All articles
Foundational Controls Let Amtrak Secure a Decade-Long Modernization While It Runs
Arturo Santos, DT Director of Cybersecurity Architecture at Amtrak, on why critical infrastructure can't wait a decade to replace legacy systems, and the foundational controls that keep them defensible now.

Make The Security Digest one of your go-to sources on Google
Replacing the entire infrastructure is going to take years, but by these principles, we'll be able to make it in a safe and scalable manner.
Critical infrastructure operators face a problem that has no fast solution: the systems most essential to national function are often decades old, geographically scattered, and impossible to replace on any near-term timeline. Waiting for a complete modernization program before securing them isn't an option, because that program will take ten years or more and the threats are here now. The practical path forward isn't replacement, but protection in place. Asset visibility, network isolation, traffic monitoring, centralized patching, and tightly controlled access give operators a defensible security foundation that manages known risk while old and new OT environments continue running side by side.
Arturo Santos is the DT Director of Cybersecurity Architecture at Amtrak, where he leads the architecture behind the railroad's OT modernization and IT/OT convergence. A firm believer in the Purdue model and a longtime cybersecurity practitioner, he serves in the Operational Technology Cybersecurity Coalition and led the creation of the US technical advisory group for IEC 63452, the emerging international standard for rail cybersecurity. His vantage point spans both the strategic standards work and the day-to-day reality of securing systems that have been running for decades.
"One of the key things that we all lack in critical infrastructure and in OT in general is asset visibility," he says. That gap is where Santos starts, because everything else in a protection-in-place strategy depends on first knowing what you actually have.
The modernization timeline is measured in decades
Amtrak is in the middle of what Santos is careful to call a program rather than a project, because it contains many projects underneath it, all aimed at modernizing the railroad's OT infrastructure. To say the original timeline was optimistic may be an understatement. "It's something we laid out for five years being extremely optimistic, probably unrealistic," Santos shares. "This is going to take us at least 10 years, but we're building the foundation for that."
The scale of the change is what makes it slow. Modernizing OT in critical infrastructure is not the incremental work of moving from one version of Windows to the next. It's replacing technology that has run for decades with something categorically different. "A lot of our OT is legacy. We're taking a quantum leap from very old legacy systems, OT devices on our wayside and old fleet that have been running for 20, 30 years or more. The new trains we're deploying are data centers on wheels. Those are super sophisticated systems now in the OT environment."
That leap creates value on the operational side. The new fleet from OEMs like Siemens and Alstom generates terabytes of data that Amtrak's maintenance teams can use for predictive maintenance and better planning around costly out-of-service windows. But the security challenge of running 30-year-old wayside devices alongside data centers on wheels doesn't resolve until the decade-long replacement is complete, which means the interim has to be secured on its own terms.
Technical debt is permanent, so build for it
Santos is candid that the technical debt in transportation will never fully disappear, because the industry is always playing catch-up. "By the time we get to replace obsolete technology, it won't be too long before it's obsolete again. It's almost obsolete by the time we replace it. It's like you're replacing Windows XP with Windows 7 in some cases," he explains.
That reality reframes the goal. If the debt is permanent, the answer can't be to eliminate it before securing the environment. The answer is a set of foundational principles that make the environment defensible regardless of how old the underlying devices are. Santos lists the drivers of Amtrak's program as asset identification and visibility, traffic monitoring, secure management, patch management, and isolation of the OT environment.
Asset visibility comes first, he says, because it's the most commonly missing piece and the prerequisite for everything else. "If you can manage that, you at least know and have a full inventory of what that is, what the risks are, and have some mitigating controls around it. That's a huge improvement over the typical situation where you don't even know what you have."
The foundational controls that hold the line
From visibility, the rest of the protection-in-place strategy follows. Santos describes a layered set of controls that let Amtrak manage risk across the mixed environment without waiting for full replacement.
The controls center on constraining how traffic and access move through the OT environment. Amtrak built five OT network convergence locations across its wayside and fleet technology to funnel all traffic through defined channels toward IT, consistent with the Purdue model's emphasis on managing north-south flow and minimizing east-west traffic to only what is necessary. "We have a lot of strategies to mitigate unauthorized access to our devices, organized patch management centralized from centralized locations, building one-way communications, and limiting access to the OT environment," Santos says.
Testing is the other pillar. Santos emphasizes realistic, environment-wide validation rather than device-by-device checks: "Doing better, more realistic testing and regression testing including the entire environment, not just specific devices. All of those are foundational principles that we're deploying."
The payoff of these principles is that they decouple security progress from replacement progress. "Replacing the entire infrastructure is going to take years, but by these principles, we'll be able to make it in a safe and scalable manner."
Regulation is now the sharpest driver
Predictive maintenance and operational value help justify modernization, but Santos is direct that the most forceful driver of change is increasingly regulatory. The rail industry is now subject to tightening TSA requirements, and regulators are moving from broad mandates to prescriptive demands. "When a regulator comes and tells you, you need to monitor your OT, a lot of times I don't think they realize how big of an ask that is. 'Monitor' is a very broad term, and they're becoming very prescriptive, demanding reporting and management of assets in a very effective way, which is great. The challenge is when they tell you that you need to comply by the end of the year."
The compressed compliance timelines are, in his framing, often a bigger transformation driver than the business case, which is one reason he participates in the OT Cybersecurity Coalition. The coalition functions as a think tank that helps shape regulation informed by the operational reality of what monitoring OT at national scale actually requires.
The misconceptions that make the work harder
Santos closes on the assumptions that complicate the job, and they start inside his own organization. The most persistent is the belief that OT and IT are fundamentally the same, and the related belief that OT is easy to manage. "Even within my organization I have to do a lot of education. People think OT is easy to manage, and it's not. It's very difficult, very diverse. We have thousands of devices with thousands of operating systems running in many different network topologies and environments," he says.
The diversity and distribution are also why replacing legacy devices is never as simple as swapping hardware. Amtrak's devices are spread across the entire nation, and many are operated by union workforces that need additional training whenever a device changes. Even a small replacement carries operational and human considerations that a pure technology view misses.
The throughline of Santos's approach is pragmatism grounded in sequence. The full modernization will take a decade, the technical debt will never fully clear, and the regulatory clock is running faster than either. What makes the situation manageable is refusing to treat security as something that has to wait for replacement. Know what you have, isolate it, monitor it, control access to it, and patch it from a central point, and the old and new can operate together safely while the long work of modernization continues underneath.






