Audit Reveals Critical Weaknesses in U.S. Aviation Cybersecurity Oversight

0
4

Key Takeaways

  • The FAA has fully implemented only three of seven objectives in its cybersecurity strategy, leaving gaps in monitoring, privileged‑user control, standards compliance, and zero‑trust migration.
  • TSA continues to rely on a 2018 Cybersecurity Roadmap that is outdated, lacks clear responsibility assignments, and is not aligned with the current DHS cybersecurity strategy.
  • Growing connectivity of aircraft systems to external networks expands the attack surface, yet no successful cyber‑intrusion of avionics has been reported to date.
  • Reported cybersecurity incidents in the broader aviation sector rose from 290 in 2020 to 562 in 2022, fell to 151 in 2024, and climbed again to 352 in 2025, highlighting persistent threats such as unpatched software, default credentials, and weak network segmentation.
  • Despite confusion over jurisdictional roles, FAA and TSA collaborate effectively through the Aviation Cyber Initiative, which meets leading practices for interagency cooperation.
  • FAA’s aircraft certification and ground‑system security authorization processes satisfy federal and industry best practices for protecting avionics, but its zero‑trust transition plan addresses only three of seven NIST‑recommended practices and omits detailed steps for its research‑and‑development environment.
  • Incomplete cybersecurity‑spending reporting by the FAA hampers congressional and executive oversight, especially as the agency explores AI and machine‑learning tools for modernization.
  • GAO recommends that TSA update its roadmap, clarify responsibilities, align with DHS strategy, and communicate changes to stakeholders; and that FAA capture all cybersecurity expenditures, complete its zero‑trust migration plan, and institute rigorous monitoring of its revised strategy.

FAA’s Partial Implementation of Its Cybersecurity Strategy
The Government Accountability Office (GAO) audit found that the Federal Aviation Administration (FAA) had fully achieved only three of the seven objectives supporting its goal of protecting and defending agency networks. Work remained incomplete in several core areas essential to the security of the National Airspace System (NAS), including continuous cyber monitoring and incident response, enforcement of controls over privileged users, compliance with up‑to‑date federal cybersecurity standards, and the transition to a zero‑trust architecture. These shortcomings persist despite the FAA’s role as the primary regulator of aircraft safety and operator of the ground systems that underpin the NAS.


TSA’s Outdated and Unclear Cybersecurity Planning
In contrast, the Transportation Security Administration (TSA) continues to rely on a Cybersecurity Roadmap dating from 2018. GAO determined that this document is no longer aligned with the Department of Homeland Security’s (DHS) current cybersecurity strategy and fails to assign clear responsibility for carrying out its goals. Moreover, TSA has not defined which of its offices are accountable for specific cybersecurity functions, nor does it delineate its responsibilities for overseeing airport and airline security programs. This ambiguity hampers TSA’s ability to hold its components and regulated entities accountable, measure progress, or improve its aviation‑focused cybersecurity work.


Increasing Connectivity Expands the Attack Surface
Modern aviation relies on extensive connections between aircraft avionics and external networks such as air traffic control facilities, weather services, navigation systems, satellites, and ground‑based IT infrastructure. While these linkages improve operational efficiency, they also create additional entry points for potential attackers. GAO noted that, although no successful cyber intrusion of aircraft flight systems has been reported, the broader aviation sector has been repeatedly targeted by state‑sponsored actors, financially motivated groups, and hacktivists.


Trends in Reported Aviation Cybersecurity Incidents
Cybersecurity incidents reported to the Cybersecurity and Infrastructure Security Agency (CISA) across the aviation subsector illustrate the evolving threat landscape. Incidents rose from 290 in 2020 to a peak of 562 in 2022, declined to 151 in 2024, and increased again to 352 in 2025. These figures encompass the wider aviation sector and do not represent successful breaches of avionics. Common vulnerabilities identified in the incidents include inadequate software patching, internet‑accessible operational technology, unsupported operating systems, insecure remote services, weak network segmentation, and the use of default credentials. Exploitation of these weaknesses could disrupt communications with air traffic controllers, corrupt data used by cockpit systems, interfere with aircraft location information, or grant unauthorized access to aviation networks.


