Line status · Clear · Threat sharing active

Green signal for the
cyber resilience of
European railways.

Rail-ISAC is the Information Sharing & Analysis Center for European rail — a confidential community where operators clear the track ahead of emerging cyber threats, share intelligence, and keep the network moving safely.

Who we are

A closed track for trusted operators — wide open for intelligence.

Cyber threats to rail don't respect borders, and neither should the defence. Rail-ISAC gives European rail organisations a secure, confidential space to exchange what matters most: real signal on real threats, verified by the people who run the trains.

01 / TRUST

Trusted Community

A confidential environment restricted to eligible members. What is shared inside, stays inside — protected by clear rules of engagement and mutual trust.

02 / INTEL

Cyber Threat Intelligence

Production and sharing of actionable threat intelligence — contextualised for rail — so members can anticipate, detect, and reduce operational cyber risk.

03 / EXPERTS

Built by Experts

A network of CSIRTs, SOCs, threat analysts and incident responders from across European rail — built by experts, built for experts.

04 / EXCHANGE

Threat Exchange

Members learn from one another — how peers detect, respond to and solve the same problems. Shared experience turns one team's lesson into everyone's advantage.

The Expert Network

Every stop on the line is a defender.

Rail-ISAC links the defenders of European rail into one coordinated line — each station a discipline, pooling expertise that no single operator holds alone.

  • CSIRTs
  • SOC Teams
  • Threat Analysts
  • Incident Responders
  • Security Experts & OT Specialists
Membership

Boarding reserved for those who run the rails.

Eligibility · Restricted
European Rail Operators

Organisations operating rail infrastructure and services across Europe.

European Rail Undertakings

Railway undertakings delivering passenger and freight services within the EU.

Membership is verified and confidential. Complete the request — it opens a pre-filled email to our team, who will guide you through onboarding.

⚠ Please send the email from your work email address — applications from private addresses cannot be verified.

Join the community

Get in touch

Signal us — let's keep
the network clear.

Questions, membership applications, or collaboration — the fastest way to reach us is one message away.

[ enable JavaScript to view ]

Terms of Reference & TLP Sharing Policy

Introduction

This document outlines the Terms of Reference for the European Railways Information Sharing and Analysis Center (Rail-ISAC.EU), aimed at enhancing cybersecurity resilience across European Railways. Rail-ISAC.EU is independent and was built by the rail sector, for the rail sector without involvement of any third-party entities or government bodies. This setup allows critical security information and data to be shared openly among members, fostering greater trust and lowering the threshold for sharing sensitive information.

Objectives

Scope

Membership

Access Policies

Governance & Liability

The Rail-ISAC will be governed by an internal committee led by Deutsche Bahn. The committee will be responsible for setting policies, overseeing activities and ensuring adherence to the ToR.

As operator of the Rail-ISAC, DB strives to provide the platform to the best of their knowledge and in compliance with current IT security standards. However, DB doesn't accept any liability for incidents, damages, or losses that may arise directly or indirectly from the use of this platform.

By using this forum, you acknowledge and agree that the platform is provided "as is," without warranties of any kind, either express or implied.

Information Sharing Protocol

Information sharing will be conducted through the forum or the threat intelligence system and in accordance with established TLP protocols to ensure confidentiality and integrity.

Confidentiality and Data Protection

Meetings and Communication

Review and Amendments

These Terms of Reference will be reviewed annually.