Signalling, traction,terminals. One record.

Transport is safety-critical OT operated by many hands: the interlocking and the train protection system, the traction power SCADA, the station systems, the crane and gate automation at a terminal — with concessionaires, OEMs and contractors on each. ASTRICS gives the operator one operational understanding of all of it, ranked by what a failure does to a train, a ship or a passenger.

India's major ports handled 915 million tonnes of cargo in FY2025–26; the Airports Authority manages 153 airports; and Kavach trackside works are under way on 21,794 route-kilometres. Transport is one of the critical sectors NCIIPC covers.

Sources: Ministry of Ports, Shipping and Waterways; Airports Authority of India; Ministry of Railways via PIB; NCIIPC

The transport estate,as ASTRICS reads it.

Signalling, traction, station and terminal assets land in one register with their process, their owner — often a contractor or concessionaire — and their consequence to safety and throughput attached.

Interlocking and CBTC

The electronic interlocking and communications-based train control that decide whether a train may move. Safety-critical by definition, and vendor-maintained.

Train protection

Kavach and equivalent systems: trackside RFID, radio and onboard units. A new network layer along every kilometre of track.

Traction power SCADA

Substations, sectioning and the 25 kV catenary — the same overlay ASTRICS paints on any switchyard.

Station systems

Passenger information, CCTV, fare collection, building management. IT-adjacent OT with a public-facing consequence.

Terminal automation

Terminal operating systems, ship-to-shore and yard cranes, gate automation. The systems NotPetya reached at JNPT through a shipping line.

OEM and concessionaire access

Signalling OEMs, rolling-stock suppliers, terminal operators. Every session observed, attributed and checked against its window.

Why transport OTis exposed through its partners.

The transport incidents on record rarely began in the operator's own network. They arrived through a supplier, a shipping line or a radio protocol that was never designed to check who was talking.

Safety-critical by definition

A signalling or train-protection failure is a safety event before it is a security one. Consequence ranking is not a preference here; it is the operating principle.

Many operators, one estate

Concessionaires run terminals, OEMs maintain signalling, contractors run stations. The record has to show who reaches what, across all of them.

Ports are IT-exposed OT

A terminal operating system talks to shipping lines, customs and hauliers all day. That is how NotPetya reached a berth in Navi Mumbai in 2017.

On the record

  • 2017

    Operations at the GTI terminal at Jawaharlal Nehru Port were disrupted when NotPetya spread through its operator, A.P. Moller–Maersk.

    Ministry of Shipping statement, June 2017

  • 2022

    A ransomware attack on the Jawaharlal Nehru Port Container Terminal caused a system outage and vessels were diverted to other terminals.

    JNPT statement, February 2022 — as reported

  • 2023

    Around twenty trains in Poland were halted when an unauthenticated radio-stop signal was broadcast on the railway's analogue radio frequency.

    Polish Internal Security Agency; PKP, August 2023

  • 2022

    Trains in Denmark stopped for hours when a ransomware attack on a supplier, Supeo, took down the application drivers use for operating data.

    DSB, November 2022

What the rules askof a transport operator.

Summaries of the notified text as we read it in September 2026. Orientation, not legal advice — check the Gazette before you rely on a clause.

CERT-In, six hours

IT Act s.70B(6) Directions

The CERT-In Directions of 28 April 2022 bind every body corporate and government organisation: covered incidents reported within six hours of noticing, 180 days of ICT logs kept in India, clocks synchronised to NIC or NPL time.

Transport is a critical sector

IT Act ss.70, 70A; NCIIPC

Transport is one of the sectors NCIIPC covers. Where an asset is identified as critical information infrastructure, it can be notified as a protected system under section 70 of the IT Act.

Railway policy and standards

IR ICT Security Policy 2019; RDSO

Indian Railways' ICT Security Policy of 2019 and RDSO's cyber security guidance apply to railway systems; Kavach is an RDSO specification with its own key management, and CBTC deployments carry their own safety certification.

Ports, ships and airports

DG Shipping EC 06/2017; Indian Ports Act 2025; CEA Regulations 2026

Indian-flag ships have carried cyber risk in their safety management systems since DG Shipping's 2017 circular under IMO resolution MSC.428(98). Port security sits with the Ministry of Ports, Shipping and Waterways and the port authorities under the Indian Ports Act, 2025; airport security with BCAS and the Airports Authority of India. Traction or port power at 50 MW or more falls under the CEA regulation in its own right.

IEC 62443 as the Indian standard

BIS / IEC 62443

The Bureau of Indian Standards has adopted the IEC 62443 series as Indian Standards. Zones, conduits and security levels are the vocabulary a signalling or terminal audit will use.

to report a covered cyber incident to CERT-In after noticing it — for every body corporate, whatever the sector.

of ICT system logs to be kept, inside India, and produced to CERT-In on request.

How ASTRICS mapsto a transport estate.

One platform, one language, one source of truth. Understand, Govern, Protect, Orchestrate and Assure travel together, so every capability below reads the same record.

The register across every partner

Asset Inventory holds interlocking, train protection, traction and terminal assets with an accountable owner and a criticality — whether the owner is the operator, an OEM or a concessionaire.

Events that already know the asset

Native syslog and event analytics correlate on the asset model, so an anomaly at a signalling gateway is an incident with a consequence, not a line in a log.

From six events to a submission

The statutory incident workflow assembles the six-hour CERT-In notification from context already held and keeps the clock, the workflow and the submission in one place.

Segmentation, proven

Zones & Conduits declares the boundaries between signalling, traction, station and corporate networks and tests them continuously against observed traffic.

Understand & Assure

Asset Inventory

The Chapter III register as a living object. Accountable owner and criticality are first-class columns because the regulation asks for them — and completeness against each field is tracked, since an incomplete register is a failed control.

Asset Inventory — concept view
Concept product view — not a production screenshot
Protect & Orchestrate

Events & Syslog

Native collection, retention and correlation — no second logging product, and no dependency on another vendor's asset data being right first. Correlation runs on the asset model, not on hostnames matching across log sources.

Events & Syslog — concept view
Concept product view — not a production screenshot
Protect & Orchestrate

Statutory Incident Response

CEA 2026 allows six hours to notify CSIRT-Power and CERT-In. The clock, the workflow and the submission all run inside the platform, assembled from context already held.

Statutory Incident Response — concept view
Concept product view — not a production screenshot
Questions

What operators askbefore they buy.

Straight answers, in the terms the regulation and the plant already use. Bring the rest to a walkthrough.

Does ASTRICS touch signalling?

No. ASTRICS builds the record from passively observed traffic and the sources the operator already has. Writes to control devices are not a permission it can be granted — that path does not exist in the product. Signalling safety cases are unaffected by observation.

We are a port with a private terminal operator. Whose estate is it?

The consequence sits with the port. ASTRICS gives the port authority its own record of what the concessionaire connected, who reaches it and what a failure would cost, independent of the operator's own tooling.

Where does traction power fit?

Traction substations and the catenary are power-system OT and appear in ASTRICS with the same single line diagram overlay as any switchyard. Where an operator's traction or port power reaches 50 MW, the CEA cyber security regulations apply in their own right.

Which obligations apply to a metro?

As of September 2026: the CERT-In Directions for incident reporting and logging, protected-system provisions where NCIIPC has identified the assets, and the operator's own contractual and safety-case requirements. ASTRICS tracks the CERT-In clocks as a live state and keeps the evidence for the rest.

See ASTRICS against your own environment.

Book a walkthrough with the ASTRICS team and bring one site's worth of questions.