The legacy constraint is real, but it is not an exemption
ENISA has repeatedly identified legacy systems, supply-chain dependencies and tensions between safety and security as major railway cybersecurity challenges. Many signalling and rolling-stock assets were designed for long service lives and cannot adopt modern controls without significant validation or recertification work.
That creates a temptation to treat the asset as untouchable and move the cyber requirement into policy. But a policy does not remove network paths, shared maintenance credentials or insecure protocols. The exposure remains until architecture changes the conditions under which the legacy function can be reached.
The practical goal is therefore compensating control: isolate the asset, constrain the conduits, monitor the allowed protocol, harden the engineering path and make change authority explicit.
Compensating controls can create enforceable trust boundaries around legacy assets without forcing the certified endpoint itself to implement modern security mechanisms.
Can the organisation demonstrate that every remaining path to the legacy asset is required, constrained and monitored?
Zones and conduits turn policy into engineering
ENISA’s 2022 guidance on railway zones and conduits was developed against CLC/TS 50701:2021 and provides a structured way to identify assets, basic process needs, threats and allowed communications. Its zoning-and-conduit method remains useful technical guidance, but projects should map it to the current CLC/TS 50701:2023 baseline. That is particularly useful where the endpoint itself cannot be modernised.
A legacy interlocking or train subsystem can remain technically unchanged while the surrounding architecture reduces who can communicate with it, from where, using which protocol and under which maintenance state. This is not equivalent to patching, but it can materially change exploitability and blast radius.
The residual risk should then be expressed clearly: what remains unmitigated because of certification or lifecycle constraints, what compensating controls are relied upon, and what event would trigger replacement, redesign or an exceptional operational restriction.
- Document required communications before segmentation.
- Remove unused protocols and maintenance paths.
- Use protocol-aware filtering where practical.
- Separate monitoring from control authority.
- Record residual risk and replacement triggers explicitly.
