
Quantifying the cost of cyber-attacks to the UK economy is a challenging exercise. There is no single consensus methodology, and impacts vary widely depending on the attack vector, point of vulnerability and the attacker’s objectives.
For this study, we worked with Department for Transport (DfT) and Network Rail to model a plausible systemic attack scenario: a cyber-attack on the train communications system leading to rapid system degradation and ultimately a total loss of service across the rail network.
Our modelling estimates a total economic impact of approximately £1.8 billion for one week of disruption, including:
(See full breakdown in the DSIT report.)
Systemic disruption would require several conditions to align — making such an event rare under current circumstances. Strong security controls and national policies have helped reduce systemic risk. However, cyber maturity remains uneven across the rail ecosystem, and a compromise in one organisation could still cascade to others.
To assess this, the DSIT study used the European Systemic Risk Board (ESRB) framework, which looks at four stages:
Based on this approach, a systemic event would need multiple amplifiers to line up — but uneven resilience and geopolitical uncertainty mean the risk cannot be ignored. Recent UK and European incidents have mostly hit ticketing systems, causing isolated financial impacts rather than network-wide outages. In contrast, in conflict zones such as Ukraine and Russia, rail operators have been targeted by state-sponsored groups and hacktivists — showing how context can change the scale of impact.
The DSIT study highlights two critical points:
For rail operators, this means understanding where your organisation sits in the risk chain and how a local incident could propagate. That insight is critical for prioritising investment and resilience measures.
Our DSIT report sets out the potential economic impact of a systemic cyber incident in the rail sector and explains how disruption could spread through critical infrastructure. It provides a useful reference point for organisations assessing their own resilience.
What stands out is the scale and complexity of the risk. A single systemic event could cost billions and disrupt essential services — and while rare, the conditions that enable such events can change quickly.
To understand the financial exposure specific to your own organisation, we encourage you to explore our Cyber Risk Quantification (CRQ) Accelerator, which uses our Cyber Risk Insights (CRI) platform to generate clear, actionable financial insights in just six weeks.
Reach out to the team for a free demo, or if you want support with more confident, data‑driven cyber risk decision‑making.
For those interested in the full research, the DSIT report is available on GOV.UK.


