UK Rail sits within Transport and Logistics —
a top-three cyber target, globally.
#3
GLOBAL
The numbers don't lie.
UK rail is under sustained attack from ransomware groups, hacktivists, and nation-state actors, and the market is responding accordingly. The exposure, and the investment needed to meet it, is growing every year.
The UK railway cybersecurity market is estimated at around £94 million in 2025, rising to roughly £198 million by 2035, making the UK the third-largest national market in Europe behind Germany and France.
Ransomware accounted for 45% of recorded railway cyber incidents, with data-related threats such as breaches and leaks making up a further 25%.
A systemic cyber attack disrupting the UK rail network for just one week could cost £1.8 billion.
Threat intelligence built for how UK rail actually operates.
Rail's cyber risk sits at the intersection of two disciplines that rarely meet in one person: cybersecurity and railway operations. CYJAX intelligence is interpreted by analysts who understand both, so what reaches your desk is context, not noise.
The Signal Box and the SOC
Reading rail-specific intelligence takes both cybersecurity expertise and an understanding of how a railway actually runs. Our analysts determine whether a threat touches a safety-critical trackside system or a back-office inconvenience, before it ever reaches your desk.
Safety-Limited Response, Built In
Rail cannot always isolate, patch, or reboot a system the way other sectors do without risking safety or service. Our intelligence is framed around what response options are actually available on a live, safety-critical network.
Legacy Protocols, Covered
Signalling and rolling stock systems often run on legacy and proprietary protocols that generic security tooling was never built to see. We provide visibility specific to the technology actually deployed across the network.
Beyond Your Own Network
Much of rail's exposure sits in a supply chain of contractors, signalling vendors, and rolling stock manufacturers outside your direct control. CYJAX monitors this extended ecosystem so third-party compromise doesn't become your incident.
The compliance bar for UK rail is rising fast.
Rail operators already sit under the NIS Regulations and are assessed against the NCSC's Cyber Assessment Framework, with the Department for Transport acting as competent authority for the sector. The incoming Cyber Security and Resilience Bill will extend those duties further, making demonstrable, evidenced threat intelligence a compliance requirement rather than a nice-to-have.
CAF
DfT
From the CYJAX desk.
Rail Cybersecurity in 2026: What the UK Market Data Tells Us About a Sector Under Pressure
Read the briefing
Why Generic Threat Intelligence Doesn't Work for Rail
Read the briefing
How to Build a Rail Threat Intelligence Programme: A Practical Roadmap
Read the briefingDownload the CYJAX Gets Rail Report.
£5m+ in cable theft. 130+ dark web listings selling access to transport networks. 308,777 records exposed in a single breach. This threat intelligence briefing covers the incidents CYJAX has tracked across UK and European rail, and what they mean for your organisation.