WICCON 2025

WICCON 2025

Pentesting the rails - security of metro and trams
2025-10-31 , Main Stage

Penetration testing of enterprise networks has become routine, but how can we safely assess the security of vehicles used by millions every day? In this talk, I’ll share insights from real-world penetration testing projects I have done on a metro & a tram. We’ll cover approaches to conducting security testing in safety critical transportation environments, highlight key findings and lessons learned. Finally, I’ll present practical steps the industry can take to strengthen the cybersecurity of the rail sector in line with applicable standards and reference architectures.

Dominika is one of the Senior Security Specialists at Bureau Veritas Cybersecurity with 10 years of experience in industrial cybersecurity. Her experience spans from pentesting critical infrastructure (like manufacturing, energy, pharma, terminals, trams) to implementing concrete solutions (like ICS monitoring, or network segmentation). She also enjoys occasional hacking of IoT devices and some good old soldering projects. Her background is in Security and Network Engineering.