
As tensions rise globally, cybersecurity experts warn that U.S. railroads could become prime targets for cyberattacks. While power grids and healthcare systems often receive attention, rail networks—vital for transporting goods and people—face growing risks. Disruptions caused by hacked systems could lead to catastrophic consequences, including derailed trains or widespread economic damage.
Despite their importance, railroads have been slow to bolster their defences. Tom VanNorman of cybersecurity firm GRIMM highlighted the industry’s vulnerabilities, pointing out that rail systems are now more connected to the internet than ever before, leaving them exposed to potential attacks.
In 2022, the U.S. Transportation Security Administration (TSA) introduced federal cyber regulations for rail operators, aiming to close these security gaps. Freight and passenger carriers are now required to implement basic cyber defences and report incidents.
However, progress has been slow. Experts like Grant Geyer from Claroty, an operational technology cybersecurity firm, stress that the rail industry lags behind other infrastructure sectors in addressing cyber threats. Upgrading the outdated systems scattered across vast distances is costly and time-consuming, but critical to preventing potentially disastrous cyberattacks.
The uneasy partnership between the rail industry and TSA continues to evolve as both parties balance security concerns with business realities. Despite early resistance, the TSA remains optimistic, with officials noting that many rail companies are beginning to understand the necessity of stronger cybersecurity measures.
As digital threats grow more sophisticated, the stakes for railroads—and the country—are higher than ever.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543