The quiet stretch of kerb that once existed as a simple strip, has become one of the most contested digital frontiers in modern transport. Cities are wiring their kerbsides with sensors, booking platforms, enforcement tools, payment gateways and live operational feeds. Micromobility fleets depend on them. EV charging networks rely on them. Freight operators navigate them. Parking systems monetise them. As this digital ecosystem expands, a new reality is emerging. The kerbside is no longer just physical infrastructure. It is a networked environment, and networked environments attract adversaries.
The sector has spent years talking about digital transformation, but because of the diversity of offerings that use this space, need to understand the potential cyber consequences. A kerb that can be booked, priced, reserved, monitored and charged is a kerb that can be hacked. The moment a city moves from static signage to dynamic access control, it enters a new arms race. Attackers see opportunity in every API, every payment flow, every device bolted to a lamp column. The stakes are rising quickly, and the industry needs to be fully prepared.
The most obvious threat is ransomware. It has already swept through hospitals, councils, universities and major corporations. Transport has not been immune, but the kerbside has so far escaped the worst of it. That grace period will not last. Parking systems are now deeply integrated with payment platforms, enforcement databases and back-office operations. A coordinated attack could lock operators out of their own systems, freeze payment flows, disable enforcement and create city-wide disruption. Imagine a morning where every pay-by-phone transaction fails, every enforcement camera goes dark and every back-office terminal displays a ransom note. The operational chaos would be immediate, and the financial impact severe.
Micromobility fleets face a different flavour of risk. Their business models depend on real-time connectivity. Bikes and scooters constantly report location, battery status, trip data and maintenance needs. They are managed through cloud platforms that orchestrate rebalancing, pricing and fleet health. This creates a tempting target for attackers who want to cause disruption or extract money. A hostile actor could lock an entire fleet, scramble GPS signals, spoof availability, drain batteries through forced commands or even push unsafe firmware updates. The result would be paralysis on the streets and reputational damage for operators who are already under scrutiny from regulators and the public.
EV charging infrastructure presents another frontier. Chargers are effectively IoT devices with payment terminals attached. They communicate with networks, energy suppliers, roaming platforms and vehicle systems. A compromised charger could refuse to authenticate users, overcharge them, undercharge them, or simply shut down. A coordinated attack on a city’s charging network would strand drivers, disrupt logistics and undermine confidence in electrification. The risk extends beyond inconvenience. If attackers gained access to load management systems, they could manipulate demand in ways that stress local grids. Cybersecurity becomes not just a transport issue but an energy resilience issue.
The kerbside is attractive to attackers because it is fragmented. Cities rely on a patchwork of vendors, legacy systems, pilot platforms and bespoke integrations. Many deployments began as small trials that grew into permanent infrastructure without the rigorous security architecture that would normally accompany critical systems. Devices are often installed outdoors, connected via wireless networks and updated remotely. They are exposed physically and digitally. Attackers thrive in environments where responsibility is diffuse and defences inconsistent.
The arms race is already under way. Vendors are racing to harden their platforms. Cities are scrambling to understand their vulnerabilities. Insurers are quietly adjusting their models. Cybersecurity firms are circling the sector with new services and warnings. The challenge is that kerbside management has become essential to urban operations. It shapes freight movement, micromobility behaviour, EV charging access, parking revenue and street safety. A successful attack would not simply inconvenience a few drivers. It would disrupt the daily functioning of a city.
The sector needs to rethink its assumptions. Cybersecurity cannot be treated as an add-on or a compliance tick-box. It must be embedded into procurement, design, deployment and maintenance. Cities should demand clear security standards from vendors, including encryption, secure boot processes, regular patching, penetration testing and transparent incident reporting. They should map their kerbside systems as critical infrastructure, not peripheral technology. Operators should invest in monitoring tools that detect anomalies in device behaviour, payment flows and network traffic. They should prepare response plans that allow rapid isolation of compromised systems.
There is also a cultural shift to navigate. Transport teams are used to thinking in terms of physical risk. They understand collisions, congestion, signage, enforcement and maintenance. Cyber risk feels abstract until it becomes painfully real. The sector needs new skills, new partnerships and new ways of working. Cybersecurity specialists must be part of kerbside planning. Procurement teams must understand the implications of insecure APIs. Operational staff must know how to respond when devices behave strangely. Leadership must recognise that digital kerbside management is not just a convenience but a vulnerability.
The arms race will intensify as kerbsides become more dynamic. Cities are exploring flexible restrictions, real-time pricing, bookable bays, automated enforcement and integrated multimodal access. Each new feature creates new attack surfaces. The more intelligent the kerb becomes, the more attractive it is to those who want to exploit it. The sector cannot afford to wait for a major incident before acting. The lessons from other industries are clear. Cybersecurity must be proactive, not reactive.
There is an opportunity here. Cities that treat cybersecurity as a core component of kerbside management will build trust with operators, users and the public. They will create resilient systems that support innovation rather than hinder it. They will avoid the reputational damage that follows high-profile breaches. They will also position themselves as leaders in a field that is rapidly evolving.
The kerbside has always been contested space. It is now contested in new ways. The digital transformation that promised efficiency, flexibility and intelligence has also opened the door to adversaries who see value in disruption. The sector must respond with seriousness, investment and collaboration. The new cyber arms race on the kerbside is already here. Cities that recognise it early will be the ones that keep their streets moving, their systems secure and their digital ambitions intact.
Click the buttons below to see more articles:
See all ArticlesIndustry InsightEventsITS Thought LeadershipITS Educational