Cylus.ai

10x your rail OT security team.

Agentic AI for rail OT security. Cylus.ai gives every rail security team an AI agent that knows rail systems, reads your security tools, and shows its work.

Book a demo
1 agent running
Running
Running
Running
Running
Running
Running
Running
Running
Running
Running
Virtual SOC Analyst

→ Investigates alerts from your SIEM and rail network monitoring across onboard, wayside and station networks. Pulls asset context, protocol baselines and maintenance schedules before it judges.

→ Writes up a verdict with the evidence attached, including correlated EDR detections and firewall sessions.

→ Drafts the ticket in your ITSM for your approval.

Thinking…
HighAlert 1003: anomalous command sequence from HMI-CTRL-03 to the wayside interlocking at Junction 12
Unusual interlocking command pattern: point machine commanded to move while the route was still locked, on a safety-critical signaling asset.
Correlated signal: EDR high-severity detection on HMI-CTRL-03 for unexpected RDP lateral movement.
Virtual GRC

→ Maps IEC 62443, TSA SD-1580/1582 and NIS2 controls to your actual environment.

→ Flags gaps and drafts remediation items with owners.

→ Collects evidence from your systems as you work, so audit prep is a review instead of a project.

Thinking…
Draft IEC 62443-3-3 assessment: 109 requirements mapped to your environment
Evidence found for asset inventory, network monitoring and zone segmentation (FR 5, restricted data flow).
Gaps flagged for identification and authentication policy (FR 1) and audit logging (FR 6). Remediation items drafted with owners for your review.
Virtual Security Architect

→ Reviews CBTC, PTC and ERTMS designs, onboard and trackside, against IEC 62443-3-2 zones and conduits.

→ Audits firewall rulesets and flags paths that bypass inspection between IT and signaling zones.

→ Simulates the impact of a proposed change and runs vendor security assessments during procurement.

Thinking…
3 paths bypass the inspection boundary between IT and the signaling zone, plus 1 segmentation model gap
Highest priority: firewall policy 12 legacy-rdp-access allows IT-VLAN to OT-Control over RDP, from IT workstations to OT HMIs.
Also flagged: a broad allow rule and an over-broad vendor remote-access path.
Safe and Secure First

→ The agent proposes; a person approves. Every critical action, like a write to a ticket, rule or config, goes through explicit approval.

→ Reasoning, data sources and tool calls are visible for every answer. Every action is recorded in the audit log.

→ Customer data is never used to train models. Encrypted in transit and at rest. SSO, RBAC and least privilege. Control alignment with NIST AI RMF, ISO/IEC 42001 and SOC 2.

Thinking…
Two changes to production systems. Nothing runs until you approve.
1. Disable firewall policy 12 legacy-rdp-access (IT-VLAN to OT-Control). Impact: two maintenance workstations lose RDP to the signaling HMIs.
2. Network-contain HMI-CTRL-03 through the EDR until patched. Impact: the HMI is unreachable for maintenance staff until you release it.
Approve bothReject✓ Approved by you · executed and logged to the audit trail

An overlay on the tools you already run.

Connect Cylus.ai to the security tools you already run. Agents read from them, reason over rail domain knowledge and your own context, and return answers, reports and draft actions. Critical actions run only after a human approves them.

Your teamAsks a question or
triggers a workflow
Query
Output
Cylus.ai
Rail OT Domain Knowledge
Reasoning Engine
Persistent Memory
Agentic Workflows
Iterates
Queries
Your tools
Retrieves
Knowledge baseRail standards, frameworks and regulations,
your own documents and topology
Book a demo

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert