What's Happening?
Cylus, a global leader in rail cybersecurity, has officially launched Cylus.ai, an intelligence layer designed to enhance rail cybersecurity. This new platform aims to provide rail-specific security expertise to security teams, working in conjunction
with existing tools to help operators interpret threats and decide on appropriate responses. Cylus.ai is developed to address the increasing connectivity of train systems, the rapid pace of AI-driven attacks, and the limited pool of security professionals with specialized rail knowledge, all while regulatory pressures continue to mount. The company also announced the appointment of three prominent rail and transit leaders to its Advisory Board: Nuria Fernández, former Administrator of the U.S. Federal Transit Administration (FTA); Josef Doppelbauer, former Executive Director of the European Union Agency for Railways; and Mario Péloquin, former President & CEO of VIA Rail Canada. Nuria Fernández brings over 35 years of experience in leading major transit systems and overseeing federal programs that fund and shape public transit in the U.S.
Why It's Important?
The launch of Cylus.ai and the addition of key figures like Nuria Fernández to its Advisory Board signify a critical step in bolstering the cybersecurity infrastructure of the U.S. and global rail industry. The increasing reliance on connected systems in rail operations makes them vulnerable to cyber threats, which could have severe consequences for public safety, economic stability, and national security. Cylus.ai's focus on providing rail-specific expertise is crucial because generic security tools often fall short in addressing the unique operational technology environments of railways. Nuria Fernández's extensive experience in U.S. public transit, including her role at the FTA, provides invaluable insight into the regulatory landscape, operational challenges, and policy needs of American transit systems. Her involvement suggests a strong potential for Cylus.ai to align with U.S. federal guidelines and address the specific cybersecurity concerns of U.S. rail operators, ultimately enhancing the resilience of the nation's transportation networks against sophisticated cyberattacks.
What's Next?
Cylus will be showcasing Cylus.ai and CylusOne, its flagship platform, at InnoTrans 2026, where its rail cybersecurity experts will provide live demonstrations. This event will serve as a key opportunity for rail operators and industry stakeholders to learn more about the new technology and its applications. The integration of Cylus.ai into existing security stacks will likely be a phased process for many rail operators, requiring training and adaptation. The expertise brought by the new Advisory Board members, particularly Nuria Fernández, is expected to guide Cylus in developing solutions that are highly relevant and effective for the U.S. market and its regulatory environment. Future developments may include further collaborations with U.S. transit authorities and the potential for Cylus.ai to become a standard component in the cybersecurity strategies of American rail and transit systems, influencing policy and investment in this critical area.
Beyond the Headlines
The introduction of Cylus.ai highlights a broader trend in critical infrastructure protection: the necessity of specialized cybersecurity solutions tailored to unique operational environments. The rail industry, with its complex interplay of legacy systems and modern digital technologies, presents distinct challenges that generic IT security measures cannot fully address. This development underscores the growing recognition that cybersecurity is not merely an IT problem but a fundamental operational and safety concern for sectors like transportation. The involvement of high-profile former government officials like Nuria Fernández also signals a convergence of public policy, private innovation, and industry expertise in addressing these complex threats. This collaborative approach is essential for developing robust defenses against cyber adversaries who are increasingly sophisticated and often state-sponsored, aiming to disrupt critical services. The long-term implications include a potential shift towards more integrated and intelligent cybersecurity frameworks across all critical U.S. infrastructure sectors.













