Saudi Arabia Boosts Railway Cybersecurity

The agreement comes against a backdrop of heightened concerns about the cybersecurity of rail transport networks in general, part of the country's critical national infrastructure and the target of not-infrequent attacks.
Rail networks rely on a combination of IT and operational technology components that rely on multiple suppliers and diverse technologies.
Sirar by stc did not immediately respond to Dark Reading's request for comment on priorities for its work with SAR, or whether or not it will use internationally-recognized cybersecurity assurance standards as a guide.
SAR is responsible for managing 4,500 kilometers of railway networks in Saudi Arabia.
Departure Board Railways face the challenge of aligning legacy tech with the latest innovations: introducing IoT signaling and communications technology increases operational efficiency.
Operational benefits from modern technologies comes with the downside of increasing the attack surface of networks.
Many systems, such as those for switching tracks and tracking train locations - often broadcast wirelessly without encryption.
Travel Chaos Recorded breaches have targeted digital signage, ticketing systems, monitoring systems, and other components in stations, leading to widespread service interruptions and data leaks.
Notable incidents include the attack on San Francisco-area transport provider BART by hacktivist group Anonymous in 2011, while in May 2017, Deutsche Bahn in Germany was hit by the WannaCry malware.
Also in March 2022, Italy's rail network was hit by a ransomware attack that impacted ticket sales, leaked passenger information, and disrupted rail communications.
In August 2023, hackers disrupted the rail network traffic around Szczecin in Poland after breaking into the railway frequencies used between drivers and signalers.
The hackers caused some trains to apply emergency brakes, and they also played recordings of Russia's national anthem and a speech by Russian President Vladimir Putin.
Rolling Stock Steps to secure rail infrastructure start with the same fundamentals as bolstering the cybersecurity of enterprise networks - such as conducting a comprehensive risk assessment, building in resilience, and developing disaster recovery plans.
Shaked Kafzan, co-founder and CTO of security vendor Cervello, says a successful cybersecurity approach for railroads should focus on threat and risk prevention rather than detection, starting with having complete and in-depth visibility into every system and asset across all environments, including real-time risks - all within the rail context.


This Cyber News was published on www.darkreading.com. Publication date: Fri, 26 Jan 2024 15:20:03 +0000


