When patching is not an option: NIS2 compliance in rail

In most IT environments, a critical vulnerability triggers a familiar response: patch the system, update the software and restore normal operations. In rail, that is often not possible. Many of the systems NIS2 aims to protect cannot simply be patched, updated or taken offline. And while the directive asks every essential organisation to manage cyber risks, report incidents quickly and strengthen accountability at board level, meeting those requirements in a railway is far more complex than on paper. That is where compliance stops being a checklist and becomes an operational challenge.

Protecting what you cannot change

Railways rely heavily on operational technology such as signalling, interlockings and control systems. Much of this infrastructure was designed to remain operational for decades. Its long lifecycle, legacy technology and dependence on specialist knowledge can make upgrades complex, costly and operationally risky.1

That makes cybersecurity very different from a typical IT environment. Where IT teams respond to vulnerabilities with patches and updates, rail operators often cannot. Limited maintenance windows and strict safety requirements mean the most critical systems are also the hardest to change.

Security can never override safety

There is a second constraint that outsiders often miss. Over decades, railways have built a rigorous safety discipline, formalised in a framework known as RAMS, short for reliability, availability, maintainability and safety. Before a safety-critical system such as signalling is allowed into service, it has to be certified against that framework: proven, in effect, that it will not endanger passengers or staff.

That is exactly what makes cybersecurity more complex. Even a seemingly minor change may require additional validation, testing or recertification before the system can safely return to service. Across the rail industry, the principle is clear: security measures must never compromise functional safety.

Building resilience beyond patching

If you cannot always fix the vulnerable system itself, you have to reduce the risk around it. That is what NIS2 looks like in practice for rail operators and it goes well beyond traditional patch management:

  • Network segmentation, preventing a breach in IT from spreading to the OT systems that keep trains running.
  • Continuous monitoring, detecting suspicious activity in systems that cannot always be updated.
  • Compensating controls and virtual patching, adding protection when the system itself cannot be modified.
  • A complete asset inventory, because you cannot protect what you do not know you have.

These measures may not stand out on a compliance checklist, but they are essential for keeping critical infrastructure secure and operational. Supplier management is just as important. As rail operators rely heavily on suppliers for patching and lifecycle management, meaning their risks can quickly become yours.

Read NIS2 as an operating model, not an audit

Treating NIS2 as a paperwork exercise may help you pass an audit, but it does little to improve resilience. In railway organisations, compliance is about much more than documentation. It means protecting systems that cannot always be patched, balancing safety and security and keeping critical operations running under all circumstances.

The potential fines, up to €10 million or 2% of global annual turnover, make NIS2 impossible to ignore. But for railways, the challenge goes beyond compliance. Many critical systems cannot simply be patched, so protecting them requires segmentation, continuous monitoring, strong governance and close supplier management. NIS2 therefore becomes more than a compliance project. It becomes part of how a resilient railway operates.

That is where Atos can help. We help railway organisations translate NIS2 requirements into practical security measures that strengthen resilience without compromising operations. Discover how Atos helps railway organisations strengthen cyber resilience across IT and OT.

Discover more

Why an SOC is essential for modern railways

Why an SOC is essential for modern railways

A railway depends on continuous operations, which means it also depends on continuous security. That is the role of the Security Operations Centre (SOC): monitoring threats around the clock, detecting suspicious activity and responding before incidents can disrupt operations. As rail networks become more connected and threats more complex, the SOC has become one of the most important parts of a railway’s cyber resilience. It is also where AI can make the biggest difference.

Read more
Why the IT-OT boundary is a critical security risk for railways

Why the IT-OT boundary is a critical security risk for railways

Many railway organisations depend on ageing systems that are difficult to replace. They are expensive to maintain, difficult to secure and increasingly hard to integrate with modern technology. Modernising them is not simply a technical challenge. Changes must be introduced without disrupting critical operations. The real challenge isn’t deciding whether to modernise gradually, but how to manage each stage: how much to move at once, what to monitor afterwards and when to pause or roll back.

Read more
Why workplace services are part of railway operations

Why workplace services are part of railway operations

Workplace services are often treated as a back-office IT function, measured through tickets, response times and satisfaction scores. In a railway environment, that view misses something important. When a train is delayed, a passenger information system fails or an operational application becomes unavailable, the people resolving the issue rely on those same laptops, applications and support services. The faster they can access the right tools, the faster they can respond.

Read more
How to modernise rail infrastructure without stopping the trains

How to modernise rail infrastructure without stopping the trains

Many railway organisations depend on ageing systems that are difficult to replace. They are expensive to maintain, difficult to secure and increasingly hard to integrate with modern technology. Modernising them is not simply a technical challenge. Changes must be introduced without disrupting critical operations. The real challenge isn’t deciding whether to modernise gradually, but how to manage each stage: how much to move at once, what to monitor afterwards and when to pause or roll back.

Read more