broadcast wirelessly <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/waterfall-security.com\/ot-insights-center\/ot-cybersecurity-insights-center\/cybersecurity-for-rail-systems-harder-than-it-sounds-episode-113\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">without encryption<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Chris Grove, expert in critical infrastructure cybersecurity at Nozomi Networks, tells Dark Reading: &#8220;Railway networks face a complex and multifaceted attack surface. This includes numerous small components controlling heavy industrial equipment in motion, often spread over vast distances. Other vulnerable areas include trackside infrastructure, train stations, kiosks, digital signage, phone apps, web servers, HVAC [heating and ventilation] systems, and power generation\/control facilities.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Travel Chaos<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Recorded breaches have targeted digital signage, ticketing systems, monitoring systems, and other components in stations, leading to widespread service interruptions and data leaks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Notable incidents include the attack on San Francisco-area transport provider <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.theguardian.com\/technology\/2011\/aug\/15\/anonymous-hackers-breach-bart-website\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">BART by hacktivist group Anonymous<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in 2011, while in May 2017, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.railtech.com\/digitalisation\/2017\/12\/11\/wannacry-virus-was-wake-up-call-for-railway-industry\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Deutsche Bahn<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in Germany was hit by the WannaCry malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also in March 2022, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.railjournal.com\/infrastructure\/italian-railway-it-system-suffers-major-cyber-attack\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Italy&#8217;s rail network was hit by a ransomware attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that impacted ticket sales, leaked passenger information, and disrupted rail communications.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In August 2023, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.bbc.co.uk\/news\/world-europe-66630260\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">hackers disrupted the rail network traffic around Szczecin in Poland<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> after breaking into the railway frequencies used between drivers and signalers. The hackers caused some trains to apply emergency brakes, and they also played recordings of Russia&#8217;s national anthem and a speech by Russian President Vladimir Putin.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Aaron Walton, a threat intel analyst from managed detection and response company Expel, says: &#8220;When we talk about railway security, there&#8217;s often concern that the operational technology and Internet of Things (IoT) components of trains will be targeted, as failure of these systems can heavily endanger passengers and transportation. However, the actual cyberattacks we&#8217;ve seen primarily disrupt the information technology (IT) components of the organization.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Rolling Stock<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Steps to secure rail infrastructure start with the same fundamentals as bolstering the cybersecurity of enterprise networks \u2014 such as conducting a comprehensive risk assessment, building in resilience, and developing disaster recovery plans.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Shaked Kafzan, co-founder and CTO of security vendor Cervello, says a successful cybersecurity approach for railroads should focus on threat and risk prevention rather than detection, starting with having complete and in-depth visibility into every system and asset across all environments, including real-time risks \u2014 all within the rail context.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u201cThere is a critical difference between a solution that can identify common IT or OT assets, and one that can pinpoint assets or protocols that are relevant and specific to the rail environment, Kafzan says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/saudi-arabia-boosts-railway-cybersecurity-partnership\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Saudi Railway Company (SAR) has announced a partnership with<\/p>\n","protected":false},"author":12,"featured_media":2425,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2424","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=2560%2C1709&ssl=1",2560,1709,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=640%2C428&ssl=1",640,428,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=640%2C428&ssl=1",640,428,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=1536%2C1025&ssl=1",1536,1025,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=2048%2C1367&ssl=1",2048,1367,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=1024%2C684&ssl=1",1024,684,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/saudi-arabia-boosts-railway-cybersecurity-scaled.jpg?fit=2560%2C1709&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2424"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2424\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2425"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}