Subway/tramway control system security for Alstom

Sogeti helped Alstom build a subway/tramway control security system by developing architecture, conduct code analysis and conducting risk assessments.


The client wanted Sogeti to develop architecture, conduct code analysis and risk assessment their train control systems. They also wanted recommendations for improving the security level, according to the critical system requirements and define the security targets.


Sogeti conducted risk analysis on a complete automatic train solution : traffic monitoring, lines management, trackside signalling and on board train movement control through segmentation of the critical parts of the system, E-bios risk analysis, security objectives setting, evaluation of the compliance with industrial standards and roadmap to reach a cyber-security level coherent with the safety level requirements.

The team also recommended architecture changes for embedded products in the train and reviewed codes and provided recommendations on application framework for embedded devices and defined security target for CC evaluation of the software components embedded in the locomotive


Security assessment reports were released, which provided a list of security recommendations (architecture guidelines, coding rules, process organzation …) to be adapted by the client.

todo todo
  • Didier Appell
    Didier Appell
    Cyber Security Offering manager
    +33 (0)4 76 39 94 08
About Alstom

Alstom is a French multinational company operating in the worldwide rail transport markets, active in the fields of passenger transportation, signalling and locomotives, with products including the AGV, TGV, Eurostar, and Pendolino high-speed trains, in addition to suburban, regional and metro trains, and Citadistrams.