UK Rail sits within Transport and Logistics —
a top-three cyber target, globally.
#3
GLOBAL
The numbers don't lie.
UK rail is under sustained attack from ransomware groups, hacktivists, and nation-state actors, and the market is responding accordingly. The exposure, and the investment needed to meet it, is growing every year.
The UK railway cybersecurity market is estimated at around £94 million in 2025, rising to roughly £198 million by 2035, making the UK the third-largest national market in Europe behind Germany and France.
Ransomware accounted for 45% of recorded railway cyber incidents, with data-related threats such as breaches and leaks making up a further 25%.
A systemic cyber attack disrupting the UK rail network for just one week could cost £1.8 billion.
Threat intelligence built for how UK rail actually operates.
Rail's cyber risk sits at the intersection of two disciplines that rarely meet in one person: cybersecurity and railway operations. CYJAX intelligence is interpreted by analysts who understand both, so what reaches your desk is context, not noise.
The Signal Box and the SOC
Reading rail-specific intelligence takes both cybersecurity expertise and an understanding of how a railway actually runs. Our analysts determine whether a threat touches a safety-critical trackside system or a back-office inconvenience, before it ever reaches your desk.
Safety-Limited Response, Built In
Rail cannot always isolate, patch, or reboot a system the way other sectors do without risking safety or service. Our intelligence is framed around what response options are actually available on a live, safety-critical network.
Legacy Protocols, Covered
Signalling and rolling stock systems often run on legacy and proprietary protocols that generic security tooling was never built to see. We provide visibility specific to the technology actually deployed across the network.
Beyond Your Own Network
Much of rail's exposure sits in a supply chain of contractors, signalling vendors, and rolling stock manufacturers outside your direct control. CYJAX monitors this extended ecosystem so third-party compromise doesn't become your incident.
The compliance bar for UK rail is rising fast.
Rail operators already sit under the NIS Regulations and are assessed against the NCSC's Cyber Assessment Framework, with the Department for Transport acting as competent authority for the sector. The incoming Cyber Security and Resilience Bill will extend those duties further, making demonstrable, evidenced threat intelligence a compliance requirement rather than a nice-to-have.
CAF
DfT
From the CYJAX desk.
How Are Organised Crime Groups Using Social Media to Commit Fraud?
Read the briefing
The Cyber Security and Resilience Bill: What It Means and Why Threat Intelligence Is Now Non-Negotiable
Read the briefing
From Data to Decision: How Trusted Threat Intelligence Cuts Through the Noise
Read the briefingGet the UK Rail Threat Report.
5 top tips to digital sovereignty and threat intelligence.
A practical briefing built for security leaders across UK rail, covering the threats, the actors, and what to do next.