The cyber risk of aviation: a problem that hides on the ground
The cyber risk in aviation is a complex problem that is often misunderstood. According to Eliran Almog, CEO of Cyviation, financial losses resulting from cyber attacks mainly occur on the ground, while airplanes remain largely unmonitored. This gap creates a situation where airlines are exposed to significant risks without adequate defenses.
Ground vulnerabilities and the importance of the data supply chain
Almog emphasizes that most financial losses resulting from cyber attacks occur on the ground, where bookings, maintenance operations, personnel planning, and airport operations are managed. These systems are often targets of ransomware and other cyber attacks. In contrast, the airplanes themselves have not caused material losses for airlines so far.
However, airplanes are not entirely irrelevant. They constantly consume data from the ground, such as navigation databases, performance data, content for the Electronic Flight Bag (EFB), and loadable software. This data forms a supply chain that is not adequately monitored. The real challenge is not so much the "hacking" of an airplane in flight, but rather the security of the data supply chain that powers the airplane.
GNSS jamming: an attack that evades traditional monitoring systems
One of the behaviors of attackers that surprises traditional security operations center (SOC) analysts is the jamming of the Global Navigation Satellite System (GNSS). This type of attack leaves no trace in traditional monitoring systems such as SIEM (Security Information and Event Management). Pilots can receive false positions or inertial systems can degrade, requiring maintenance upon landing. However, there are no logs or alerts in the monitoring systems, making it difficult for analysts to detect and respond to these attacks.
The vulnerability of PX4 Autopilot and the importance of authentication
Another example of vulnerability in the aviation sector is the CVE-2026-1579 in PX4 Autopilot, the flight control software used in a wide range of drones and UAVs. This software accepts unsigned messages, allowing an attacker on the same network to control the aircraft. The vulnerability does not require a sophisticated exploit chain, but simply exploits the fact that the system does not authenticate commands.
This example illustrates a broader problem in the aviation sector: many systems critical to safety do not have authentication mechanisms. Instead of trying to bypass protections, attackers can simply exploit the lack of authentication to take control of systems.
The Electronic Flight Bag and the data supply chain
The Electronic Flight Bag (EFB) is a tablet used by pilots to access performance data and navigation charts. Although it is an underrated point of entry, the real exposure lies in the data supply chain that powers it. This chain is the same one that provides loadable software to airplanes. The challenge is to ensure the integrity and provenance of the data loaded and the ability to reconstruct what was loaded later. Most operators are unable to do either.
The need for digital twins for aircraft security
Almog suggests the use of digital twins to improve aircraft security. Digital twins allow modeling of the aircraft's subsystems and communication paths so that loadable parts can be tested against hostile inputs before they reach the fleet or to reproduce an event to determine if it was caused by a cyber attack or a malfunction.
Digital twins can help map vulnerabilities and attack techniques against a framework like AV-ATT&CK, an extension of MITRE ATT&CK specific to aviation. This framework covers techniques such as GPS spoofing and TCAS (Traffic Collision Avoidance System) manipulation.
Management of operational data and trust between parties
Airlines are often reluctant to share operational data with aircraft manufacturers (OEMs) for commercial reasons. Cyviation addresses this problem by keeping the infrastructure isolated for each customer, ensuring that one airline's data never comes into contact with another's. Analyses are performed under the user's control and only specific results are shared.
A credible security program for an airline with 30 aircraft
For an airline with 30 aircraft and only two people in the cybersecurity team, the priority should be threat management, detection engineering, and aircraft visibility. The first phase should be a complete inventory of the software present on the fleet and its dependencies. Next, it should focus on the security of ground systems, such as implementing multi-factor authentication (MFA) and managing administrative access and vendors.
Finally, the airline should invest in aircraft visibility, purchasing monitoring solutions rather than developing them internally. A shared digital twin can help respond quickly to incidents without the need for long and complex investigations. It is also essential to draft an incident response plan to be prepared to manage the first hours of an attack.
