They probably don't have their entire database of secrets connected anywhere to the Internet. If there is no physical connection, then there is no means of access for any hacker. This simple thing appears to completely defeat just about every other organisation; there is an obsession out there to connect everything to the web and thus leave it accessible. Once connected, all and every firewall, access protocol, security measure becomes a challenge to be beaten.
It wont be long before some bright spark decides that trains or signalling systems need a web connection; one that is highly secured with 256 bit encryption etc., of course. For software updates; for in-cab signalling, whatever. But it has to be connected to the internet (for some reason). And it won't be long afterwards that the system is hacked and something happens that we really don't want......