Watchdog Urges Strengthened Security Measures for Commercial Aviation

0
3

Key Takeaways

  • The GAO warns that U.S. aviation infrastructure faces growing cyber‑risk due to increased interconnectivity of aircraft, air‑traffic‑control, airport, and airline systems.
  • While the FAA has defined cyber‑security roles, the TSA lacks clear responsibilities and its 2018 Cybersecurity Roadmap is outdated and misaligned with DHS strategy.
  • No successful cyber‑attack on flight‑critical avionics has been reported, but ground‑based systems (check‑in, baggage, ticketing, traffic‑management) are increasingly targeted, as shown by recent ransomware incidents.
  • Experts stress that aviation’s complex, shared‑responsibility environment makes risk mitigation difficult; legacy systems slow the adoption of modern security controls.
  • GAO recommends updating the TSA roadmap, improving FAA cyber‑budget reporting, implementing a detailed Zero Trust Architecture plan aligned with NIST, and strengthening monitoring, threat‑intelligence, and privileged‑user controls.
  • DHS and Transportation officials agree with the recommendations, but caution that validating changes in safety‑critical avionics takes years and must not compromise reliability.

GAO Warning on Aviation Cybersecurity
The Government Accountability Office (GAO) issued a report this month highlighting that the United States aviation infrastructure could become increasingly vulnerable to cyber‑attack. Titled “Aviation Cybersecurity: FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls,” the study acknowledges that the Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) do work together on cyber‑security, yet significant gaps remain. The GAO points out that while the FAA has clearly delineated roles and responsibilities, the TSA does not, and the FAA has not fully reported its cyber‑security spending or implemented its cyber‑security strategy. Even though seven FAA entities are tasked with executing the strategy, implementation is incomplete because the agency lacks a comprehensive process to monitor and evaluate progress toward its goals.

Current Collaboration and Gaps
Doc McConnell, head of Policy and Compliance at cybersecurity provider Finite State and a former CISA branch chief, cautioned against over‑interpreting the GAO findings as a definitive statement on aircraft security. He emphasized that aviation’s attack surface is highly complex, involving airlines, airports, air‑traffic controllers, and multiple layers of government. This shared‑responsibility model means no single organization can fully grasp or control the risk. McConnell noted that the GAO’s focus on governance, strategic planning, budgeting, and project‑implementation monitoring is sound, but the interconnected nature of the sector dilutes the impact of any one agency’s efforts.

Outdated TSA Roadmap
A major weakness identified by the GAO is the TSA’s reliance on a 2018 Cybersecurity Roadmap that no longer aligns with the Department of Homeland Security’s current Cybersecurity Strategy. The roadmap fails to designate which offices are responsible for implementing its objectives and does not define the agency’s cyber‑security roles concerning airport and aircraft‑operator security programs. Consequently, TSA’s ability to prioritize and coordinate cyber‑risk mitigation across the aviation subsector is hampered, leaving stakeholders without a clear, up‑to‑date framework.

Risk to Aircraft and Travelers
The GAO warns that heightened interconnectivity between onboard aircraft systems and ground‑based National Airspace System components raises the overall vulnerability to exploitation. Eliran Almog, CEO of CYVIATION (a Boeing‑partnered aviation cybersecurity firm), stated that connectivity is now the operating baseline, not a future threat. He cited GNSS spoofing and jamming in the Eastern Mediterranean, Black Sea, and Persian Gulf as daily occurrences that compromise safety‑critical navigation inputs without requiring direct network intrusion. While direct compromise of flight‑critical avionics remains unlikely in the near term, the expanding attack surface creates more opportunities for malicious actors.

