Key Takeaways
- The FAA has clearly defined cybersecurity roles and responsibilities, while the TSA lacks such clarity, causing confusion among industry stakeholders.
- Misalignment between the agencies creates risks to aviation operations because interconnected ground‑and‑air systems rely on coordinated security controls.
- The FAA’s cybersecurity budget request grew dramatically from FY 2024 to FY 2026 (ranging from $42 million to $11 billion), but transparency in how those funds are allocated and spent needs improvement.
- Only three of the seven objectives in the FAA’s cybersecurity strategy were fully implemented; gaps remain in monitoring, detection, response, privileged‑user controls, and zero‑trust architecture.
- The TSA received a single recommendation to produce and share a cybersecurity roadmap that clearly defines its aviation‑cybersecurity duties.
- All five GAO recommendations were accepted by the agencies, offering Congress a concrete opportunity to strengthen policy, oversight, and funding for aviation cybersecurity.
Background and Motivation for the Review
The review was sparked by a provision in the FAA Reauthorization Act of 2024 that directed the Government Accountability Office (GAO) to evaluate the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA) on their cybersecurity roles, responsibilities, budgeting, and strategy implementation. Jennifer Franks, director of the GAO Center for Enhanced Cybersecurity, explained that the mandate aimed to assess how well the two agencies collaborate to protect the increasingly interconnected aviation ecosystem.
Roles and Responsibilities: FAA Clarity vs. TSA Ambiguity
The FAA has established and clearly assigned roles and responsibilities for carrying out its aviation‑cybersecurity goals and objectives. In contrast, the TSA has not formally defined or clarified its specific duties in this domain. Interviews with industry stakeholders—including airlines and related groups—revealed widespread confusion about what the TSA is supposed to do and how its guidance aligns with that of the FAA. This lack of clarity hampers effective coordination and leaves airlines uncertain about which agency to rely on for particular security matters.
Operational Risks Stemming from Agency Misalignment
When the TSA and FAA operate with overlapping or undefined responsibilities, the aviation sector faces heightened risk. Ground‑based security measures managed by the TSA (such as passenger screening and airport access controls) must seamlessly interface with airborne systems overseen by the FAA (flight‑deck avionics, air‑traffic‑control communications, and navigation equipment). If stakeholders do not understand the intended purpose or interconnected nature of these systems, gaps in security controls can emerge, leaving both known and unknown threats unaddressed. The potential for a cyber incident that disrupts either ground operations or flight safety increases when coordination is weak.
Budgeting and Financial Transparency Concerns
The GAO examined the FAA’s cybersecurity budget requests from fiscal years 2024 through 2026, which ranged from a modest $42 million to an astonishing $11 billion. While the sheer scale of the request reflects the growing threat landscape, the review found that the FAA’s management of those funds lacked transparency, especially in research‑and‑development areas. Clear tracking of how money moves from initial appropriation to actual deployment, maintenance, and continuous improvement is essential for ensuring that resources keep pace with evolving cyber threats. The GAO therefore recommended that the FAA improve budget transparency to enable better oversight and resource alignment.
Implementation Gaps in the FAA’s Cybersecurity Strategy
Although the FAA had articulated a cybersecurity strategy with seven supporting objectives, only three were fully implemented during the assessment period. The successfully met objectives included improving cyber‑threat‑intelligence collection and processing, enhancing detection and mitigation capabilities, and leveraging cybersecurity research and development. The remaining four objectives—particularly those concerning continuous monitoring, incident response, privileged‑user access controls, and adoption of zero‑trust architectural principles—were not fully realized. These gaps create processing weaknesses that could be exploited by adversaries seeking to infiltrate or disrupt aviation systems.
TSA’s Single Recommendation: Clarify and Share a Cybersecurity Roadmap
The TSA did not “ace” the review; it received one recommendation focused on developing and disseminating a clear cybersecurity roadmap. This roadmap must explicitly define the TSA’s roles and responsibilities for aviation cybersecurity and be shared with pertinent stakeholders, including airlines, airport operators, and federal partners. By doing so, the TSA can eliminate the confusion identified in stakeholder interviews and foster a more cohesive approach to securing both ground and air components of the aviation system.
Agency Response and Congressional Implications
All five GAO recommendations—covering FAA budget transparency, strategy implementation, and TSA role clarification—were accepted by the agencies. This unusual alignment presents Congress with a clear policy direction: enact oversight measures that enforce the GAO’s suggestions, ensure adequate funding with transparent reporting, and mandate inter‑agency coordination frameworks. Given that the original mandate originated from congressional legislation, lawmakers are well‑positioned to monitor compliance, appropriate resources, and potentially amend statutes to close any remaining jurisdictional gaps. Strengthening these controls now is critical, as no major cyber incident has yet disrupted aviation traffic control or ground transportation, but the threat environment continues to evolve, and preparedness is essential to prevent a future catastrophe.