The cyber risk in aviation is a complex problem that requires a balanced approach. Airlines must invest in the security of ground systems, where financial losses are more likely, and improve the visibility and security of aircraft through the use of digital twins and other technological solutions. The management of operational data and trust between parties is crucial for ensuring an effective and sustainable approach to cybersecurity.
The cyber risk of aviation: a problem that hides on the ground
The cyber risk in aviation is a complex problem that is often misunderstood. According to Eliran Almog, CEO of Cyviation, financial losses resulting from cyber attacks mainly occur on the ground, while airplanes remain largely unmonitored. This gap creates a situation where airlines are exposed to significant risks without adequate defenses.
Ground vulnerabilities and the importance of the data supply chain
Almog emphasizes that most financial losses resulting from cyber attacks occur on the ground, where bookings, maintenance operations, personnel planning, and airport operations are managed. These systems are often targets of ransomware and other cyber attacks. In contrast, the airplanes themselves have not caused material losses for airlines so far.
However, airplanes are not entirely irrelevant. They constantly consume data from the ground, such as navigation databases, performance data, content for the Electronic Flight Bag (EFB), and loadable software. This data forms a supply chain that is not adequately monitored. The real challenge is not so much the "hacking" of an airplane in flight, but rather the security of the data supply chain that powers the airplane.
GNSS jamming: an attack that evades traditional monitoring systems
One of the behaviors of attackers that surprises traditional security operations center (SOC) analysts is the jamming of the Global Navigation Satellite System (GNSS). This type of attack leaves no trace in traditional monitoring systems such as SIEM (Security Information and Event Management). Pilots can receive false positions or inertial systems can degrade, requiring maintenance upon landing. However, there are no logs or alerts in the monitoring systems, making it difficult for analysts to detect and respond to these attacks.
The vulnerability of PX4 Autopilot and the importance of authentication
Another example of vulnerability in the aviation sector is the CVE-2026-1579 in PX4 Autopilot, the flight control software used in a wide range of drones and UAVs. This software accepts unsigned messages, allowing an attacker on the same network to control the aircraft. The vulnerability does not require a sophisticated exploit chain, but simply exploits the fact that the system does not authenticate commands.
This example illustrates a broader problem in the aviation sector: many systems critical to safety do not have authentication mechanisms. Instead of trying to bypass protections, attackers can simply exploit the lack of authentication to take control of systems.
The Electronic Flight Bag: An Underrated Point of Access
The Electronic Flight Bag (EFB) is often considered an underrated point of access, but the real threat lies in the data loading chain. EFBs are tablet devices used by pilots to access performance data and navigation charts, but the security of the data loading chain is crucial. The ability to verify the integrity and provenance of the data loaded and to reconstruct what was loaded is essential to prevent attacks.
The Importance of Digital Twins
Digital twins represent a promising solution to improve aircraft security. These digital models allow testing of loadable parts against hostile inputs before they reach the fleet or reproducing events to determine if they were caused by cyber attacks or malfunctions. Digital twins can be mapped against frameworks like AV-ATT&CK, which covers attack techniques specific to aviation, such as GPS spoofing and TCAS manipulation.
Management of Operational Data and Trust Between Parties
Management of operational data is a critical aspect for aviation security. Airlines are often reluctant to share operational data with aircraft manufacturers for commercial reasons. Solutions like isolated infrastructure for each customer can ensure that one airline's data never comes into contact with another's, maintaining trust between parties.
A Security Program for Medium-Sized Airlines
Investing in aircraft visibility through monitoring solutions and the use of shared digital twins can help respond quickly to incidents without the need for long and complex investigations. Drafting an incident response plan is essential to be prepared to manage the first hours of an attack.
The cyber risk in aviation requires a balanced approach that takes into account both the security of ground systems and that of aircraft. Airlines must invest in advanced technological solutions such as digital twins and ensure the secure management of operational data. Collaboration between the parties involved and the creation of an incident response plan are fundamental to ensuring an effective and sustainable approach to cybersecurity.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.