Urban public transport operator
Primary Italian publicly-controlled urban public transport operator
Continuity and security of mobility for millions of passengers
An operator responsible for managing metro, tram and surface networks serving a large urban area. It runs critical infrastructure in which operational control systems and traditional IT networks operate in convergence, multiplying the potential attack surface towards the command-and-control systems.
Sector
Local public transport
Revenue
Consolidated financials of regional significance
Headquarters
Large Italian urban area
The industry scenario
According to ACN, the segregation of IT/OT networks through Zero Trust architectures is a fundamental control for reducing attack vectors in critical public-transport infrastructure.
National Cybersecurity Agency (ACN) — Report on the Cyber Security of Critical Infrastructure · 2025
Challenge
Protecting the operational control systems
According to the Cybersecurity & Data Protection Observatory of the Politecnico di Milano, in 2025 62% of Italian public-transport operators recorded at least one unauthorised access attempt to their operational control infrastructure, a 34% increase on the previous year. The convergence between IT and OT networks, accelerated by the digitalisation of ticketing and fleet-monitoring systems, has turned transport systems into critical targets for malicious actors, multiplying the attack vectors towards the infrastructure that ensures service continuity.
Areas of intervention
The operator faced a complex situation: operational control infrastructure distributed across multiple sites, progressively connected to the corporate IT networks for monitoring purposes and integration with planning systems. This integration, although necessary, had significantly widened the attack surface towards the critical systems that run metro, tram and surface vehicles, without introducing adequate isolation mechanisms.
Isolation of OT domains
The absence of clear network segmentation between the operational control systems and the traditional IT networks, with a risk of lateral propagation of incidents from one zone to another.
Visibility and control of interconnections
The lack of continuous, proactive monitoring of the communication flows between the IT and OT domains, making it difficult to detect anomalies and unauthorised behaviour.
Security governance
The need to align protection practices with the regulatory standards for critical infrastructure (ACN, NIS2) and to maintain constant oversight of the critical interconnections.
Cross-domain access management
The need to implement granular access-control logic on the interfaces between IT and OT systems, reducing the risk of unauthorised lateral movement.
Solutions
A security-by-design IT/OT segregation architecture
The operator implemented a model that isolates the operational control domains from the traditional IT networks, built on three integrated components: network-zone design with asset management and device hardening, oversight of the events on the IT/OT interfaces and access control based on Zero Trust logic, governed by a defined systemic OT risk analysis metric.
Services activated and technologies
Network infrastructure
IT/OT segregation and zoning, asset management and hardening
Retelit designed and implemented a logical and physical segmentation of the networks, defining security boundaries between the operational control systems and the IT networks. The interconnections between domains were reduced to the necessary minimum and overseen through controlled gateways, reducing the horizontal propagation of cyber incidents. The scope also covers asset management of the network equipment and OT devices — discovery, classification and an up-to-date inventory of configurations and firmware — together with hardening activities on devices, protocols and exposed services, to remove unnecessary configurations and reduce known vulnerabilities.
Industrial Control Systems (ICS)
Oversight of the IT/OT interfaces and ICS evolution on the pilot sites
The events generated by the gateways and by the boundary zones between the IT and OT domains are collected in centralised logs, with automated alerts and a defined incident-response procedure that contains events within the intended network boundaries; security-data management is compliant with the ISO 27001 standard. For the pilot sites, the adoption of a dedicated Industrial Control System (ICS) is under assessment, extending control to the supervision of field devices and processes.
Governance and compliance
Zero Trust on the interconnections and systemic OT risk measurement
Access between the IT and OT domains is subject to strong authentication, granular authorisation and continuous verification of endpoint integrity. The architecture ensures full visibility over who accesses which critical resources, aligning with the regulatory requirements for critical infrastructure (National Cybersecurity Agency, NIS2). The evolution of the OT implementation is governed by a defined systemic OT risk analysis metric, which measures the exposure of the control domains over time, verifies their maturity level and makes it possible to prioritise subsequent actions.
Results
A reduced attack surface and operational resilience
The IT/OT segregation architecture contained the risk of cyber incidents propagating to the urban-mobility control systems, preserving service continuity.
Isolation of the operational control domains from the traditional IT networks, eliminating direct attack paths towards the critical OT assets.
Containment of security events within defined network boundaries, reducing the potential blast radius of an incident and easing the operational response.
Continuous visibility over the IT/OT interconnections through proactive monitoring and centralised event management, in line with ISO 27001 standards.
Alignment of security governance with the regulatory frameworks for critical infrastructure, with oversight of the interfaces based on Zero Trust logic.
An approach that can be replicated in your sector
IT/OT segregation for critical public-transport infrastructure
Contact Retelit to assess how to apply this security-by-design architecture to your operational control networks.
Insights from our Magazine.
Articles, white papers and analyses from our magazine.