Cybersecurity skills, emerging threats and critical assets in transport and manufacturing
Read the whole report here: https://cyrus-project.eu/wp-content/uploads/2025/05/CYRUS-D1.1-Report-on-the-cybersecurity-skills-and-needs.pdf
The digital transformation of Europe’s transport and manufacturing sectors is accelerating. Smart factories, connected vehicles, predictive maintenance systems, cloud-based logistics platforms and industrial IoT ecosystems are driving efficiency and competitiveness. At the same time, this transformation significantly expands the cyber-attack surface.
Within the CYRUS project, we assessed:
- The current cybersecurity skills, competences and training needs in the transport and manufacturing (TM) sectors
- The future cyber-threat scenarios likely to impact these industries
- The workforce profiles and assets most at risk
The results of this research phase provide a solid evidence base for the design of CYRUS training content and capacity-building activities.
A targeted approach to sector-specific cybersecurity
Many European studies analyse cybersecurity readiness across SMEs in general, grouping different industries together after data collection. CYRUS adopted a different strategy. Rather than offering a horizontal overview, the project focused vertically on two complex and strategically critical sectors:
- Transport (including automotive, railways, aviation, logistics, and mobility services)
- Manufacturing (including industrial production, smart factories, and supply chain operations)
Methodology overview
- 79 organisations across Europe participated
- 4-month survey period (20 April – 24 July 2023)
- 22 in-depth online interviews conducted with sector stakeholders
- A 3-phase assisted data collection process to ensure high-quality, reliable results
- Use of a customised Capability Maturity Model
To assess training processes, CYRUS applied the Cybersecurity Maturity Model for Educational Paths, developed by Cefriel. This model evaluates how organisations design, implement and maintain cybersecurity training and upskilling pathways. You can find more information about the model here: https://cyrus-project.eu/how-do-models-help-organisations-assess-their-cybersecurity-capabilities/
The outcome is a representative and reliable picture of real-world needs, challenges, and maturity levels across European SMEs in transport and manufacturing.
Cybersecurity skills and competence gaps in the two sectors
-
Awareness remains a critical weak point
One of the most consistent findings across both sectors is the urgent need to raise cybersecurity awareness, especially among non-technical staff, administrative roles, finance and HR departments as well as middle and senior management.
Cybersecurity is still often perceived as an “IT issue.” However, incidents frequently originate from phishing attacks targeting finance teams, social engineering affecting HR or misconfiguration or policy gaps due to management decisions.
Without organisation-wide awareness, even advanced technical controls can fail.
-
Technical skills: OT–IT convergence challenges
Transport and manufacturing environments combine:
- Information Technology (IT)
- Operational Technology (OT)
- Industrial Control Systems (ICS)
- Industrial IoT devices
This convergence creates new complexity. Technical staff increasingly require:
- Knowledge of both IT and OT security
- Network segmentation skills
- Secure configuration of industrial systems
- Incident response in hybrid environments
- Understanding of supply chain cybersecurity
Many organisations report difficulty in finding professionals who understand both traditional IT security and industrial environments.
-
The need for customised, role-based training
A key insight from the surveys and interviews is that generic cybersecurity training is not sufficient.
Effective programmes must:
- Be tailored to specific roles
- Include real-world sector case studies
- Offer practical exercises and simulations
- Reflect actual operational workflows
For example:
- A logistics manager requires training on supply chain risk and ransomware impact on delivery operations.
- A production supervisor needs to understand the consequences of compromised programmable logic controllers (PLCs).
- A CEO must be able to assess cyber risk in strategic and financial terms.
Customisation increases engagement and practical applicability.
Future cyber-threat scenarios in transport and manufacturing
CYRUS identified and mapped:
- 38 cyber threats in the transport sector
- 21 cyber threats in the manufacturing sector
These were aligned with specific workforce personas most exposed to them.
Key threat trends
-
Ransomware targeting operational continuity
Ransomware remains one of the most disruptive threats. In both sectors, operational downtime translates directly into production losses and therefore delayed deliveries.
In manufacturing, a single day of halted production can cause cascading financial losses. In transport, system outages can affect passengers, cargo, and infrastructure reliability.
-
Supply chain attacks
Transport and manufacturing are deeply interconnected ecosystems. Suppliers, contractors and service providers share data, platforms and remote access to systems.
Attackers increasingly exploit smaller suppliers as entry points into larger organisations. SMEs with limited cybersecurity maturity are particularly vulnerable.
-
Data breaches and intellectual property theft
Manufacturing companies, in particular, hold proprietary designs, trade secrets, process innovations and R&D data. Data exfiltration can severely undermine competitiveness.
In transport, personal data (e.g., passenger data, tracking information) is also a high-value target.
Personas most at risk
CYRUS partners identified personas based on real operational roles and responsibilities.
Commonly exposed profiles include:
- IT and OT administrators
- Production managers
- Fleet managers
- Logistics coordinators
- Finance officers
- HR managers
- Senior executives
Importantly, exposure is not limited to technical roles. In many scenarios, non-technical staff are primary targets for initial compromise.
Critical assets at stake
The assets at risk in transport and manufacturing extend beyond IT infrastructure.
-
Operational continuity
- Production lines
- Transport scheduling systems
- Fleet management platforms
- Warehouse automation
Downtime directly affects revenue and contractual obligations.
-
Safety
In transport and industrial environments, cybersecurity incidents can have physical consequences:
- Disruption of railway signalling systems
- Compromised vehicle software
- Manipulated industrial control systems
Cybersecurity in these sectors is tightly linked to human safety.
-
Intellectual property and competitive advantage
For manufacturing firms, design files, formulas, prototypes, and production processes represent strategic assets. Their compromise can result in:
- Market disadvantage
- Counterfeiting
- Long-term economic damage
-
Trust and reputation
Transport operators and manufacturers rely on customer and partner trust. Cyber incidents can:
- Damage brand reputation
- Reduce investor confidence
- Lead to regulatory penalties
Reputation loss often has longer-lasting consequences than the technical breach itself.
From findings to action: Designing the CYRUS training pathways
The results of the research conducted form the foundation for the next phase of the project:
- Development of tailored training modules
- Persona-based learning paths
- Practical, scenario-driven exercises
- Alignment with real-world sector threats
By grounding its training design in empirical data from 79 European organisations, CYRUS ensures that its educational content directly addresses actual competence gaps with realistic threat scenarios based on sector-specific operational constraints.
Conclusion
The transport and manufacturing sectors are undergoing rapid digitalisation, which brings both opportunity and risk. CYRUS has demonstrated that:
- Cybersecurity maturity in training processes varies significantly across organisations
- Awareness among non-technical roles must be strengthened
- Role-based, customised training is essential
- Future threat landscapes will increasingly target operational technology, supply chains, and AI-enabled systems
Most importantly, cybersecurity in these sectors is no longer a purely technical matter. It is a strategic, organisational, and safety-critical issue.
Through evidence-based training design and stakeholder engagement, CYRUS aims to strengthen Europe’s resilience where it matters most: in the infrastructures and industries that keep society moving and producing.

