REVIEW 3 major objections 4 minor 6 references
Cybersecurity in Transportation Systems: Policies and Technology Directions
T0 review · 3 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read A survey of transportation cybersecurity argues that digitalization has expanded the attack surface across aviation, road, rail, and maritime systems, and that only coordinated policy and hybrid technology measures can secure them.
desk verdict Competent survey of transportation cybersecurity; urgency overreaches on weak statistics, but worth refereeing as a review. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The paper is organized around a two-part mapping presented in Table 1: identified causes of rising vulnerability are matched to programmatic and policy strategies (standards, testing, certification, insurance, workforce, reporting) and to emerging-technology combinations, all framed by the confidentiality, integrity, and availability (CIA) requirements of transportation systems. The rapid adoption of internet-of-things devices and connected autonomous vehicles serves as the driver that expands the attack surface; the hybrid technology pairings are proposed as the counterweight, with cross-pollination of technologies argued to be more effective than any single tool.
What would settle it
A comprehensive, mode-by-mode incident database with consistent definitions and denominators would settle the claim: if incident rates per vehicle-mile, per port, or per connected device were flat or declining from 2017 to 2023, the 'growing threat landscape' premise would be falsified.
Extended reading notes
Core claim
The paper's central claim is that no single technology or agency can secure modern transportation: the expansion of cyberspace across modes has created a shared vulnerability that must be met with both institutional collaboration and hybrid technological defenses. The paper catalogs why vulnerabilities are increasing—connectivity and automation, information/operational technology convergence with legacy systems, supply chains, human factors, and software bugs—and maps those causes to programmatic/policy strategies and to emerging-technology combinations. Its stated conclusion is that the threat landscape in transportation is growing in complexity and there is an urgent need for robust and collaborative cybersecurity measures to secure digital infrastructure.
Load-bearing premise
The load-bearing premise is that the cited statistics and incident anecdotes accurately represent a growing threat landscape; these figures come from industry reports, media articles, and a book chapter rather than a defined, peer-reviewed incident dataset, and the paper does not define what counts as a cyber incident or provide the denominators needed to compare rates over time.
Editorial extensions
If this is right
- National cybersecurity standards and certification schemes would raise the security floor across the transportation supply chain, making vendors accountable through compliance.
- Cyber liability insurance would shift part of the financial burden of inevitable incidents to insurers and could incentivize companies to adopt the standards and testing the paper recommends.
- A national, transparent database of transportation cyber incidents would give industry and researchers the data needed to prioritize defenses and measure whether threats are actually growing.
- Hybrid defenses—zero trust with post-quantum cryptography, confidential computing with zero trust, and blockchain with cryptography—would protect data in transit, at rest, and in use, rather than securing only one layer.
- Workforce and training programs focused on cybersecurity literacy would directly reduce the human-error factor that the paper identifies as a major vulnerability.
Reading between the lines
- The paper does not quantify a denominator for its incident statistics; a testable extension would be to build the very database it proposes and compare per-mode incident rates against traffic or connection volumes over time.
- If cyber liability insurers begin requiring the standards and testing that the paper lists, insurance pricing could become a de facto enforcement mechanism for transportation cybersecurity policy.
- The hybrid-technology claims are plausible but largely untested in transportation; a concrete next step would be pilot deployments of zero trust plus confidential computing in a traffic-management center or a port, measuring attacker dwell time and operational uptime against current baselines.
- The paper's mode-agnostic approach suggests that lessons from maritime and aviation attacks, such as ship-tracking spoofing and airline supply-chain ransomware, may transfer directly to the less regulated road sector, where adoption of similar reporting and testing practices could occur faster.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper is a literature synthesis / position paper on cybersecurity for multimodal transportation systems. It argues that digitalization and interconnectivity have increased cyber vulnerabilities across aviation, road, rail, and maritime modes, and it presents two clusters of strategies: programmatic/policy measures (national standards, testing, certification, insurance, workforce development, incident reporting) and emerging-technology directions (blockchain with cryptography, zero trust architecture with post-quantum cryptography, confidential computing with zero trust, hybrid hardware-software security, satellite-based quantum communication, and the quantum internet). The central claim, stated in the Conclusions, is that the growing complexity of the transportation threat landscape creates an urgent need for robust and collaborative cybersecurity measures, and that hybrid/integrated technological approaches are particularly promising.