Cyber News related to Saudi Arabia Boosts Railway Cybersecurity

Saudi Arabia Strengthens Its Cybersecurity Posture - The Kingdom of Saudi Arabia continues to advance its strategic commitment to cybersecurity, led by its National Cybersecurity Authority, the driver of many of the country's cyber protection initiatives. The NCA, formed in 2017, in the past year has ...
1 year ago Darkreading.com
Investing in Cloud Infrastructure in the Kingdom of Saudi Arabia - Digital transformation is at the heart of the Kingdom of Saudi Arabia's ambitious Vision 2030 program as the nation looks to future-proof its economy and enhance people's lives. The Kingdom is looking to diversify its economy and develop public ...
10 months ago Paloaltonetworks.com
UAE, Saudi Arabia Become Plum Cyberattack Targets - Hacktivism-related DDoS attacks have risen 70% in the region, most often targeting the public sector, while stolen data and access offers dominate the Dark Web. With the UAE and Saudi Arabia increasingly invested in digitization, AI development, and ...
6 months ago Darkreading.com
Saudi Arabia Boosts Railway Cybersecurity - The agreement comes against a backdrop of heightened concerns about the cybersecurity of rail transport networks in general, part of the country's critical national infrastructure and the target of not-infrequent attacks. Rail networks rely on a ...
1 year ago Darkreading.com
The 2024 ERA-ENISA Conference on Railway Cybersecurity seeks to strengthen sector preparedness and resilience against current threats — ENISA - The 2024 ERA-ENISA Conference on Railway Cybersecurity seeks to strengthen sector preparedness and resilience against current threats Amidst emerging technology advancements and evolving security challenges in the sector, the fourth edition of the ...
6 months ago Enisa.europa.eu
Middle East CISOs Fear Disruptive Cloud Breach - As organizations in the Middle East increasingly adopt cloud services, business leaders worry that their cloud-security measures are falling short. Running in the Cloud The worries arise as organizations in the Middle East accelerate their cloud ...
1 year ago Darkreading.com
Fortinet Contributes to World Economic Forum's Strategic Cybersecurity Talent Framework - Shining a light on the cybersecurity workforce challenge, the World Economic Forum recently published its Strategic Cybersecurity Talent Framework, which is intended to serve as a reference for public and private decision-makers concerned by the ...
11 months ago Feeds.fortinet.com
Ransomware Attacks Strike South Africa, Decline in UAE - Cybercrime - and especially ransomware - traditionally have had an uneven impact across the Middle East and Africa, yet recent data suggests that ongoing geopolitical conflicts will likely raise the overall level of cyberattacks across the regions. ...
1 year ago Darkreading.com Molerats LockBit
Student Cybersecurity Clubs: Fostering Online Safety - Student cybersecurity clubs are playing a crucial role in promoting online safety among students. Student cybersecurity clubs play a vital role in this regard, as they provide a platform for students to learn about the latest threats, share best ...
1 year ago Securityzap.com
Saudi Arabia's National Cybersecurity Authority Announces the GCF Annual Meeting 2024 - Under the theme 'Advancing Collective Action in Cyberspace,' the event will unite thought leaders, decision makers and experts across the global Cyberspace community to bolster international cooperation, address shared challenges, enhance ...
1 year ago Darkreading.com
Hajj Pilgrimage Hit by Extensive Phishing and Data Theft Scams - Cybersecurity threats rise during this peak season as millions embark on the annual Hajj pilgrimage. This article offers crucial tips for pilgrims to safeguard themselves online while ensuring a safe and fulfilling Hajj experience. Every year, ...
10 months ago Hackread.com
How to become a cybersecurity architect - Cybersecurity architects implement and maintain a comprehensive cybersecurity framework to protect their company's digital assets. The cybersecurity architect position is a fundamental role that all organizations need, said Lester Nichols, director ...
9 months ago Techtarget.com
Growing threats outpace cybersecurity workforce - The cybersecurity skills shortage threatens the well-being and even survival of numerous businesses as cybersecurity threats grow more numerous, sophisticated, and dangerous to the point that cybersecurity groups have vowed not to pay ransom demands. ...
1 year ago Legal.thomsonreuters.com
Cybersecurity Curriculum Development Tips for Schools - With the constant threat of cyber attacks, schools must prioritize the development of a robust cybersecurity curriculum to equip students with the necessary skills and knowledge. This article provides valuable insights and tips for schools aiming to ...
1 year ago Securityzap.com
The Importance of Cybersecurity Education in Schools - Cybersecurity education equips students with the knowledge and skills needed to protect themselves and others from cyber threats. Cybersecurity education can teach students about the impact of cyberbullying, how to prevent it, and how to respond ...
1 year ago Securityzap.com
African Organizations Aim to Fix Cybersecurity in 2024 - Faced with numerous cybersecurity threats and challenges, but lacking adequate cyber training, African nations hope to develop the depth of skills needed to defend against attackers in 2024. In December, for example, the University of Lagos, the ...
1 year ago Darkreading.com
Understanding the New SEC Rules for Disclosing Cybersecurity Incidents - The U.S. Securities and Exchange Commission recently announced its new rules for public companies regarding cybersecurity risk management, strategy, governance, and incident exposure. "Currently, many public companies provide cybersecurity disclosure ...
1 year ago Feeds.dzone.com
Digital Learning Tools for Cybersecurity Education - In the field of cybersecurity education, digital learning tools have become indispensable. This article explores various digital learning tools tailored specifically to cybersecurity education. These digital learning tools play a crucial role in ...
1 year ago Securityzap.com
What the cybersecurity workforce can expect in 2024 - For cybersecurity professionals, 2023 was a mixed bag of opportunities and concerns. The good news is that the number of people in cybersecurity jobs has reached its highest number ever: 5.5 million, according to the 2023 ISC2 Global Workforce Study. ...
1 year ago Securityintelligence.com
Cybersecurity Training for Business Leaders - This article explores the significance of cybersecurity training for business leaders and its crucial role in establishing a secure and resilient business environment. By examining the key components of effective training programs and the ...
1 year ago Securityzap.com
Ukraine’s state railway restores online ticket sales after major cyberattack | The Record from Recorded Future News - Among those who assisted the railway in recovering from the attack are Ukraine’s largest telecom operator, Kyivstar, and the Ministry of Justice — both of which were targets of recent large-scale attacks suspected to have been carried out by ...
3 weeks ago Therecord.media
Gamification in Cybersecurity Education - Gamification has become increasingly prevalent in numerous domains, including cybersecurity education. Gamification presents a promising approach to meet this challenge, making cybersecurity education both effective and enjoyable. One way to ...
1 year ago Securityzap.com
Cyber Employment 2024: Sky-High Expectations Fail Businesses & Job Seekers - Well-publicized estimates of a massive shortfall in cybersecurity workers have resulted in high expectations among job seekers in the field, but the reality often falls flat, because of a mismatch between companies' requirements and job seekers' ...
1 year ago Darkreading.com Equation
Key cybersecurity skills gap statistics you should be aware of - As the sophistication and frequency of cyber threats continue to escalate, the demand for skilled cybersecurity professionals has never been bigger. The skills gap is not merely a statistical discrepancy; it represents a substantial vulnerability in ...
1 year ago Helpnetsecurity.com
How to Avoid Falling Below the Cybersecurity Poverty Line - The security poverty line broadly defines a divide between the organizations that have the means and resources to achieve and maintain mature security postures to protect data, and those that do not. It was first coined by cybersecurity expert Wendy ...
2 years ago Csoonline.com

Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)