Transport
Traffic management, ports, airports and railways rely on systems that must not stop, and a large share runs on equipment fifteen years old or more.
What the Act requires of this sector
Transport is the second sector of Annex I and covers air, rail, water and road transport. The competent CSIRT for every sub-sector is the national cyber security centre.
The competent authority differs by sub-sector. For rail, water and road transport it is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA). For air transport, Annex III names the Croatian Civil Aviation Agency (HACZ) as the body competent for sectoral legislation.
The category follows size, with possible classification regardless of size under the special criteria of Article 11. The sector is distinctive for the number of external contractors with access, so the supply chain measure carries more work here than elsewhere.
Where this sector usually gets stuck
What we do for you
Who from the sector falls in scope
The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.
Danish trains stopped by an attack on a supplier
Trains run by Denmark’s largest operator stood still for several hours on a Saturday morning. Nobody attacked the railway. The target was Supeo, the supplier of the app drivers use to get speed limits and track work information. Supeo shut down its servers to contain the attack, the app stopped working and drivers had to halt. A continuity plan has to cover somebody else’s servers too, not only your own.
SOURCE: DSB statements and reporting by Danish public broadcaster DR, November 2022.
Frequently asked questions
The questions transport operators ask first, mostly about contractors and systems that must not stop.
Which operators and managers are in scope?
Air, rail, water and road transport, including ports, airports and infrastructure managers. The category follows sector and size.How do we reconcile security with systems that must not stop?
With planned change windows and compensating measures for anything that must not be touched. A postponement with no deadline and no justification reads to an auditor as an omission.What about a large number of external contractors?
Every contractor with access goes into the supplier register, with security clauses, a right of inspection and an obligation to report incidents. Without that, their incident becomes yours.Do we have to join physical and cyber security?
The thirteenth measure covers physical and environmental security, so the records of both functions have to meet. Two logs that never exchange anything struggle to evidence one measure.Do sector rules apply alongside the law?
They do. Air and maritime transport have their own rules, so the first step is to delimit what falls under the law and what under the sector regime.Who is our competent authority?
For rail, water and road transport it is the central state authority for cyber security. For air transport, Annex III of the Act names the Croatian Civil Aviation Agency as the body competent for sectoral legislation. The competent CSIRT in every case is the national cyber security centre.Does an incident at a contractor fall within our obligations?
If it affected your service, it does. That is why sub-measure 8.6 requires incident response plans that include direct suppliers, and the contract must oblige the supplier to notify you within a period that lets you meet your own deadlines.How many contractors go into the register?
All direct suppliers and service providers, under sub-measure 8.2. The register is not a list of every partner but of those with access to your systems or data, or whose outage stops your service.Related pages
The pages that set out in full what transport has to show in measures and evidence.
Let us start from the list of critical systems.
Half an hour, no obligation. We start from the list of systems that must not stop.
