Current-baseline note. CLC/TS 50701:2023 is the current European technical specification referenced here. The compensating-control architecture remains an engineering judgement for legacy assets, not a claim that zoning alone makes an unpatchable endpoint secure.

The legacy constraint is real, but it is not an exemption

ENISA has repeatedly identified legacy systems, supply-chain dependencies and tensions between safety and security as major railway cybersecurity challenges. Many signalling and rolling-stock assets were designed for long service lives and cannot adopt modern controls without significant validation or recertification work.

That creates a temptation to treat the asset as untouchable and move the cyber requirement into policy. But a policy does not remove network paths, shared maintenance credentials or insecure protocols. The exposure remains until architecture changes the conditions under which the legacy function can be reached.

The practical goal is therefore compensating control: isolate the asset, constrain the conduits, monitor the allowed protocol, harden the engineering path and make change authority explicit.

What this diagram shows

Compensating controls can create enforceable trust boundaries around legacy assets without forcing the certified endpoint itself to implement modern security mechanisms.

Trust and authority pathLegacy Rail Assets Do Not Become Secure Because the Policy Improved
Trust pressure / decision point Governed state or evidence domain
Authority and evidence flow
Trust pressureLegacy assetCertified function remains unchanged
Evidence domainSecurity zoneBoundary limits reachable attack surface
Evidence domainControlled conduitOnly required traffic is permitted
Evidence domainModern monitoringExternal controls provide detection and evidence
Decision gate

Can the organisation demonstrate that every remaining path to the legacy asset is required, constrained and monitored?

YESThe decision can rely on bounded, auditable trust.
NOThe residual authority or evidence gap remains material.
How to read this: the dark node marks the point where trust can be lost or authority can expand. Arrows represent control, evidence or dependency relationships, not necessarily direct network links.

Zones and conduits turn policy into engineering

ENISA’s 2022 guidance on railway zones and conduits was developed against CLC/TS 50701:2021 and provides a structured way to identify assets, basic process needs, threats and allowed communications. Its zoning-and-conduit method remains useful technical guidance, but projects should map it to the current CLC/TS 50701:2023 baseline. That is particularly useful where the endpoint itself cannot be modernised.

A legacy interlocking or train subsystem can remain technically unchanged while the surrounding architecture reduces who can communicate with it, from where, using which protocol and under which maintenance state. This is not equivalent to patching, but it can materially change exploitability and blast radius.

The residual risk should then be expressed clearly: what remains unmitigated because of certification or lifecycle constraints, what compensating controls are relied upon, and what event would trigger replacement, redesign or an exceptional operational restriction.

For legacy rail, the control objective is to reduce reachable authority while preserving the certified function.
The decision
Use zoning, conduits and controlled maintenance to reduce authority around legacy rail assets without destabilising the certified core.
Operational checks
  • Document required communications before segmentation.
  • Remove unused protocols and maintenance paths.
  • Use protocol-aware filtering where practical.
  • Separate monitoring from control authority.
  • Record residual risk and replacement triggers explicitly.
Related episodeListen to the podcast versionLinkedInJoin the discussion
Source record

Sources & further reading

4 cited sourcesHow we source →
← All analysisCompanion episode →