Cybersecurity Evaluation and Testing

TRA’s services give organizations a holistic view of their cyber risk posture across digital and physical environments. Cyber tabletop exercises and hands on training test employee readiness and systems. TRA has experience with Operational Technology, ICS, and SCADA. These assessments identify gaps, validate safeguards, and support compliance with key cybersecurity standards.

Frequently Asked Questions

An evaluation typically reviews the agency’s cyber posture across information technology, operational technology, and the people and processes that connect them. This includes network architecture, access controls, incident response capability, vendor risk management, and physical security of critical equipment rooms. The goal is a realistic picture of where the agency is strong, where it is exposed, and what to fix first.

OT systems like SCADA, ICS, train control, signaling, and building management run on hardware and software that is often decades old and cannot tolerate the same patching cycles or reboots as office IT. A poorly timed scan or update can disrupt actual operations, so OT assessments require specialized tools and procedures. Effective OT security programs start with asset inventory and network segmentation, then layer on monitoring that does not interfere with real-time control systems.

A cyber tabletop walks leadership and technical staff through a realistic incident scenario, such as a ransomware attack on fare collection or a signaling system intrusion, in a discussion format. Participants practice decisions around containment, communications, regulator notification, and service continuity without taking systems offline. These exercises consistently reveal gaps in contact lists, authority chains, and assumptions about who does what during an incident.

Transit agencies commonly align with the NIST Cybersecurity Framework, TSA Security Directives for surface transportation, and CISA guidance on critical infrastructure. Rail agencies subject to TSA directives have specific requirements around cybersecurity coordinators, incident reporting, vulnerability assessments, and cybersecurity implementation plans. Agencies often use the NIST CSF as the umbrella and map regulatory obligations into that structure to avoid maintaining multiple parallel programs.

At minimum, once per year and after any major system change, merger, incident, or leadership transition. Threat actors, tooling, and regulatory expectations evolve quickly, so a three-year-old assessment is often badly out of date. Many agencies now combine an annual baseline assessment with quarterly vulnerability scans and continuous monitoring for the most sensitive systems.

How Can We Help You?

With a wealth of industry knowledge and experience, our experts have the skills to solve even the most complex problems. Let us know how TRA can help you meet your goals and improve results.

Contact Us