Blog Post

Cyber Loss in Rail and Signalling

October 3, 2026

Table of Contents

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately.

‍

Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one.

‍

What Does Fail-Safe Mean Here?

‍

The permissive state requires something to keep working, and its absence produces a stop.

‍

Proceed aspects need continuous electrical current, so a broken circuit, a lost supply or a failed relay drops the signal back to danger. Electromechanical designs used gravity and heavy springs to force contacts into the restrictive position, and the European standards family covering railway reliability, software and safety-related electronic systems formalizes how software-driven signalling achieves the same benchmark, with interlocking functions held at the highest safety integrity level.

‍

The Priority Is Stated Explicitly

‍

The design literature puts it plainly. A delayed or stopped train is an operational inconvenience, and a false permissive signal showing proceed on blocked track is a catastrophic hazard. The system is engineered to accept the first in order to eliminate the second.

‍

Which Makes the Safety Design the Attack Surface

‍

For the financial loss rather than the physical one, and this is the uncomfortable inversion.

‍

Outage duration exceedance curve showing the likelihood of an event exceeding a working day, twelve hours, twenty-four hours and forty-eight hours
Where the loss is a halt rather than a hazard, duration is the term the whole figure rests on.

An attacker does not need to defeat the safety system to cause the maximum available loss. Triggering it is the attack. Interfering with the circuits, the communications or the interlocking produces stops, and the more robust the fail-safe design the more reliably an interference converts into service disruption.

‍

Which Reverses the Usual Control Logic

‍

Elsewhere, hardening a safety system reduces the loss. Here it guarantees the loss takes the financial form, so protecting the operation means protecting availability rather than integrity, and those are different controls, which quantifying operational technology exposure has to account for per sector rather than generically.

‍

How Is a Halt Priced?

‍

An existing industry mechanism prices it, which almost no other operational sector has.

‍

In the United Kingdom, the infrastructure manager and the train operators operate a payment regime for disruption driven by attributed delay minutes against pre-agreed benchmarks. The infrastructure manager and the train operators compensate each other formulaically, with the infrastructure manager acting as a clearing house, and the regulator sets baseline rates for each control period.

‍

Which Gives the Severity Term a Published Number

‍

Most operational technology scenarios require estimating what an hour of disruption costs. Here the rate is regulated, the unit is the delay minute, and the arithmetic is delay minutes multiplied by a published figure. The severity input arrives from outside the model rather than being constructed inside it.

‍

Who Bears It?

‍

Whoever the attribution process assigns it to, which makes the scenario definition unusually consequential.

‍

Per-event impact summary showing median loss with the first and ninety-ninth percentile range, alongside equivalent ranges for duration and records affected
A duration range reported separately from the loss is what allows a published per-minute rate to be applied across the distribution.

An industry-wide delay attribution system assigns responsibility for each delay to a party, distinguishing infrastructure failure from fleet failure. So a compromise of signalling attributes differently from a compromise of an operator's own systems, and the rates between the parties are asymmetric.

‍

Which the Scenario Has to Specify

‍

A cyber scenario that says signalling disrupted without naming whose system was compromised cannot be priced, because the attribution decides who pays and at what rate. Naming the compromised party is therefore a modeling requirement rather than a detail, and how granular a scenario set should be is decided by that constraint here rather than by preference.

‍

What Sets the Recovery Duration?

‍

Assurance rather than restoration, which extends the halt well past the technical fix.

‍

Returning a system at the highest safety integrity level to service after a suspected compromise is not a restore. Where the integrity of the signalling software cannot be demonstrated, the safety case has to be re-established before service resumes, and that is an engineering and regulatory exercise rather than an IT one.

‍

Which Is the Familiar Pattern in a Third Form

‍

A production line is bounded by recommissioning and an airline by repositioning. Rail is bounded by revalidation, so all three have an operational clock that runs longer than the systems clock, for three unrelated reasons, and recovery bounded by something other than the restore sets out the first version.

‍

What Sits Outside the Fail-Safe Design?

‍

Everything that is not a safety function, and those losses behave conventionally.

‍

Passenger information, ticketing and retail, freight scheduling and depot management carry no fail-safe property. A compromise there produces the ordinary mixture of lost revenue, refunds and recovery cost, and it does not stop trains. So an exposure model needs two populations rather than one.

‍

Which Population Carries More?

‍

The safety population, because a halt propagates across the network while a ticketing failure degrades a service that continues running. A stopped train blocks a section and every following service inherits the delay, which is the mechanism the attribution regime exists to apportion.

‍

Does the Regime Cap the Exposure?

‍

Partly, and the part it does not cover is the one that grows with severity.

‍

Payments under the performance regime are formulaic and bounded by the rate and the attributed minutes, which makes them predictable. What sits outside are passenger compensation claims, the regulatory consequence of a prolonged safety-related outage, and the commercial position at the next franchise or access negotiation. A short disruption is almost entirely inside the regime and a long one is not.

‍

Which Changes the Shape of the Distribution

‍

Short events price linearly at a published rate, so the lower and middle of the distribution is unusually well determined. The tail behaves differently because the uncapped components arrive only at length, and reading a distribution at more than one point is how a linear middle and a non-linear tail get presented without one hiding the other.

‍

What Does That Mean for the Modeling Effort?

‍

Almost none is needed on the frequent case, since the rate does the work. The effort belongs on the threshold at which uncapped components begin, which is a question about regulatory and commercial triggers rather than about the technology, and exposure modeled by industry is where those triggers differ most between sectors.

‍

What Should Be Established?

‍

Four things, and two of them come from outside the security function.

‍

The published per-minute rate applying to your arrangements, which the commercial team holds. Historic attribution outcomes for comparable infrastructure failures, since they establish the delay minute distribution. Whether a suspected compromise of a safety system triggers revalidation before return to service, and how long that has taken. Then which systems are safety-related and which are not, because the two populations behave differently. Cyber risk quantification that treats duration as its own distribution is what lets a published rate be applied across the range rather than at a point.

‍

The Fail-Safe Design Decides the Loss Type

‍

Signalling forces itself into the most restrictive state on any failure, with proceed aspects requiring continuous current and interlocking held at the highest safety integrity level, because a stopped train is an inconvenience and a false proceed signal is a catastrophe. So a compromise produces a halt, which makes the safety design the attack surface for the financial loss rather than a protection against it, and hardening integrity guarantees the loss takes the disruption form. Rail is then unusual in having a published price for a halt, since the track access performance regime pays formulaically on attributed delay minutes at rates a regulator sets. Attribution decides who bears it, so a scenario has to name whose system was compromised. Recovery is also bounded by re-establishing a safety case rather than by restoring a system. Kovrr's cyber risk quantification models duration as its own distribution.

‍

To see disruption exposure modeled against a published per-minute rate, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Rail Cyber Loss FAQs

Speak to an Expert

What is the fail-safe principle in railway signalling?

Does a cyber attack on rail signalling cause a crash?

Why is fail-safe design also the attack surface?

How is rail service disruption priced?

What is delay attribution in rail?

Why does rail cyber recovery take longer than restoring the systems?