Event details

As the UK rolls out modern digital signalling, unified passenger apps, and interconnected freight systems, the railway becomes a more prominent target for cyber-attacks. Ransomware threats to operational technology (OT) can freeze network performance instantly. This theme addresses how to protect next-generation European Train Control System (ETCS) architectures, securely manage data within unified GBR systems, and evaluate digital risk across a supply chain featuring thousands of external software and SaaS providers.

.

   

Want to sponsor

 

Want to speak









Who Attends

Times are displayed in BST

  • 08:30 AM - 08:45 AM

    Keynote

  • 08:55 AM - 09:40 AM

    Defending the Digital Railway: Mitigating Ransomware in Signalling Networks

    This panel addresses the immediate threat of cyber-attacks on safety-critical rail systems. Chief Information Security Officers (CISOs), operational technology (OT) engineers, and national security experts will discuss how to isolate and defend modern signalling infrastructure from ransomware. The conversation will focus on practical strategies for securing digital train control networks, building resilient backup systems, and responding to live cyber incidents without completely halting passenger and freight services.

    Key Discussion Points

    • The OT Ransomware Threat: Understanding how ransomware can breach IT systems to target operational infrastructure, and the cascading impacts on network performance.
    • Securing Next-Gen ETCS: Identifying vulnerabilities within digital signalling architectures and building robust cyber-defences into European Train Control System rollouts.
    • Network Segmentation & Containment: Practical protocols for air-gapping and isolating compromised subsystems to keep wider network operations running safely.
    • Incident Response Under Pressure: How control rooms, infrastructure managers, and emergency teams can coordinate rapidly during a live cyber-attack.
  • 09:50 AM - 10:35 AM

    The GBR Data Space: Balancing Operational Data Pools with Privacy

    This panel explores the complex data governance challenges of building a unified data architecture under Great British Railways. Data protection officers, digital transformation directors, and privacy lawyers will discuss how to securely pool vast streams of operational, passenger, and freight data. The session will focus on establishing strict access controls, maintaining regulatory compliance, and protecting sensitive commercial and passenger privacy while unlocking data-driven network efficiencies.

    Key Discussion Points

    • The Unified Data Ecosystem: Architecting a central data space that allows track, train, and third-party developers to safely collaborate.
    • Passenger Privacy at Scale: Implementing robust anonymisation and data masking techniques for ticketing, travel patterns, and passenger app data.
    • Protecting Commercial Secrets: Balancing open data principles with the need to shield confidential freight volumes and operator financial data.
    • Governance and Compliance: Ensuring the GBR unified pool meets rigorous UK GDPR standards and international data sharing frameworks.
  • 10:45 AM - 11:30 AM

    Hardening the Supply Chain: Managing Third-Party Rail-Tech Risks

    This panel tackles the systemic digital risks introduced by an increasingly interconnected rail supply chain. Procurement leads, software security auditors, and Tier 1 technology vendors will discuss how to evaluate and mitigate third-party vulnerabilities. The session will focus on standardising cybersecurity procurement criteria under GBR, continuously auditing external SaaS and software providers, and ensuring a single compromised vendor cannot create a back-door entry point into safety-critical rail systems.

    Key Discussion Points

    • The Vendor Vulnerability: Mapping the digital attack surface across thousands of external software providers, rolling stock suppliers, and IoT maintenance systems.
    • Standardising Security Procurement: Embedding rigorous, non-negotiable cyber-resilience benchmarks directly into the Great British Railways tendering process.
    • Continuous SaaS Auditing: Moving beyond "point-in-time" security questionnaires to real-time, automated monitoring of third-party software risks.
    • Containing the Cascade: Engineering strict zero-trust architectures to ensure a breach at a minor supplier does not compromise core operational networks.
  • 11:40 AM - 12:25 PM

    Digital Ticketing and Biometrics: Securing Public Trust and Accessibility

    This panel addresses the dual challenge of innovation and inclusivity as GBR modernises the passenger experience. Passenger advocacy groups, biometric technology developers, and data security experts will debate the rollout of advanced digital ticketing systems, pay-as-you-go tech, and facial recognition trials. The session will focus on securing public trust through ironclad biometric data protection, addressing privacy concerns, and ensuring automated gating systems remain fully accessible to vulnerable, elderly, or unbanked travellers.

    Key Discussion Points

    • Securing Biometric Data: Implementing zero-trust architectures and encryption standards to protect sensitive facial and fingerprint data from cyber-theft.
    • Winning Public Trust: Addressing surveillance anxieties and clearly communicating the opt-in boundaries of biometric ticketing to passengers.
    • Designing for Total Accessibility: Ensuring next-generation digital gates and ticketing apps remain fully usable for neurodivergent individuals and passengers with physical disabilities.
    • The Risk of Digital Exclusion: Creating resilient backup systems and maintaining accessible alternatives for travellers who lack smartphones or traditional banking options.

Register

Our registration process uses cookies, by submitting this registration form you agree to our cookie policy. * Required Fields