Table 3.

Summary of findings within the within the socio-technical framework

Socio-technical systemsSummary of findingsSocio-technical theoryPotential mitigation strategies
PeopleMalicious attacks
  • Unknown threat actors, often without a clear plan or goal and poor traceability of an attacker, make rail transport a relatively easy target for cyber-attacks

  • Malicious attackers (e.g. nation state, terrorist and even organised crime) with very clear plans/goals can cause economic disruption or serious harm

  • Social engineering techniques, such as concealing a cyber-attack as a fault in the system, can be an issue combined with HF issues such as workload and distraction (e.g. a particularly busy day can lead to not noticing changes in the system)

Further HF evaluation, re-design and training opportunities
Human error
  • HF-related issues can include human error (e.g. accidentally sharing information)

  • Heavy cognitive load, stress and workload can cause human error (e.g. mistakes and slips)

Non-malicious
  • Non-malicious risks (e.g. not recognising a fault in the system or becoming an accidental insider/non-malicious threat actor [e.g. through unintentionally tampering with the system]) due to a number of factors, including training

  • Cyber-security-related risks can originate from other parties, e.g. maintainers or third-party suppliers during maintenance activities on the railways

Organisational factors/cultureLack of awareness
  • Organisational factors can increase cyber-related risks to the railways due to a lack of security culture and awareness (i.e. lack of systematic review of maintenance activities, training or monitoring)

HF input to organisational strategies around cyber-security, including job design, training and awareness
Lack of “buy-in” from senior management
  • Management may not provide sufficient consideration for cyber-security, which may lead to a “relaxed security culture”

  • The key role of senior management to mitigate against cyber-security risks may not be fulfilled, so mitigation strategies are not fully explored. These may include, e.g. development of safety requirements around security, fit-for-purpose design, goal/task-oriented system design, etc

TechnologyNew technology-related risks
  • Implementation of new technologies such as ERTMS and increased connectivity bring new opportunities for attackers and cyber-criminals as both driver assistance and control systems present new attack surfaces

  • Computerised rail systems are also at risk from human error, such as failures to update and configure software correctly. This includes actions as innocuous as attaching unauthorised devices to networks (e.g. by the maintainers)

  • Risks around integration of new systems with legacy systems

  • Re-design limitations of the legacy systems

HF input to re-design; training opportunities
InfrastructureInfrastructure risks (e.g. physical access threat)
  • Physical access is another threat to safety-critical systems, such as railway systems. Modern technologies in rail transport being relatively unprotected can cause this risk

  • Rail systems may also expose or introduce, vulnerabilities allowing third parties to obtain remote access to systems (maintenance-related risks)

HF input to re-design; training opportunities
GoalsRailway operators (e.g. signallers) goal-related risks
  • Day to day pressures to complete the jobs on time may lead not noticing cyber-security-related risks (both signallers and maintainers)

Training and job design opportunities
TrainingProblems distinguishing between a system fault and a genuine cyber-attack not being prepared for an attack
  • Cyber-attacks or social-engineering-related manipulation can mimic system faults

  • Signallers are often not able to distinguish whether an issue within the system is due to a cyber-attack or fault in the system

  • Signallers are not prepared for a cyber-attack as they are not “expecting one”

  • As the signallers are not able to distinguish whether an issue within the system is due to a cyber-attack or fault in the system, they are also not specifically trained for the aftermath of a cyber-attack

  • The role of the signaller following an attack on the infrastructure often has direct or indirect consequences on their day-to-day activities

  • If digital systems fail, signallers have to take control “manually”; however, the individual steps for mitigation are not clear

Further HF evaluation and training opportunities
Source: Created by authors

or Create an Account

Close subscription notice
Close access options