Computational & Technology Resources
an online resource for computational,
engineering & technology publications
Civil-Comp Conferences
ISSN 2753-3239
CCC: 15
PROCEEDINGS OF THE SEVENTH INTERNATIONAL CONFERENCE ON RAILWAY TECHNOLOGY: RESEARCH, DEVELOPMENT AND MAINTENANCE
Edited by: J. Pombo
Paper 20.2

Applying the New IEC 63452 OT Railway Cybersecurity Standard to Operators and System Integrators

H. Parkinson1,2, D. Basher2, G. Bamford2, S. Parkinson3 and J. Murray2

1, University of Huddersfield, United Kingdom
2, Digital Transit Limited, United Kingdom
3Department of Computer Science, University of Huddersfield, United Kingdom

Full Bibliographic Reference for this paper
H. Parkinson, D. Basher, G. Bamford, S. Parkinson, J. Murray, "Applying the New IEC 63452 OT Railway Cybersecurity Standard to Operators and System Integrators", in J. Pombo, (Editor), "Proceedings of the Seventh International Conference on Railway Technology: Research, Development and Maintenance ", Civil-Comp Press, Edinburgh, UK, Online volume: CCC 15, Paper 20.2, 2026, doi:10.4203/ccc.15.20.2
Keywords: railway cybersecurity, OT cybersecurity, IEC 63452, IEC 62443, zone and conduit model, security level, system integrator, train operator, automatic train protection.

Abstract
IEC 63452 is a new international standard specifically designed to address operational technology (OT) cybersecurity in railway applications. To be published later in 2026, it adapts the widely used IEC 62443 series of industrial cybersecurity standards to the specific context and safety-critical requirements of the railway domain. This paper examines how IEC 63452 applies in practice from two complementary perspectives: that of the train operator (in this case also acting as railway duty holder and asset owner), and that of the system integrator responsible for delivering a new railway OT solution. Using a worked case study of an Automatic Train Protection (ATP) system for maintenance vehicles, the paper walks through the standard’s lifecycle phases from stakeholder identification and system definition through to the detailed risk assessment, zone and conduit modelling, and determination of Target Security Level (SL-T) vectors. The paper identifies practical insights, challenges, and lessons learned from applying the standard, including the complexity of zone derivation, the use of the ERORAT threat assessment template, and the relationship between cybersecurity and functional safety under IEC 63452. The paper concludes with recommendations for organisations embarking on their first IEC 63452 assessment.

download the full-text of this paper (PDF, 15 pages, 515 Kb)

go to the previous paper
go to the next paper
return to the table of contents
return to the volume description