Expert Views on Real‑World Threats
Damon Small, a board member at cybersecurity provider Xcape, observed that concerns about avionics hacking have persisted for nearly two decades. As fly‑by‑wire and other advanced avionics become more technology‑dependent, the potential attack vector grows, although no successful avionics cyber‑attack has been publicly reported. Jacob Krell of Suzu Labs emphasized that demonstrated risk is concentrated in ground infrastructure. He referenced the September 2025 ransomware hit on Collins Aerospace’s check‑in platform at several European airports, the 2024 Port of Seattle disruption affecting baggage and ticketing, and Thales’ report of 27 major ransomware attacks by 22 groups between January 2024 and April 2025—a 600% year‑over‑year increase in aviation‑sector ransomware. Of eight FAA systems reviewed by the GAO, only one possessed a current security‑authorization assessment. Krell warned that compromising the planning layer used by air‑traffic controllers could degrade situational awareness, disrupt routing, and trigger large‑scale ground stops, especially as AI‑driven traffic‑management tools become more prevalent.

GAO Recommendations
To address these shortcomings, the GAO called for the FAA and TSA to improve cyber‑threat intelligence collection, processing, dissemination, and reporting; enhance monitoring and detection; strengthen privileged‑user control and visibility; and develop capabilities for detecting and mitigating internal and external threats. It also urged the adoption of Zero Trust Architecture. Specifically, the GAO made five recommendations:

  1. The TSA Administrator should update the TSA Cybersecurity Roadmap to define roles and responsibilities for TSA entities executing the roadmap’s goals—including the aviation subsector—and align it with the DHS Cybersecurity Strategy, then communicate the updated roadmap to non‑federal stakeholders.
  2. The FAA Administrator should revise the agency’s cyber‑budget data request process to capture all cyber‑security spending from program offices.
  3. The FAA Administrator must ensure the updated Zero Trust Implementation Plan includes detailed steps for transitioning every operating environment to a zero‑trust model.
  4. The FAA Administrator should align the Zero Trust Implementation Plan with NIST best practices for migrating to zero trust.
  5. The FAA Administrator should direct the Cybersecurity Steering Committee to monitor implementation of the revised Cybersecurity Strategy, incorporate lessons learned, and ensure monitoring occurs as planned.

Stakeholder Reactions
Both the Departments of Homeland Security and Transportation have concurred with the GAO’s recommendations. John Strand of Black Hills Information Security praised the call to refresh the outdated 2018 roadmap, but reminded listeners that many aviation systems are decades old and undergo rigorous validation to guarantee reliability. He noted that the lengthy validation process slows the adoption of newer technologies and modern security controls, posing a core challenge: modernizing critical systems without sacrificing the dependability passengers expect.

Krell added that the FAA’s rollout of AI‑enabled traffic‑management platforms—set to influence routing for over 40,000 daily flights—lacks detailed zero‑trust transition steps for its research‑and‑development environment. He argued that merely updating documents and aligning with NIST is insufficient given the rapid expansion of attack surface driven by AI.

Almog reiterated that while network monitoring and identity management are essential ground‑infrastructure hygiene, the aircraft itself remains largely unmonitored. Modern airliners host networked assets such as e‑enabled avionics, electronic flight bags, satellite communications, ACARS, and maintenance laptops that plug directly into data buses. Because these components are not continuously watched like corporate networks, risk is distributed across airlines, MROs, lessors, and ground handlers who often lack visibility requirements.

Conclusion and Implications
The GAO’s report underscores that while collaboration between the FAA and TSA exists, significant governance, planning, and implementation gaps leave the U.S. aviation ecosystem exposed to cyber‑threats. Outdated strategies, incomplete budgeting, and insufficient monitoring hinder effective defense. Although no flight‑critical avionics breach has been documented, the increasing targeting of ground‑based systems and the potential spill‑over effects on air‑traffic safety demand urgent action. Implementing the GAO’s recommendations—particularly a modernized TSA roadmap, comprehensive FAA cyber‑budget transparency, and a rigorously tested Zero Trust Architecture—could enhance resilience. However, stakeholders caution that any security upgrades must be balanced against the stringent reliability and validation processes that keep aviation safe, ensuring that modernization does not inadvertently jeopardize the very safety it seeks to protect.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here