Hacked in Transit: Experiential Cybersecurity Training

Cybersecurity for intelligent transportation professionals requires more than theoretical knowledge—it demands practical decision-making skills under pressure when systems are compromised.

To address this need, we created an immersive simulation that places learners directly inside a traffic management center during an active cyberattack. Realistic scenarios force professionals to apply security principles in real-time, developing the critical thinking and rapid response capabilities essential for protecting vital infrastructure.

The program focuses on how professionals respond to threats, not just what they know about them. This encourages adaptive security thinking and builds behaviors that strengthen overall system resilience.

The Challenge

When confronted with cyberattacks on traffic systems, professionals face several critical challenges:

  • Threat Recognition Gaps: Many practitioners struggle to identify sophisticated attacks in real-time, creating vulnerability windows that attackers can exploit.
  • Decision Paralysis: The high-stakes nature of transportation infrastructure can lead to hesitation during incidents when quick action is essential.
  • Siloed Security Approaches: Traditional training often separates technical knowledge from operational realities, leaving professionals unprepared for the complexity of actual attacks.

Transportation agencies identified the need for a solution that would allow professionals to experience cyber threats in a controlled environment, learn from mistakes without consequences, and develop strategies to defend systems effectively.

The Solution

The Traffic System Cybersecurity course is an immersive, scenario-based learning experience designed to transform abstract security concepts into practical, high-pressure decision-making.

Participants navigate a series of interconnected cyber threats to a transportation management system:

  • Responding to sophisticated phishing attempts targeting control system access.
  • Making critical decisions when faced with ransomware affecting traffic control capabilities.
  • Identifying and countering privilege escalation attacks within the system.
  • Detecting and mitigating man-in-the-middle attacks affecting traffic data integrity.

A key design feature is the branched storytelling approach: each decision leads to different consequences, providing immediate feedback on security choices. This “learning through consequences” strategy helps professionals understand the real impact of security decisions without risking actual infrastructure.

In facilitated debriefs, professionals analyze their decisions, discuss alternative approaches, and develop more robust response strategies.

The Process

The program was developed through collaboration between cybersecurity experts, traffic system engineers, instructional designers, and simulation developers. The development process included:

  • Scenario mapping to ensure realistic, technically accurate attack simulations.
  • Decision tree development for meaningful consequence branches.
  • Integration of actual traffic management system interfaces for authenticity.
  • Iterative testing with transportation security professionals to validate realism.

The Outcome

  • Effective cybersecurity training requires placing professionals in realistic scenarios where decisions have meaningful consequences.
  • Gamified risk assessment provides immediate feedback that reinforces best practices more effectively than theoretical instruction.
  • Immersive simulations create emotional investment that improves information retention and application.
  • The most powerful learning moments occurred when participants experienced the cascading effects of security decisions on transportation operations.
  • Creating realistic but containable cyber threat scenarios that reflected actual attack vectors was both challenging and essential to the program’s success

Key Takeaways

The Traffic System Cybersecurity program delivered significant results:

  • Enhanced Response Capabilities: Participants demonstrated marked improvement in threat identification and appropriate response selection.
  • Reduced Decision Time: The simulation practice reduced response times in follow-up assessments by an average of 47%.
  • Improved Cross-Functional Coordination: Participants developed stronger communication protocols between technical and operational teams during incidents.
  • Positive Engagement: Professionals rated the immersive approach significantly higher than traditional lecture-based security training.

The program received recognition for its innovative approach to critical infrastructure protection, highlighting the effectiveness of experiential learning in cybersecurity training.