TCMS cybersecurity assessment and approval
Customer: Newag, Poland
Project tasks
- Supporting the customer throughout the V-model with a focus on cybersecurity
-
Assessing cybersecurity requirements relevant to the TCMS in accordance with IEC 62443 / TS 50701
- Conducting high-level and detailed risk analyses, threat matrix assessments and CbC analyses
- Defining security-related application conditions (SecRACs)
- Supporting the assessment and approval process
Our approach
The cybersecurity assessment followed the methodology of IEC 62443 / TS 50701 and combined technical analysis, structured documentation and verification throughout the entire V-model. This ensured that cybersecurity aspects were integrated early into development, assessment and compliance activities.
The work included high-level and detailed risk analyses, threat matrix assessments, CbC analyses, SecRACs, and the development of the TCMS Technical Security Concept, covering network architecture, firewall configurations and system settings. In addition, incorporation of outcomes from external penetration tests have into the security concept have been made.
PROSE prepared the Security Case and supported the customer throughout the assessment and approval process. All analysis and evidence activities were consistently linked and documented in a traceable manner.
Customer benefit
NEWAG received structured support aligned with IEC 62443 / TS 50701 to address cybersecurity requirements during vehicle development and approval. Security risks could be identified and assessed at an early stage and addressed through appropriate technical and organisational measures.
The independent technical assessment also strengthened the evidence required for safety and cybersecurity compliance. By combining railway-system expertise with cybersecurity competence, PROSE helped ensure a consistent and traceable link between development, verification and approval activities.