Significance. If the urgency premise is accepted, the paper offers a useful and clearly organized taxonomy of policy and technology responses, with Table 1 providing a concise overview. Its emphasis on cross-pollination of emerging technologies is a reasonable and somewhat original framing for a survey, and the paper collects relevant recent references (e.g., NIST SP 800-171, ISO/SAE 21434, recent ZTA/CAV and QKD work). The paper is also transparent about its use of AI editing tools. However, the contribution is synthetic rather than empirical: it offers no new data, no systematic incident analysis, and no technical evaluation of the proposed hybrid approaches. Its value therefore depends entirely on the reliability of the cited evidence for the threat landscape and on the plausibility of the asserted technology benefits.
major comments (3)
- [Introduction and 'Why Cyber Vulnerabilities Are Increasing'] The load-bearing empirical premise of the paper is that the transportation cyber threat landscape is growing rapidly, but the key quantitative support is not verifiable. Specifically, the 186% weekly ransomware increase (ref 4), the 900% maritime attack rise from 2017 to 2021 (ref 12), and the 90% cloud-breach-employee-error figure (ref 13) come from industry guides, IAPH guidelines, and a book chapter, respectively, and none provides a definition of what counts as a cyber incident, a denominator, or the relevant time window. As written, these figures could reflect enhanced reporting or vendor-specific telemetry rather than a true increase in attacks. Since the conclusion's 'urgent need' is justified by exactly this growth, the authors should either replace these with peer-reviewed incident data (e.g., from academic maritime or transportation incident databases) or explicitly re-frame them as illustrative, with caveats about their provenance and comparability.
- [Cross-Pollination of Emerging Technology Domains (including Table 1)] The paper asserts that hybrid approaches 'would benefit more' and 'can significantly enhance' cybersecurity (e.g., ZTA+PQC, confidential computing+ZTA, hardware-software co-design), but it provides no empirical or simulation evidence that these combined approaches are effective for transportation systems. The cited works (refs 57-65) address individual technologies in isolation, often in non-transportation domains, and the paper itself acknowledges that 'adaptation feasibility, and operational assessment of these technologies’ cross-pollination for modern transportation systems remain unexplored.' Because Table 1 presents these as recommended strategies with concrete benefits, the authors should temper the claims to match the evidence: either label these as open research directions requiring validation, or add proof-of-concept results.
- [Incident evidence and methodology] The paper's incident examples (§1, §2) are selected anecdotes from media and industry reports, with no systematic sampling or incident definition. This is acceptable for a narrative survey, but the paper could strengthen the argument by referencing the existing incident databases it later mentions (e.g., CSIS, EuRepoC, CIRAS, Maritime Cyber Attack Database) to demonstrate that the examples are representative rather than cherry-picked. Without such grounding, the 'growing threat landscape' claim rests on an unexamined sample.
minor comments (4)
- [Table 1 and related text] In Table 1, the row 'Better Reporting of Cyber Incidents' lists 'Cybersecurity Incident Reporting and Analysis System' but the text (p. 9) refers to ENISA's CIRAS; the acronym should be introduced consistently, and the reference to the University of Maryland's Cyber Events Database uses 'Center for International and Security Studies at Maryland' twice.
- [Conclusions] The Conclusions refer to 'satellite-based quantum computing' whereas the body discusses 'satellite-based quantum communication' (QC); this is a substantive terminology mismatch that should be corrected to avoid confusion.
- [References] Reference 84 is a company blog post used to support a technical claim about blockchain security; a peer-reviewed source (e.g., the blockchain survey in ref 83) would be more appropriate. Also, reference 48's URL contains a space ('maritime-cyber attack-database') and should be repaired.
- [Minor prose issues] The paper states 'In June 2023, the Oregon Department of Motor Vehicles was affected by a global hack targeting the MOVEit file transfer system' and later 'Just this year, a software bug in a CrowdStrike update caused major disruptions' (p. 5); the latter uses an unclear temporal anchor—define the year. Also, the AI editing acknowledgment says 'Chat GPT 3.5 and 4-o'—use the standard spelling '4o'.
Circularity Check
No circular reasoning: the urgency claim is a synthesis of external incident reports and statistics, and the paper's two self-citations are illustrative rather than load-bearing.
full rationale
This paper is a literature review and policy/technology survey; it contains no predictive model, no fitted parameters, and no derivation chain whose output could reduce to its input. The central claim that the transportation threat landscape is growing and requires collaborative cybersecurity measures is supported by external incident anecdotes and industry statistics, not by a quantity computed from those same statistics. None of the seven circularity patterns applies: there is no self-definitional claim, no fitted input called a prediction, no uniqueness theorem imported from the authors' prior work, and no ansatz smuggled in via citation. The two self-citations (refs 21 and 30) are used only as illustrative examples—a list of possible CAV communication attacks and the existence of hardware trojan threats—and neither one is needed to establish the paper's main conclusion. Even the weakness of the supporting statistics (e.g., the 186% ransomware surge, 900% maritime attack rise, and 90% employee-error figure) is an evidence-quality and correctness concern, not a circularity: the conclusion would not be true by construction if those figures were revised. Score 1 reflects the presence of two minor, non-load-bearing self-citations in an otherwise self-contained review, with no circular reasoning found.
