Thron, E., Faily, S. and Dogan, H., 2024. Human Factors and Cyber Security Risks on the Railway – The Critical Role Played by Signalling Operations. Information and Computer Security, 32 (2), 236-263.
Full text available as:
|
PDF (OPEN ACCESS ARTICLE)
10-1108_ICS-05-2023-0078.pdf - Published Version Available under License Creative Commons Attribution. 1MB | |
PDF
Rail Human Factors and Cyber Security Risks PDF_Proof.PDF.pdf - Accepted Version Restricted to Repository staff only Available under License Creative Commons Attribution Non-commercial. 408kB | ||
Copyright to original material in this document is with the original owner(s). Access to this content through BURO is granted on condition that you use it only for research, scholarly or other non-commercial purposes. If you wish to use it for any other purposes, you must contact BU via BURO@bournemouth.ac.uk. Any third party copyright material in this document remains the property of its respective owner(s). BU grants no licence for further use of that third party material. |
Abstract
Purpose - Railways are a well-known example of complex critical infrastructure, incorporating socio-technical systems with humans such as drivers, signallers, maintainers, and passengers at the core. The technological evolution including interconnectedness and new ways of interaction lead to new security and safety risks that can be realised, both in terms of human error, and malicious and non-malicious behaviour. This article identifies the human factors (HF) and cyber-security risks relating to the role of signallers on the railways and explores strategies for the improvement of ‘Digital Resilience’ – for the concept of a resilient railway. Methodology- Overall, 26 interviews were conducted with 21 participants from industry and academia. Findings- The results showed that due to increased automation, both cyber-related threats and human error can impact signallers’ day-to-day operations - directly or indirectly (e.g., workload and safety-critical communications) - which could disrupt the railway services and potentially lead to safety-related catastrophic consequences. This article identifies cyber-related problems including external threats; engineers not considering the human element in designs when specifying security controls; lack of security awareness amongst the rail industry; training gaps; organisational issues and many unknown ‘unknowns’. Originality- We discuss socio-technical principles through hexagonal socio-technical framework and Training Needs Analysis (TNA) to mitigate against cyber-security issues and identify predictive training needs of the signallers. This is supported by a systematic approach which considers both, safety and security factors, rather than waiting to learn from a cyber-attack retrospectively.
Item Type: | Article |
---|---|
ISSN: | 2056-4961 |
Uncontrolled Keywords: | Human Factors; Cyber-security; Railway; Safety; Resilience; Training Needs |
Group: | Faculty of Science & Technology |
ID Code: | 38971 |
Deposited By: | Symplectic RT2 |
Deposited On: | 08 Sep 2023 12:22 |
Last Modified: | 05 Jun 2024 06:47 |
Downloads
Downloads per month over past year
Repository Staff Only - |