Last week the senior level official at the European Aviation Safety Agency (EASA) established what has been dubbed a cyber SWAT team in an effort to combat the continuous changing suite of cyber threats against aviation.
Clearly, this moves well beyond the traditional role organizations around the world have played. This takes place as aviation authorities all over the world have and continue to state that at this time a verified cyberattack by an individual or a group has never successfully hacked a commercial airliner’s systems (power or flight-control systems) while the aircraft was operating and airborne.
Not everyone is comforted. Some cybersecurity experts have expressed concerns about the continuously growing threats posed by cyberattacks that target or use an aircraft’s connections to ground-based systems, networks, and services that are commonly used for maintenance, navigation and even cabin entertainment. Some talk about the risk of aviation systems becoming compromised and impacting the flight control systems that could result in a crash. (See one example here.)
INTEL: In June 2015 Polish national carrier LOT notified Poland’s domestic intelligence agency that a cyberattack had disabled the system LOT uses for issuing flights plans.
Many people wonder if Malaysia Airlines Flight 370 (which disappeared back on March 8, 2014) may have fallen victim to a successful cyberattack against its onboard systems. Others point to Spanair flight JK 5022 that crashed on take-off killing all 172 on board way back on August 20, 2008. Malware that affected warning systems has been implicated in that crash.
The actions by the EASA should be applauded as the concerns over air transportation cyber security are certainly well founded! However, the question remains: is this enough?




