Rail IoT Connectivity Across Borders in 2026
Why rail IoT connectivity breaks at borders, in tunnels and on rural track, what that costs in fleet availability, and what a cross-border architecture needs.
A train crosses a border and its connectivity assumptions cross with it. The onboard router holds the same SIM, the same APN, the same back office destination. Everything underneath changes: a different mobile operator, a different roaming agreement, a different national position on how long a foreign device stays attached to a local network.
Cross-border rail IoT connectivity has four jobs. It has to hold onboard systems on a network while the train moves between them, through tunnels and across rural track. Then it has to keep that traffic off the public internet and show you what each device is doing in time to act. Most rail deployments answer the first job and stop.
Transport was the most targeted OT sector of 2025
Nozomi Networks, in its February 2026 OT/IoT Cybersecurity Trends and Insights report covering the second half of 2025, found transportation and manufacturing remained the number one and number two most targeted sectors for the full calendar year, with transportation first. The same report put adversary-in-the-middle techniques behind more than a quarter of all alerts in the environments it observed.
Rail carries the profile that draws this attention: long asset lives, wireless everywhere, several maintainers per asset, and public visibility the moment something stops.
Four places rail connectivity breaks
The national border
A SIM tied to one home operator depends on that operator's roaming agreement in the next country. Where the agreement is thin, the train attaches to whichever network the agreement covers instead of the network with the best signal on that stretch of track.
A SIM that authenticates against every operator its provider holds an agreement with in that market has more paths to try, and the choice happens per attachment instead of per contract.
The tunnel and the rural stretch
Coverage inside a tunnel depends on what the tunnel owner installed and which operators that installation carries. A single-network SIM reaches the tunnel only if its network is one of them. The same logic applies to rural track, where one operator has masts and another does not.
Permanent roaming rules
Several markets restrict how long a device stays permanently attached as a roamer. A fleet based in one country and running services into another meets that rule directly. Local IMSI options and eUICC provisioning are the answer, and they belong in the architecture before the fleet is deployed, not after a regulator asks. The mechanics are in how to replace permanent roaming in global IoT.
The single-network dependency
When one operator has a regional outage, a single-network fleet loses that region. Availability of the connectivity layer sets the ceiling on availability of everything above it.
The onboard estate nobody counted as an attack surface
Count what is IP-connected on a modern vehicle. Condition monitoring on bogies, brakes, doors and traction. Diagnostic gateways. CCTV cameras and onboard recorders. Passenger information displays. Passenger Wi-Fi. HVAC controllers. Ticketing validators. Then count trackside: level crossing monitoring, point heaters, axle counters, environmental sensors, lineside cabinets.
Palo Alto Networks' 2025 Device Security Threat Report, built on telemetry from 27 million devices, found 21% of IoT devices carry at least one known vulnerability, and that roughly a third of devices on corporate networks sit outside IT control. Rolling stock is a moving version of that problem, with a service life measured in decades and several different maintainers, each holding their own access path.
None of those devices runs security software. A brake sensor has no operating system to patch and no memory for an agent. If your security model depends on something installed on the device, the rail estate sits outside it.
Condition monitoring pays back only when the data arrives
The business case for onboard telemetry is condition-based maintenance: stretch intervals, catch a failure before it takes a unit out of service, put more kilometres on the same fleet. That case rests on a continuous data series. A gap of a few hours at a border or on a rural stretch removes the point in the series where the trend turned. Maintenance teams then fall back on fixed intervals, and the fleet holds the availability it always had.
A private APN is not the finish line
A private APN keeps vehicle traffic off the public internet, and most rail operators stop there. Private APN hides traffic but doesn't defend it. Inside the APN the fleet sits on a flat network, so a compromise on one CCTV recorder reaches the next vehicle. The APN also shows nothing about what each device talks to, which is the first thing an auditor asks for.
The gap between isolation and enforcement is where the work sits. We set the layers out in why private APNs fall short for global industrial IoT.
What NIS2 adds for rail
Rail sits in Annex I of the NIS2 Directive. Both infrastructure managers and railway undertakings, as defined in Article 3 of Directive 2012/34/EU, fall in scope where they meet the size thresholds. Article 21(2) names the technical measures, and the directive places accountability at board and C-suite level, personally.
What a cross-border rail architecture needs
| Requirement | Why rail is different | What answers it |
|---|---|---|
| Network choice per attachment | Track crosses operators, borders, tunnels and rural gaps | Multi-network SIM authenticating against every operator its provider holds an agreement with in that market |
| No permanent roaming exposure | Services run into markets with attachment limits | Local IMSI options and eUICC profile provisioning |
| Traffic off the public internet | Onboard systems carry operational and passenger data | Private APN with private routing into the operator's own systems |
| Device-level containment | One vehicle compromise must not reach the fleet | Policy-based segmentation between individual devices |
| Supplier access to one asset | Several maintainers per vehicle, each with their own tools | Brokered, time-limited, recorded browser sessions |
| Real-time SIM status | Incident reporting clocks run in hours | A connectivity platform with live SIM state, not a 24-48 hour data delay |
| Real-time traffic visibility | An auditor asks what each device talks to | Traffic mapping in the Zero Trust layer, which is a separate layer from SIM management |
Which approach fits which fleet
Choose a single-network national SIM if your fleet never leaves one country, your onboard estate is telemetry only, and no supplier needs remote access.
Choose a multi-network roaming SIM with a private APN if you run cross-border services and your requirement stops at reliable delivery of operational data.
Choose a multi-network SIM with private networking and Zero Trust enforcement if you are in NIS2 scope, several suppliers maintain subsystems on your vehicles, or you need to show an auditor what each device reaches.
Frequently asked questions
Is rail in scope for NIS2?
Yes. Transport sits in Annex I of the NIS2 Directive, and rail is named within it. Both infrastructure managers and railway undertakings, as defined in Article 3 of Directive 2012/34/EU, fall in scope where they meet the size thresholds.
Does a private APN cover the NIS2 technical measures?
No. A private APN isolates traffic. Article 21(2) also asks for access control, segmentation, incident detection and an audit trail of supplier access. Those sit above the APN.
How does connectivity hold up in tunnels?
It depends on what the tunnel owner installed and which operators that installation carries. A SIM that authenticates against multiple operators in a market has more paths into a tunnel than one locked to a single home network.
What is permanent roaming, and why does it matter for rolling stock?
Permanent roaming is a device staying attached to a foreign network indefinitely. Several markets restrict it. A fleet based in one country and running services into another meets that restriction directly, and the fix is local IMSI provisioning instead of a roaming SIM.
Do onboard devices run VPN clients?
Most do not. Sensors, cameras and diagnostic gateways have no capacity for client software. Enforcement has to happen in the network and cloud instead.
How many devices does a rail operator have to connect?
Once onboard telemetry, CCTV, passenger systems and trackside sensors are counted, a mid-sized operator runs into the thousands. Fleet size understates the device count substantially.
Where IXT fits
IXT runs a dedicated mobile core built for IoT from the ground up. The SIM identifies the device, in SIM, eSIM or iSIM form, across 600+ mobile networks in 190+ countries. SecureNet keeps the traffic off the public internet. A Zero Trust layer in the network and cloud checks every session before it opens. Fewer trade-offs than a single-network SIM for most rail deployments.
Ask us how it works for your fleet.
Related articles