As cyber threats increased in 2022, we saw that standards and regulations expanded to help bridge the gap between safety and security and set cybersecurity requirements for both new and existing rail systems. As more and more projects are driven by regulation, rail companies must comply, patch potential vulnerabilities, and gain complete visibility of their assets. In most cases, the number of assets to monitor and protect is massive, and railway systems face challenges.
Here is how Cylus and Thales collaborated to address these challenges and deployed a cybersecurity solution for one of Europe's most prominent rail companies to protect its signaling system.
At Rail Live 2022, Cylus had the opportunity to present a joint case study with Thales. Amir Levintal, CEO and Co-Founder at Cylus, and Agustín Solís Pila, Head of Business Development of Cybersecurity at Thales, offered a view into the collaborative project the companies are partnering on deploying cybersecurity capabilities for one of Europe's most prominent rail companies to protect its signaling system. The joint presentation was titled: “Cylus and Thales - Bridging the Gap Between Cybersecurity and Rail Operations.”

In their presentation, Amir and Agustín addressed the history of this project, which started a few years ago with an assessment of the risks in the customer’s signaling environment, to a validation of the cybersecurity solution in Thales’ lab in Madrid, and finally to the trial conducted on the customer’s selected signaling infrastructure. The trial was conducted to demonstrate protection in a live operational installed base of rail-specific systems.
The two key drivers for this successful joint project were:
- Demonstrating compliance with the customer’s cybersecurity requirements, including NIS directives
- Providing real-time network and asset visibility across a widely distributed rail infrastructure network with thousands of assets and many rail-specific protocols. The project was conducted in a multi-vendor rail network covering the rail signaling network and the operational technology (OT) networks supporting the CCTV and VoIP infrastructure.
The design layout of the project is shown in the image below, which included using non-intrusive virtual network probes to monitor the network continuously for three months for cybersecurity anomalies, including external threat intelligence from Cylus research labs and integration into the customer’s SIEM solution.

The project success criteria for the customer in this project included the following:
- Real-time asset visibility.
- Visibility of unknown assets.
- The creation of network security zones according to TS-50701.
- Automated virtual segmentation and policy creation.
- Demonstrated regulatory compliance.
- Demonstrated real-time security threat detection in a live rail-specific network.
To wrap up their presentation, Amir and Agustín presented the joint project outcomes from the deployed cybersecurity product trail with one of Europe's most prominent rail companies in its signaling system. The results included:
- Successfully demonstrating the simple deployment of a non-intrusive cybersecurity solution in a live, legacy rail network.
- Protecting both the rail safety-critical infrastructure and other OT systems.
- Providing network and asset visibility with deep rail context and intelligence for the identified systems.
- Demonstrating cybersecurity use cases that helped bridge the customer’s security and operations teams.
Become a Cylus Partner and help lead the way to a cyber-secure future of rail.



