Cyber readiness platform

The cyber readiness workspace for rail operations.

RailSecure puts phishing practice, incident drills, response playbooks, and live vulnerability monitoring in one workspace, built around the daily work of a rail security team.

09
Training modules

Practice, guidance, references, and live risk context in one workspace.

Live
NVD CVE feed

Filtered vulnerability monitoring with KEV-aware workflows.

Claude
AI assistance

Purpose-built flows for drills, triage, and plain-English explainers.

Local
Password tools

Generation and strength checks that stay in the browser.

Module index

Pick a line

09 modules
01Phishing LabGenerate rail-specific phishing simulations, score analyst reads against hidden red flags, and triage pasted emails.02Password StudioGenerate and score passwords entirely in the browser, so secrets never leave the device.03Incident LabRun realistic IT and OT incident narratives, then benchmark your first-response strategy against sector practice.04PlaybooksBuild six-phase response playbooks for specific scenarios and compare them against your own drafts.05Knowledge QuizFresh multiple-choice checks on hygiene, regulation, and OT awareness with instant scoring and coaching.06Compliance HubConnect NIS2, GDPR, CER, ISO 27001, and IEC 62443 to concrete controls, tooling, and awareness planning.07Vulnerability FeedSearch and filter live CVEs by severity, window, and KEV status, with plain-English AI explainers.08Reference LibraryA curated standards and guidance library, plus a scoped explainer for the parts people get stuck on.09Awareness WallReal transport-sector incidents, the patterns that repeat across them, and prompts for tabletop discussion.

Reporting clocks

The deadlines that shape an incident

  1. 24hNIS2 early warning

    For a significant incident, send the early warning within 24 hours of becoming aware so the CSIRT or competent authority gets an early signal.

  2. 72hNIS2 detailed notification

    Follow with the incident notification within 72 hours, including severity, impact, and any indicators of compromise available at that stage.

  3. 72hGDPR breach notification

    If a personal data breach is likely to create risk for individuals, notify the DPC without undue delay and, where feasible, within 72 hours of awareness.

  4. 1moFinal reporting and learning

    Under NIS2, expect a final report within one month after the incident notification, then feed the lessons back into controls, comms, and exercises.

In practice

A short loop, repeated often

See the incidents behind it
  1. 01

    Brief

    Ground the session in a real incident or a live CVE.

  2. 02

    Practice

    Run a simulation, drill, or quiz against it.

  3. 03

    Review

    Score the response and read the coaching notes.

  4. 04

    Improve

    Fold the gaps into playbooks and training plans.