

Network Rail OT Cybersecurity: First-of-a-Kind Security Monitoring for Signalling
Network Rail needed to extend security monitoring beyond its enterprise IT environment and into safety-critical signalling networks. Complete Cyber was initially engaged to deliver a proof of concept assessing whether the existing SIEM platform was suitable for rail OT cybersecurity monitoring.
Following the findings, the scope expanded to support the procurement of a dedicated OT SIEM and network collection capability, and to develop the high-level and low-level designs required to integrate monitoring across two of Network Rail’s largest Railway Operating Centres.
SCOPE
CHALLENGES
Monitoring a safety-critical railway environment required a different approach from traditional enterprise IT. Complete Cyber first built cloud-based sandbox environments to perform a like-for-like evaluation of the incumbent SIEM against OT monitoring use cases.
The physical environment introduced another challenge. Legacy network switches meant SPAN mirroring was not viable, while any alternative had to provide the required visibility without introducing risk to operational signalling. Our team reviewed network and signalling bookwiring, conducted site surveys and carried out light passive discovery before selecting copper and fibre network TAPs for passive traffic collection.
OUTCOMES
Complete Cyber delivered the high-level and low-level designs for a scalable OT security monitoring architecture across two of Network Rail’s largest Railway Operating Centres, providing the SOC with visibility of safety-critical signalling networks for the first time.
To achieve this safely, our specialists combined evidence-led SIEM evaluation, signalling bookwiring reviews, site surveys and light passive network discovery. Where legacy switching ruled out SPAN mirroring, we designed the collection approach around copper and fibre network TAPs, enabling passive traffic monitoring without intrusive testing on safety-critical systems.
Before the solution reached the operational estate, Complete Cyber red teamed the deployment during Factory Acceptance Testing (FAT) to validate the OT SIEM’s detection and response capabilities. The result was a first-of-a-kind security monitoring project within Network Rail, with an architecture designed to bring additional sites into scope without redesign.