As railways become increasingly digitalised, building cyber resilience is becoming just as important as developing new systems. This aspect is already being taken into account at the design stage of new railway investments. Another challenge is adapting planned projects to the requirements of military mobility in crisis situations.
“The main cybersecurity challenge in the railway sector is the geographical dispersion of the digital infrastructure managed by PKP Polskie Linie Kolejowe. Another issue is the growing integration of IT information systems with operational technology, or OT. I am referring to industrial automation and control systems — systems that directly affect the safety of rail traffic and passengers,” Grzegorz Kuta, Director of the Cybersecurity Office at PKP Polskie Linie Kolejowe, told Newseria.
According to the Report of the Government Plenipotentiary for Cybersecurity for 2025, the digitalisation of state and economic processes, combined with Poland’s key geopolitical position — including the ongoing war in Ukraine and hybrid activities carried out by foreign intelligence services — has placed the country’s critical infrastructure under constant pressure from advanced cyberattacks.
Data published by the European Union Agency for Cybersecurity, ENISA, for 2025 indicate that the transport sector was the second most frequently targeted by hackers in the European Union, accounting for 7.5% of cyberattacks. Public administration ranked first with 38.2%, while digital infrastructure and services came third with 4.8%.
“Railways are becoming digitalised, and therefore the risks and challenges related to ensuring cyber resilience are much greater than they were just a few years ago,” Kuta emphasises.
He adds that PKP Polskie Linie Kolejowe has introduced an obligation to address cybersecurity requirements already at the pre-design and design documentation stages of planned investments, such as the construction of new railway lines. This applies to all projects involving a digital component.
“At the design-documentation stage, the aim is to carry out a risk analysis related to the possibility that a given component could be subject to cyber disruption, and to introduce a risk-management plan, meaning mitigation measures. This makes it possible to monitor the component and prevent potential cyberattacks and related threats already during construction and later in operation,” explains the Director of the Cybersecurity Office at PKP PLK.
“We design railway lines and are currently preparing project documentation, so ensuring cybersecurity for this infrastructure is a key element for us. Designing all critical infrastructure and network devices in such a way that appropriate cyber resilience can be ensured at the next stage is an area on which designers are focusing very strongly,” says Włodzimierz Sosnowski, Vice-President of WASKO and President of FONON.
As he notes, contractors are continuously improving their capabilities in building cyber protection systems.
“The challenge is that problems in this area change from day to day, while the design process is long-term. As a result, it is very difficult at the design stage to keep up with changes arising from cybersecurity challenges,” Sosnowski stresses.
Cooperation to strengthen rail cybersecurity
Many parties are involved in building the cyber resilience of railway infrastructure. In 2023, Polish State Railways signed an agreement with the Ministry of Digital Affairs, PKP Polskie Linie Kolejowe and PKP Informatyka. Its objective is to strengthen cooperation between railway companies and public administration in improving the security of Poland’s cyberspace.
Through this cooperation, the parties can consult on proposed or adopted technical and technological solutions used to ensure the security of data, ICT systems and digital information.
A sectoral cybersecurity incident response team is also being created: CSIRT Infrastructure. This specialised unit is intended to strengthen protection against cyberattacks and shorten response times to digital incidents in the transport and water-supply sectors.
Dual-use infrastructure and military mobility
Cyber resilience is gaining additional importance in the context of developing dual-use infrastructure — civil infrastructure prepared for defence purposes and for military use in crisis situations.
“Adapting civil infrastructure to defence tasks is difficult because civil and defence infrastructure are governed by different requirements. They have to serve somewhat different purposes, so this is not a straightforward situation,” says the Vice-President of WASKO and President of FONON.
“The military sphere, military regulations and NATO requirements have their own rules, which may sometimes involve classified information. Therefore, if we want to take into account the needs of the armed forces at the design stage — whether in terms of technical infrastructure, transport resilience or military movements on the infrastructure being built — we would need to receive those requirements at that stage in order to include them in the operational process,” says the Director of the Cybersecurity Office at PKP PLK.
On Monday, 15 June, a new long-term plan for Poland’s railway system was presented: the assumptions of the Integrated Railway Network. The document includes issues related to national defence and adapting railways to military mobility requirements.
According to the Ministry of Infrastructure, the main railway corridors forming the Integrated Railway Network are planned as dual-use infrastructure.
The document identifies several key elements: ensuring technical parameters that allow military transport movements, creating alternative diversion routes to maintain traffic even if one line is damaged, providing infrastructure enabling the rapid loading and reloading of military equipment and supplies, ensuring resistance to sabotage, and enabling rapid repairs.
By taking these factors into account, the Integrated Railway Network is expected to improve military mobility, strengthen the country’s resilience to threats and increase the overall level of security.





