Environment
A regional passenger rail operator ran signaling, interlocking, and traffic management systems on a network that had grown organically alongside corporate IT for over a decade. Engineering workstations, maintenance laptops, and the signaling control network shared broadcast domains with office systems in several stations, a legacy of early cost-driven infrastructure decisions rather than a deliberate design.
Challenge
An internal audit flagged that a compromise starting on the corporate side had a plausible, largely unobstructed path toward signaling-adjacent systems. The operator could not simply shut down and rebuild the network -- trains needed to keep running, and any change window touching signaling infrastructure required safety sign-off and coordination with regulators.
Approach
The team used IEC 62443 zone and conduit modeling to formally separate the network into zones by function and trust level: corporate IT, station operational support, and the signaling/interlocking core. Each conduit between zones was documented with its purpose, the protocols it carried, and the specific control enforcing the boundary. Rather than a single cutover, segmentation was phased station by station, starting with the sites carrying the highest legacy risk, with rollback plans agreed before each change window. Security levels (SL-T) were assigned per zone based on realistic threat assumptions, and existing controls were assessed against that target to produce a prioritized gap list instead of a vague "segment everything" mandate.
Outcome
Within two maintenance cycles, the signaling core operated on an isolated zone with a small number of explicitly documented, monitored conduits rather than an open broadcast domain. The zone and conduit documentation also became the artifact regulators and internal safety reviewers referenced going forward, turning a one-time remediation into a maintained architectural baseline.