Transit OS

Guides / Compliance

Security when nobody's job title says security

Around thirty percent of 2025 breaches involved a third party. Here is the short list of things a small agency can do without a security budget, ordered by what actually reduces risk.


Roughly thirty percent of breaches in 2025 involved a supply-chain or third-party compromise. For transit that matters more than the headline number suggests, because agencies run long-lived operational technology — signalling, train control, power — that cannot be patched or monitored the way an office laptop can.

You are not going to solve operational-technology security with a checklist. But most agencies we talk to are exposed through much more ordinary doors, and those you can close this month.

In order of what actually helps

  1. Turn on multi-factor authentication for email first. Email is the master key — it resets every other password you own.
  2. Write down every vendor with access to your systems, and what each one can reach. Most agencies cannot produce this list, which is itself the finding.
  3. Remove access for people who have left. Check quarterly. This is the single most common real-world hole.
  4. Stop sharing one login. Individual accounts are free and they are the difference between an audit trail and a guess.
  5. Get an offline copy of your schedules and configuration. If everything else fails, this is what you rebuild from.
  6. Know who to call. Have the number written on paper before you need it.

Notice that none of the first six items costs money. Almost all real improvement at small-agency scale is procedural rather than technical.

A worker in a hard hat silhouetted against tall shed windows, working high on the frame of a locomotive in a dim maintenance building.
Plate 03The equipment is old. That is not the same as neglected.

The operational-technology problem, honestly

Signalling, crossing controls, train control and power systems are a different category from your office network. They were installed to last thirty years, they often cannot be patched, and the vendor who supplied them may no longer support the version you run.

Nobody is going to solve that with a checklist, and any vendor who tells you their product secures your operational technology is selling something. What a small agency can realistically do is reduce the ways an office compromise reaches the operational side.

  • Know what is connected to what. A simple hand-drawn diagram beats no diagram, and most agencies have neither.
  • Keep operational systems off the same network as email and general web browsing, even if that means a separate cheap switch.
  • Do not let vendors connect remotely on a standing basis. Turn access on for the visit and off afterwards.
  • Ask your OT vendors, in writing, what they support and until when. The answer is often uncomfortable and always worth having before an incident rather than during one.

None of that is glamorous and none of it requires a security budget. It requires somebody being given the time to find out how things are actually wired, which is a management decision rather than a technical one.

Questions to put to every vendor, including us

  • Where is our data stored, and under whose jurisdiction?
  • Who on your staff can read our data, and is that access logged?
  • How do we get a complete export today, without asking permission?
  • What is your notification commitment if you are breached, in hours?
  • Do you use our data to train models? Can we say no and keep the product?

A vendor that cannot answer these quickly and specifically has not thought about them. That includes us — hold us to the same list, and hold us to it in writing.

Source: Trends shaping public transportation, including third-party breach exposure — Modeshift

Questions

Is cloud software less safe than keeping it in our building?

Honestly, usually the opposite at this scale — not because cloud is magic, but because a server in a closet with no patching schedule and no backups is a genuinely difficult thing to secure. The real question is not where it runs but who is accountable for patching it, and whether that person exists.

We are too small to be a target.

Most attacks are not targeted. They are automated sweeps that find an exposed service and take whatever is behind it. Being small changes the motive, not the exposure.

Read next

  • Evaluating software you will barely useA buyer's guide for small agencies: the questions that actually predict whether a system will be used, the pricing traps to name out loud, and what to insist on in writing.
  • When the person who knows everything retiresInstitutional memory is the largest undocumented asset at most small agencies and heritage railroads. A practical method for getting it out of one head before you need to.