Back to overview

Cogwheel railway to the Pilatus

Assessment of ICT security

The redesign of the Pilatus cogwheel railway as part of the 2015+ strategy meant replacing the existing rolling stock and adapting the infrastructure, signalling systems and operating concept.

With the specifically developed dispatcher assistance system (incl. collision warning), speed monitoring and control of the movable track elements, new electromechanical systems as well as operation-critical ICT systems were introduced.

Compared to the previous situation, there was the possibility of attacks on the newly introduced OT systems (operational technology) and the data processed by them. The focus of the security assessment was on the possibility that the operation of the railway could be disrupted by manipulation of these systems and, in extreme cases, an accident could be caused.

To take account of this new threat, Emch+Berger AG Bern carried out a comprehensive assessment of ICT security in accordance with CLC/TS 50701. The centralised and decentralised components of the visualisation and command system for railways and position-based signalling systems (including the vehicle equipment) were subjected to a detailed risk assessment with subsequent risk evaluation of the threat scenarios. Special attention was also paid to the data networks and the radio and WiFi connections to the vehicles.

Place
Alpnachstad - Pilatus Kulm
Client
Pilatus-Bahnen AG
Period
2023
Fields of activity
Infrastructure;Rail infrastructure;Mobility and traffic;Rail systems;Rail vehicles
Delivered services
Assessment of ICT security according to CLC/TS 50701
Definition of the overall system to be analysed
Breakdown of the overall system into zones and conduits
Hazard analysis and interface analysis
Identification of threat scenarios
Risk assessment of the threat scenarios
Recommendations for assuring cyber security during operation