Nice bit of topical comment and casual racism to kick things off. Moving on...
1) The 'guy in his bedroom in Hounslow', Navinder Singh Sarao also made a $40 million dollar profit on his trades (which he had legitimate access to via his work as a trader).
2) Andreas Lubitz had already mentioned that he wanted to do something "spectacular and unforgettable", again by his legitimate access to the cockpit. He killed 149 innocent people.
The common trends? Legitimate access plus minimum effort, maximum effect. Neither of those two mentioned had to do anything out of the ordinary to bring about their respective effects. Even a rogue insider would have to hack the system to defeat the inbuilt interlocking. But we are talking about outside influences hacking into a secure system to alter it for nefarious effect.
No one said that "it can't possibly happen to us" (and how is UKIP relevant by the way?) What was said that in the framework of terrorists or other groups wanting to cause mass casualties, it would be unlikely. Think about it. Hack into a secure computer system or ram a stolen HGV through some automatic half barriers as a train is approaching? A hacking attack has every chance of failure, not least because it would require (and I'll repeat myself for the hard of understanding) hacking at
EVERY level of ERTMS. Not just the signalling station, but the train itself, plus everything else that goes with it. Not just a laptop attached to a cable somewhere, but the actual on train equipment, plus point operating equipment etc etc.
A HGV or other obstruction placed across the running line or for that matter, an explosive device placed on a train or station would have every chance of success. Why? Because it's simple and can't be planned for. When was the last time YOUR bag was checked getting on a train? Or when was the last time that the vehicle at the front of queue at a AHBC was checked by the police? In fact, when was the last time anyone other than a few spotters with cameras were stopped by police and/or security at a major railway station? Millions of people walk in and out of stations carrying bags, rucksacks, suitcases every single day. An attacker would just blend in unnoticed. Simple attacks like explosive devices or obstructions on the line would be far more likely than an expensive and potentially fail-worthy hacking attempt, purely because they are simple, difficult to disrupt and cause maximum devastation.
Terror groups want MASS casualties. They WANT to shock, to cause revulsion to (In Andreas Lubitz own words) cause something "spectacular and unforgettable". Fiddling with ERTMS so as to have the chance to cause an accident (not even a 100% chance as there are drivers on-board who can stop the trains, plus signallers in the signalling stations; someone still has to set the route the train is travelling over and they can send out emergency stop messages via GSMR or even the ERTMS itself) has so many flaws and pitfalls that I, personally would consider it unlikely to happen. Plus, its a one off event. The first time it gets hacked, the system gets redesigned or has its security enhanced so the attacker has to start again. While I'm sure that no computer system is infallible, I'm equally sure that the people who design and implement them may have thought about hacking access. ERTMS has been in development since 1990
http://www.ertms.net/?page_id=49 Do you think that at some point in it's 25 year development (a process that is still ongoing) the people at the sharp end may have considered the feasibility of external hacking, or did you think that they waited for good Professor to rock up on the BBC and suddenly think "Shiiiiiiiiiiiiiiiiiii*e! We hadn't thought of that! Back to the drawing board lads.."?
And, don't forget that modern passenger rolling stock is extremely crash worthy. Great Heck was the highest speed railway accident the UK has seen so far. Every one of the ten deaths in that crash will be sorely missed by their loved ones, but it is a credit to modern rolling stock design that more people weren't killed. As we saw on 7/7, you cannot prevent someone with an explosive device getting on-board a packed train (or bus for that matter). It is simple and sadly, deadly effective and one I think is far more likely to happen than some SPECTRE like agency pouring it's naughty resources into hacking ERTMS.