RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Transport

Traffic management, ports, airports and railways rely on systems that must not stop, and a large share runs on equipment fifteen years old or more.

What the Act requires of this sector

Transport is the second sector of Annex I and covers air, rail, water and road transport. The competent CSIRT for every sub-sector is the national cyber security centre.

The competent authority differs by sub-sector. For rail, water and road transport it is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA). For air transport, Annex III names the Croatian Civil Aviation Agency (HACZ) as the body competent for sectoral legislation.

The category follows size, with possible classification regardless of size under the special criteria of Article 11. The sector is distinctive for the number of external contractors with access, so the supply chain measure carries more work here than elsewhere.

Where this sector usually gets stuck

Traffic management systemsAvailability outranks everything, so security changes are constantly postponed.
Many external contractorsEach brings their own access, accounts and equipment.
Physical and cyber security kept apartTwo teams that do not share records struggle to evidence the physical security measure.

What we do for you

01A readiness review across the thirteen measures02An inventory of assets and critical systems03Rules for contractors and their access04Joining physical and cyber security05A continuity plan and an exercise

Who from the sector falls in scope

WHOCATEGORYNOTE
Air transport: carriers, airport operators, air traffic controlEssential or importantAnnex III names the Croatian Civil Aviation Agency for sectoral legislation
Rail transport: infrastructure managers and operatorsEssential or importantBy size
Water transport: operators, port authorities, vessel traffic servicesEssential or importantBy size
Road transport: road authorities and intelligent transport system operatorsEssential or importantBy size

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · DENMARK, NOVEMBER 2022

Danish trains stopped by an attack on a supplier

Trains run by Denmark’s largest operator stood still for several hours on a Saturday morning. Nobody attacked the railway. The target was Supeo, the supplier of the app drivers use to get speed limits and track work information. Supeo shut down its servers to contain the attack, the app stopped working and drivers had to halt. A continuity plan has to cover somebody else’s servers too, not only your own.

SOURCE: DSB statements and reporting by Danish public broadcaster DR, November 2022.

Frequently asked questions

The questions transport operators ask first, mostly about contractors and systems that must not stop.

Which operators and managers are in scope?

Air, rail, water and road transport, including ports, airports and infrastructure managers. The category follows sector and size.

How do we reconcile security with systems that must not stop?

With planned change windows and compensating measures for anything that must not be touched. A postponement with no deadline and no justification reads to an auditor as an omission.

What about a large number of external contractors?

Every contractor with access goes into the supplier register, with security clauses, a right of inspection and an obligation to report incidents. Without that, their incident becomes yours.

Do we have to join physical and cyber security?

The thirteenth measure covers physical and environmental security, so the records of both functions have to meet. Two logs that never exchange anything struggle to evidence one measure.

Do sector rules apply alongside the law?

They do. Air and maritime transport have their own rules, so the first step is to delimit what falls under the law and what under the sector regime.

Who is our competent authority?

For rail, water and road transport it is the central state authority for cyber security. For air transport, Annex III of the Act names the Croatian Civil Aviation Agency as the body competent for sectoral legislation. The competent CSIRT in every case is the national cyber security centre.

Does an incident at a contractor fall within our obligations?

If it affected your service, it does. That is why sub-measure 8.6 requires incident response plans that include direct suppliers, and the contract must oblige the supplier to notify you within a period that lets you meet your own deadlines.

How many contractors go into the register?

All direct suppliers and service providers, under sub-measure 8.2. The register is not a list of every partner but of those with access to your systems or data, or whose outage stops your service.

Related pages

The pages that set out in full what transport has to show in measures and evidence.

Let us start from the list of critical systems.

Half an hour, no obligation. We start from the list of systems that must not stop.

Book a callINFO@RISKORIA.EU · +385 97 737 1345