Assumptions & free parameters
assumptions (4)
- domain assumption Cited industry statistics are accurate and comparable across transportation modes.
- domain assumption The set of illustrative incidents is representative enough to support the claim of a growing threat landscape.
- domain assumption The described emerging technologies are sufficiently mature and applicable to transportation contexts to justify the recommendation to combine them.
- domain assumption NIST, ISO/IEC, ISO/SAE, and OWASP frameworks apply directly to transportation OT/IT systems across all modes.
Cite this review
Pith. "Pith review of Cybersecurity in Transportation Systems: Policies and Technology Directions." pith.science (2026). https://pith.science/paper/3DNFDBVU
@misc{pith2026250105356,
author = {Pith},
title = {Pith review of: Cybersecurity in Transportation Systems: Policies and Technology Directions},
year = {2026},
howpublished = {\url{https://pith.science/paper/3DNFDBVU}},
note = {Machine review of arXiv:2501.05356}
}
read the original abstract
The transportation industry is experiencing vast digitalization as a plethora of technologies are being implemented to improve efficiency, functionality, and safety. Although technological advancements bring many benefits to transportation, integrating cyberspace across transportation sectors has introduced new and deliberate cyber threats. In the past, public agencies assumed digital infrastructure was secured since its vulnerabilities were unknown to adversaries. However, with the expansion of cyberspace, this assumption has become invalid. With the rapid advancement of wireless technologies, transportation systems are increasingly interconnected with both transportation and non-transportation networks in an internet-of-things ecosystem, expanding cyberspace in transportation and increasing threats and vulnerabilities. This study investigates some prominent reasons for the increase in cyber vulnerabilities in transportation. In addition, this study presents various collaborative strategies among stakeholders that could help improve cybersecurity in the transportation industry. These strategies address programmatic and policy aspects and suggest avenues for technological research and development. The latter highlights opportunities for future research to enhance the cybersecurity of transportation systems and infrastructure by leveraging hybrid approaches and emerging technologies.
Reference graph
Works this paper leans on
-
[16]
Ransomware Attack Hits Rail Freight Operator OmniTRAX
Tabak, N. Ransomware Attack Hits Rail Freight Operator OmniTRAX. FreightWaves. https://www.freightwaves.com/news/ransomware-attack-hits-short-line-rail-operator-omnitrax. Accessed Jul. 20, 2024. 17. Osorio, N. Russians in Novosibirsk Forced To Pound Pavements As Team OneFist Paralyzes Traffic. International Business Times. https://www.ibtimes.com/russians...
-
[29]
Afenyo, M., and L. D. Caesar. Maritime Cybersecurity Threats: Gaps and Directions for Future Research. Ocean & Coastal Management, Vol. 236, 2023, p. 106493. https://doi.org/10.1016/j.ocecoaman.2023.106493. 30. Tine, J. M., S.-N. Puspa, R. Majumdar, G. Comert, M. Chowdhury, and Y. Lao. Threats of Trojan Incursion in Transportation Hardware. Presented at t...
-
[45]
The 5 Best Cyber Insurance Companies of 2024
Tretina, K. The 5 Best Cyber Insurance Companies of 2024. Investopedia. https://www.investopedia.com/best-cyber-insurance-5069694. Accessed May 27, 2024. 46. USDOT ITS Research - ITS Cybersecurity Workforce Development. https://www.its.dot.gov/research_areas/cybersecurity/workforce.htm. Accessed May 27, 2024. 47. ENISA. Incident Reporting. CIRAS. https://...
-
[58]
Shipman, M. E., N. Millwater, K. Owens, and S. Smith. A Zero Trust Architecture for Automotive Networks. 2024. https://doi.org/10.4271/2024-01-2793. 59. Malina, L., P. Dzurenda, S. Ricci, J. Hajny, G. Srivastava, R. Matulevičius, A.-A. O. Affia, M. Laurent, N. H. Sultan, and Q. Tang. Post-Quantum Era Privacy Protection for Intelligent Infrastructures. IEE...
arXiv 2024
-
[71]
Valivarthi, R., Davis, S.I., Peña, C., Xie, S., Lauk, N., Narváez, L., Allmaras, J.P., Beyer, A.D., Gim, Y., Hussein, M. and Iskander, G., 2020. Teleportation systems toward a quantum internet. PRX Quantum, 1(2), p.020317. 72. Cacciapuoti, A.S., Caleffi, M., Tafuri, F., Cataliotti, F.S., Gherardini, S. and Bianchi, G., 2019. Quantum internet: Networking c...
-
[86]
Chou, H.F., Ha, V.N., Al-Hraishawi, H., Garces-Socarras, L.M., Gonzalez-Rios, J.L., Merlano-Duncan, J.C. and Chatzinotas, S., Satellite-based Quantum Network: Security and Challenges over Atmospheric Channel (No. arXiv: 2308.00011)
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.