Transport

The NIS2 directive highlights the importance of bolstering cybersecurity in the transport sector to protect critical infrastructure across aviation, maritime, rail, and road transport. 

Transport operators, manufacturers, suppliers, and the broader transport ecosystem are recognized as highly critical due to their significance in the EU’s economy and stability. By addressing the evolving cyber threat landscape, NIS2 aims to ensure the resilience and safety of vital transport services within the EU.

ENISA published the first report on the cybersecurity threat landscape of the transport sector in 2023. The ENISA Transport Threat Landscape report brought new insights into the reality of the transport sector by mapping and studying cyber incidents from January 2021 to October 2022. The 2024 ENISA threat landscape highlights the increasing number of incidents faced by the EU transport, which was the 2nd most targeted sector.

The Transport Sector plays a key role in the EU economy and society, accounting for a large segment of Europe’s overall freight and passenger transport. The sector has been steadily undergoing a digital transformation with the introduction of innovative solutions based on ICT, the convergence between IT and OT, and the increasing numbers of interconnections with external and multimodal systems. The cyber risk profile of the sector has evolved, as shown by the increase in cyberattacks against European transport infrastructure such as airports, ports, railways, shipping companies, and more. This change highlights the need for cybersecurity to be addressed in more detail. ENISA works closely with the European Commission, ERA, EMSA, EASA and National competent authorities towards this direction.

Railways 

The Railway ecosystem comprises of the railway undertakings (RU), in charge of providing services for the transport of goods and/or passengers by rail, and the infrastructure managers (IM), in charge of establishing, managing and maintaining railway infrastructure and fixed installations, including traffic management, control-command and signalling, but also station operation and train power supply. Both are recognized as essential by the NIS2 Directive.

In 2023, ENISA signed a Memorandum of understanding with the EU agency for Railways to strengthen cooperation and information exchange. ENISA supports cybersecurity capabilities in the Railway Sector through guidance and recommendations, actively participating in the railway community by: 

  • Issuing guidance and recommendations;
  • Participating in discussions with the railway community on regulatory matters;
  • Providing situational awareness information to national competent authorities; 
  • Contributing to the standardisation of activities;
  • Organising physical and virtual events; and
  • Raising awareness for the sector (#CyberOnTrack)

Maritime

Port authorities, terminal operators, other entities operating within ports, shipping companies, classification societies, shipbuilding companies, and more, create the EU maritime ecosystem. Their individual cybersecurity posture is key for the Maritime Sector. As part of the transport sector, maritime entities are recognized as essential by the NIS2 Directive.
The EU Agency for Cybersecurity plays its role in the continuous process of strengthening the cybersecurity of the EU Maritime Sector by:

  • Addressing key issues and recommendations;
  • Supporting the development and implementation of the relevant policy and regulatory framework;
  • Facilitating information sharing and the exchange of good practices between maritime stakeholders;
  • Providing situational awareness information to national competent authorities; and
  • Participating in physical and virtual events.

Aviation 

ENISA has been working on aviation cybersecurity since 2010, aiming at enhancing the security and resilience of air transport in Europe together with all relevant key stakeholders and sectorial agencies (e.g. EASA, Eurocontrol). Within the scope of the NIS Directive we find air carriers, airport managing bodies, core airports and entities operating ancillary installations contained within airports and traffic management control operators providing air traffic control (ATC) services, which are recognized as essential by the NIS2 Directive.

ENISA actively works towards increasing the cybersecurity capabilities and the overall cyber resilience of the Aviation Sector by:

  • Engaging in structured collaboration with EASA and other sectorial stakeholders;
  • Participating in the European Strategic Cooperation Platform;
  • Contributing with technical advice on regulatory matters, e.g. Commission Implementing Regulation (EU) 2023/203; and
  • Providing situational awareness information to national competent authorities.