Industries · Transport and logistics

Transportation cybersecurity: for sites that move, and sites nobody visits

Transport networks are spread thin: cabinets on a roadside, depots, vehicles, a temporary compound for a works programme. There is rarely a rack and never a local engineer. QS-WAN ships the gateway configured, gives each device one identity, and keeps what each site may reach on a map you control centrally.

Three kinds of site in one network
01
Fixed but unattended
02
Temporary, for a season
03
Moving, all day

They all need the same rules and none of them has an IT room.

The constraint

The network has to travel with the work

A transport operator runs a network that refuses to sit still. Roadside equipment, signalling cabinets, port terminals, depots that open for a project and close again, and vehicles that are connected for the whole shift.

Every one of those places is hostile to the usual approach. No rack, no spare engineer, physical access that is easier for a stranger than for your own team, and connectivity that is rented, shared or cellular.

So the design question is about arrival and revocation. What can be sent to a site already working, and how quickly can a device that goes missing stop being trusted?

A cabinet by a road is a data centre with worse locks.
What makes transport its own case
01

Physical access is not controlled

Roadside and depot equipment can be reached by people you did not invite. Whatever is on that network has to assume the box can be touched.

02

Contractors come with the project

Works programmes bring crews and equipment for months at a time, each needing access that should end when the programme does.

03

Connectivity is borrowed

Cellular and shared links are the norm, so the protection has to live in what crosses them rather than in the link itself.

How QS-WAN handles scattered sites

Ship it configured, revoke it centrally

QS-WAN runs a private network from one console and QNova Client puts it on laptops, tablets and phones. Across a scattered estate, three things carry the weight.

01

Hardware that arrives ready to plug in

We ship the gateway configured, so a depot supervisor connects it rather than commissions it. Where a site has a host, it runs as software instead.

02

One identity per device, revoked in one action

Each device holds a certificate per gateway membership. A tablet that disappears from a cab stops being trusted from the console, without touching anything else.

03

What each site may reach, as a drawing

Segments and the edges between them are set centrally. A contractor compound gets a path to one system for the length of the programme, and the edge is switched off when it ends.

Underneath, the same everywhere

Post-quantum by default

Key establishment between device, gateway and control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design, which matters when the link belongs to somebody else.

Offline is expected

Changes are recorded centrally and converge when a gateway reconnects, and the console shows which sites are online, so you can tell intention from reality.

What you can show

The questions that follow a scattered estate

Regulators, insurers and your own risk team ask about the edges of the network, because that is where the assumptions live.

Q1

What sites exist, and which are online?

Each gateway, its segments and its current state, so the estate is a list of facts rather than a spreadsheet.

Q2

What can a site reach?

The edges in the Network Map for that gateway, each one way, two way, disabled or zero trust.

Q3

Who holds a way in, and on which device?

User profiles, devices and one certificate per gateway membership, with a CSV export.

Q4

What happens when equipment is stolen?

The membership is revoked centrally, and the console shows what that device could reach before it was.

The caveat that matters most out here. A green confirmation means the change was recorded. A cabinet on a sleeping cellular link applies it when it reconnects, so read the online state next to the record.

Where it stops

What this does not cover in transport

Transport security covers a great deal that a network platform has no business claiming.

The vehicle and its systems

Onboard control systems, telematics units and their suppliers stay where they are. This is the network around them.

Physical protection

Locks, enclosures, tamper switches and the people who check them are outside this.

Nobody is watching for you

QuantumNova is a product, not a managed service. The evidence and the score are produced for your team to read.

Links it does not run

The cellular or leased connection stays with your provider. What changes is that what crosses it is unreadable to them.

Start with the site nobody wants to drive to

That is the one where the configuration is oldest and the assumptions are strongest. A demonstration is free.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top