Solutions · Rail & Transportation

Which identities touched the railroad last night?

The adversaries probing critical infrastructure do not break in. They log in, with valid credentials, and wait. CINQUE learns what normal looks like for every identity across the enterprise, the yard, and the operations network.

Book a Discovery WorkshopGet the datasheet
The ledger a railroad never balances

Every other ledger gets reconciled.
Access does not.

Entitlement is asserted in your role model; behavior is the only proof. CINQUE reads all five control points together and shows where the two disagree.

PersonaEntitled, per RBACObserved, per CINQUEVariance
Wayside vendor techSignal telemetry onlyDispatch path reachedBOUNDARY CROSSED
Crew-ops service accountCrew boards, batch windowNew scopes, off-windowSCOPE DRIFT
Engineering contractorRead asset drawingsRead and bulk exportNEW EXPORT PATH
Maintenance AI agentRecommend work ordersRecommend and createFOUR-EYES BREAK
PTC back-office feedPosition reports, continuousPosition reports, continuousRECONCILED
Illustrative. Each variance sits below the triage threshold of the console that owns it. It exists only once all five control points are read together.

Detection tells you what happened. Context tells you whether it was supposed to happen.

Where railroads point it first

Four places railroads point it first.

The IT/OT boundary

Who, or what, is crossing from corporate toward dispatch, signaling, and PTC.

Vendors and contractors

What contracted identities actually touched, on the operations network and beyond it.

Non-human identities

Service accounts, Shadow AI, and the agents entering rail workflows, each baselined as a persona of its own.

Reporting readiness

When a risk is real, the full journey is attached: the story a 24-hour incident report needs.

Evidence for the people who ask

TSA asks whether the controls work.
Show how access is actually used.

The expectation
Who is asking
What CINQUE gives you
Access control and continuous monitoring and detection for critical cyber systems
TSA SD 1580/82-2022-01 series
Evidenced from observed behavior across all five control points.
Whether controls work, not whether they exist
Your annual assessment
Show how access is actually used, not how the diagram says it is.
A short, defensible risk picture
Your insurer and board
A short list of correlated risks with the full journey attached, Shadow AI and rogue service accounts included.

TSA's rail directives (SD 1580/82-2022-01 series) require segmentation, access control, continuous monitoring and detection, and patching, under a plan assessed annually.

Datasheet

CINQUE for Rail & Transportation security leaders

Which identities touched the railroad last night? The ledger a railroad never balances: access. Entitled versus observed across the enterprise, the yard, and the operations network.

What it covers
  • Who, or what, is crossing from corporate toward dispatch, signaling, and PTC
  • Vendors and contractors: what they actually touched on the operations network
  • Service accounts, Shadow AI, and agents in rail workflows, each baselined
  • The full journey attached when a risk is real: what a 24-hour incident report needs (TSA SD 1580/82-2022-01)

Your data, handled like we mean it. You choose the export: limited, point-in-time, analyzed in an isolated environment, and deleted after your readout. Ask us for the data-handling summary; we are a security company and we expect the question.

The CINQUE Discovery Workshop · complimentary

Bring your identity export.
Leave with your correlated risk picture.