The work examines the main subjects and cyber risks in a transport company, as well as an approach to constructing an analytical model for assessing the effectiveness of the transport company's information system in order to assess the risks of unauthorized access and distortion of personal data of passengers, employees and clients of the Transport Company.
Digitalization of business process at transport companies, includes the widespread installation of information and communication technologies both into management systems and into the technical and technological infrastructure of the enterprise. This enables companies to make fast and efficient logistics and management decisions, resulting in more efficient use of assets, reduced costs, reduced inefficiencies and optimization of all stages of the supply chain. Information technologies within the framework of a process approach allows us to combine all business processes of an enterprise and create a Digital Transport Systems (Transport Company Digital Ecosystem) that is able to withstand existing and future cyber threats that can disrupt the normal functioning of Information Technologies (IT) and Operational Technologies (OT) used in transport industry. One of the elements of such Digital Ecosystems is Information System in which Personal Data about passengers, employees and clients of a transport company are stored and processed (ISPD). The work examines the main subjects and cyber risks in a transport company, as well as an approach to constructing an analytical model for assessing the effectiveness of the transport company's information system in order to assess the risks of unauthorized access and distortion of personal data of passengers, employees and clients of the transport company.