Rail SCADA
Rail SCADA refers to the supervisory control and data acquisition systems that operate a railway's non-signaling infrastructure: traction power substations and catenary sectioning, tunnel ventilation, pumps, lighting, escalators and station systems. Operators in a control center monitor and command remote equipment through a network of controllers and remote terminal units.
How it works
Field equipment such as circuit breakers, transformers, fans and pumps is connected to programmable logic controllers or remote terminal units at each site. These report measurements and alarms to a central SCADA server and receive commands from it, using industrial protocols such as IEC 60870-5-104, DNP3, Modbus or IEC 61850. Operators see the state of the whole network on human-machine interface screens and can, for example, isolate a section of overhead line for maintenance or start emergency ventilation in a tunnel.
Rail SCADA systems typically span hundreds of sites over a wide area and have long lifecycles. Many were originally deployed on serial links and have since been migrated onto IP networks, often sharing telecom infrastructure with signaling and corporate traffic.
Why it matters for security
Traction power and tunnel systems are safety-relevant even though they are not part of the signaling safety case. Cutting power to a line, opening breakers under load or disabling ventilation can strand trains and endanger passengers. The industrial protocols involved were designed without authentication, so anyone with network access can often issue valid-looking commands.
Because SCADA equipment tends to be more standard than signaling equipment, it is also where generic industrial malware and known vulnerabilities are most likely to apply. Asset visibility and protocol-aware monitoring across the SCADA estate are therefore core parts of rail OT security programs and are explicitly covered by regulations such as NIS2 and the TSA directives.
Related solution
Operating rail infrastructure at network scale
Signaling, power, communications and control centers protected across network-wide environments.
See the solution →

