Summary of findings within the within the socio-technical framework
| Socio-technical systems | Summary of findings | Socio-technical theory | Potential mitigation strategies |
|---|---|---|---|
| People | Malicious attacks |
| Further HF evaluation, re-design and training opportunities |
| Human error |
| ||
| Non-malicious |
| ||
| Organisational factors/culture | Lack of awareness |
| HF input to organisational strategies around cyber-security, including job design, training and awareness |
| Lack of “buy-in” from senior management |
| ||
| Technology | New technology-related risks |
| HF input to re-design; training opportunities |
| Infrastructure | Infrastructure risks (e.g. physical access threat) |
| HF input to re-design; training opportunities |
| Goals | Railway operators (e.g. signallers) goal-related risks |
| Training and job design opportunities |
| Training | Problems distinguishing between a system fault and a genuine cyber-attack not being prepared for an attack |
| Further HF evaluation and training opportunities |
| Socio-technical systems | Summary of findings | Socio-technical theory | Potential mitigation strategies |
|---|---|---|---|
| People | Malicious attacks | Unknown threat actors, often without a clear plan or goal and poor traceability of an attacker, make rail transport a relatively easy target for cyber-attacks Malicious attackers (e.g. nation state, terrorist and even organised crime) with very clear plans/goals can cause economic disruption or serious harm Social engineering techniques, such as concealing a cyber-attack as a fault in the system, can be an issue combined with HF issues such as workload and distraction (e.g. a particularly busy day can lead to not noticing changes in the system) | Further HF evaluation, re-design and training opportunities |
| Human error | HF-related issues can include human error (e.g. accidentally sharing information) Heavy cognitive load, stress and workload can cause human error (e.g. mistakes and slips) | ||
| Non-malicious | Non-malicious risks (e.g. not recognising a fault in the system or becoming an accidental insider/non-malicious threat actor [e.g. through unintentionally tampering with the system]) due to a number of factors, including training Cyber-security-related risks can originate from other parties, e.g. maintainers or third-party suppliers during maintenance activities on the railways | ||
| Organisational factors/culture | Lack of awareness | Organisational factors can increase cyber-related risks to the railways due to a lack of security culture and awareness (i.e. lack of systematic review of maintenance activities, training or monitoring) | HF input to organisational strategies around cyber-security, including job design, training and awareness |
| Lack of “buy-in” from senior management | Management may not provide sufficient consideration for cyber-security, which may lead to a “relaxed security culture” The key role of senior management to mitigate against cyber-security risks may not be fulfilled, so mitigation strategies are not fully explored. These may include, e.g. development of safety requirements around security, fit-for-purpose design, goal/task-oriented system design, etc | ||
| Technology | New technology-related risks | Implementation of new technologies such as ERTMS and increased connectivity bring new opportunities for attackers and cyber-criminals as both driver assistance and control systems present new attack surfaces Computerised rail systems are also at risk from human error, such as failures to update and configure software correctly. This includes actions as innocuous as attaching unauthorised devices to networks (e.g. by the maintainers) Risks around integration of new systems with legacy systems Re-design limitations of the legacy systems | HF input to re-design; training opportunities |
| Infrastructure | Infrastructure risks (e.g. physical access threat) | Physical access is another threat to safety-critical systems, such as railway systems. Modern technologies in rail transport being relatively unprotected can cause this risk Rail systems may also expose or introduce, vulnerabilities allowing third parties to obtain remote access to systems (maintenance-related risks) | HF input to re-design; training opportunities |
| Goals | Railway operators (e.g. signallers) goal-related risks | Day to day pressures to complete the jobs on time may lead not noticing cyber-security-related risks (both signallers and maintainers) | Training and job design opportunities |
| Training | Problems distinguishing between a system fault and a genuine cyber-attack not being prepared for an attack | Cyber-attacks or social-engineering-related manipulation can mimic system faults Signallers are often not able to distinguish whether an issue within the system is due to a cyber-attack or fault in the system Signallers are not prepared for a cyber-attack as they are not “expecting one” As the signallers are not able to distinguish whether an issue within the system is due to a cyber-attack or fault in the system, they are also not specifically trained for the aftermath of a cyber-attack The role of the signaller following an attack on the infrastructure often has direct or indirect consequences on their day-to-day activities If digital systems fail, signallers have to take control “manually”; however, the individual steps for mitigation are not clear | Further HF evaluation and training opportunities |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.