Division of Responsibilities Between FAA and TSA
The FAA regulates aircraft safety, oversees the cybersecurity of avionics through its certification process, and operates the ground systems supporting the NAS. TSA, meanwhile, manages security programs maintained by airports and aircraft operators. GAO observed that the FAA’s cybersecurity strategy clearly assigns duties to seven agency organizations, whereas TSA’s planning documents lack comparable clarity. Industry representatives interviewed by investigators expressed confusion about TSA’s role, with some believing that cybersecurity requirements introduced by a Joint Emergency Amendment in March 2023 fell under FAA’s authority. Subsequent guidance clarified that resources tied to aircraft airworthiness are excluded from TSA’s mandate, and Congress later granted the FAA exclusive authority over civil‑aircraft cybersecurity in the FAA Reauthorization Act of 2024.


Effective Interagency Collaboration Through the Aviation Cyber Initiative
Despite jurisdictional uncertainties, GAO found that the FAA and TSA work together effectively via the Aviation Cyber Initiative, a joint effort involving the Departments of Transportation, Homeland Security, and Defense. The initiative satisfied all eight of GAO’s leading practices for interagency collaboration: defining common outcomes, assigning leadership, sharing resources, establishing written agreements, and fostering mutual accountability. This cooperative framework helps bridge gaps in each agency’s individual planning and enables coordinated responses to emerging threats.


FAA Strengths in Avionics and Ground‑System Protection
The audit highlighted several areas where the FAA performed favorably. GAO concluded that the agency’s current and proposed aircraft certification process addresses all federal and industry best practices identified for protecting avionics against cybersecurity risks. Likewise, the FAA’s security authorization process for the ground systems it operates within the NAS meets those same practices. These findings indicate that, while broader strategic implementation lags, the FAA’s core safety‑certification and system‑authorization functions remain robust.


Weaknesses in FAA’s Zero‑Trust Migration Plan
Significant deficiencies were noted in the FAA’s plan to migrate its networks to a zero‑trust architecture. The implementation plan fully addressed only three of the seven migration practices recommended by the National Institute of Standards and Technology (NIST). It lacked detailed transition plans for the agency’s research‑and‑development environment and only partially addressed the identification of users, assets, data flows, and business processes across other operating environments. Because research and development drives the continued modernization of the NAS, GAO warned that the FAA cannot be assured it is comprehensively managing associated cybersecurity risks without applying zero‑trust principles uniformly across all its environments.


Incomplete Cybersecurity‑Spending Reporting
GAO also found that the FAA has not fully reported its cybersecurity spending to the Office of Management and Budget. Although the agency’s annual budget requests line items for network protection, secure remote access, authentication systems, and research into attack‑detection tools, the Information Security and Cybersecurity Program’s funding figures ($6.4 million for FY 2024, $5.9 million for FY 2025, and $4.6 million for FY 2026) were omitted from the government‑wide budget submission. FAA’s internal reporting procedure captures only investments already listed in a prepopulated spreadsheet, neglecting to direct program offices to add other cybersecurity expenditures. Although FAA officials claimed the program was included in the FY 2027 budget submission, GAO noted that no supporting evidence had been provided as of April. This incomplete reporting obstructs congressional and executive oversight, especially as the agency experiments with AI, machine‑learning, and other emerging technologies for aviation modernization.


GAO Recommendations for Improvement
To address the identified shortcomings, GAO issued five recommendations. For TSA, the watchdog urged an update of its Cybersecurity Roadmap, clear assignment of responsibility for achieving its goals, alignment with the DHS cybersecurity strategy, and communication of the revised plan to non‑federal aviation stakeholders. For the FAA, GAO recommended that the agency capture all cybersecurity expenditures in its budget reporting, develop detailed transition steps for every operating environment, bring its zero‑trust plan into full alignment with NIST guidance, and ensure that implementation of its revised cybersecurity strategy is monitored by the Cybersecurity Steering Committee, incorporating lessons from the earlier strategy’s tracking failures. Implementing these actions would strengthen the resilience of the nation’s aviation infrastructure against evolving cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here