Rail
Depots, stations and everything in between, spread across a network.
Rail operational OT is distributed by definition: a maintenance depot, a set of stations, and trackside facilities nobody is standing next to. The assurance question is how many of those places are in the model, and who can reach them.

- Depot systems, station systems and trackside facilities as canonical zones
- Contractor access modelled as what it is: a standing path into operational systems
- Passenger information and building services written down with their real protocols
- IEC 62443 and NIS2 answered from one estate

What this page covers, and what it deliberately does not.
This page is about rail OPERATIONAL OT: depots, stations, passenger information, building services and trackside facilities. It is not about signalling, interlocking or train protection. Those are regulated, certified domains with their own assurance regimes, and OTReady makes no claim about them. Nothing on this page, including the screenshots, should be read as covering a safety-critical signalling function.
Understand the environment
Distribution is the defining feature.
A rail infrastructure owner runs a small number of large sites and a large number of small ones. The depot has staff, a network and a maintenance system. A station has a control room, passenger information, lifts and escalators, and a building management system somebody installed at refurbishment. Trackside there are cabinets: power distribution monitoring, point heating, tunnel lighting.
Almost none of it was installed by the same supplier, and much of it is maintained by contractors who need a way in. That standing access is usually the first thing an assessment finds and the hardest thing to describe accurately, because it is several arrangements rather than one.
Availability matters in the ordinary way and in the public way: a station system failure is visible to passengers within minutes. The work that can be done is architectural and documentary, which is what OTReady is for.
- A few large sites and many small distributed ones
- Multiple contractors with standing access to different systems
- Public-facing systems whose failure is immediately visible
- Refurbishment-era equipment alongside recent installations
Terminology
What OTReady calls things here.
- Site
- A depot, a station, a trackside facility grouping. Physical only.
- Zone and Subzone
- Depot operations, depot plant, station systems, passenger information, building services, trackside power and lighting.
- Conduit
- The operational DMZ to depot plant; station systems to passenger information. The relationship carries the required Security Level.
- Communication Channel
- A contractor SSH session, a configuration transfer, a BACnet building services link, an arrivals feed. Encryption per channel, including "not recorded".
- OT Domain
- Depot operations, station systems, passenger information, facilities and power. The operator's own words.
OT Domains
Function across a network, not inside one building.
"Everything that is passenger information" spans several stations and sits inside zones that also contain other things. That is a functional question, and it is what OT Domains answer.
Domains are assigned on the object itself and are explicitly not a zone, not a Purdue level and not a Security Level. They give a distributed operator a way to ask about a function across the network without pretending the function is a security boundary.

How OTReady applies
The same chain, on a rail estate.
- OT context
- Architecture
- Risk
- Targets
- Assessments
- Findings & Evidence
- Remediation
- Reports
Trackside zones are often the last to be approved, and the assurance reading reflects that rather than smoothing it over.
Assurance
A distributed estate, read as it is.


Findings
Attributed to the depot, the station or the cabinet.
A finding names the object it concerns, which for a distributed operator is the difference between a programme that can be planned by site and a list that cannot.
Representative use cases
What rail operators bring to it.
- A maintenance depot
- Maintenance systems and depot plant as zones, with the contractor paths that reach them written down.
- Station systems
- Control room, passenger information and building services, each with its own target and its own conclusions.
- Distributed trackside facilities
- Power, lighting and remote cabinets as an estate rather than as a footnote.
- NIS2 as an essential entity
- Readiness assessed on the same estate the architecture work produced.
Not available today
- Dedicated rail acceleratorPlanned: Planned
Rail is CONFIGURABLE today with the standard OTReady objects, exactly as shown above. A dedicated rail accelerator, with a rail-specific starting structure and vocabulary, remains planned and does not exist. The illustrative configuration behind these screenshots is not that accelerator and must not be read as evidence of it.
Where the detail lives
OT architecture
Sites, Zones, Conduits and the Channels inside them.
OT Domains
Functional context across a distributed estate.
Governance
Scoped access for contractors and reviewers.
See OTReady against your own rail estate.
A working session on your depot, your stations and your distributed operational systems.