{"id":28341,"date":"2025-08-05T10:34:51","date_gmt":"2025-08-05T14:34:51","guid":{"rendered":"https:\/\/ops.group\/blog\/?p=28341"},"modified":"2025-08-13T07:36:11","modified_gmt":"2025-08-13T11:36:11","slug":"cybersecurity-in-bizav-a-growing-operational-risk","status":"publish","type":"post","link":"https:\/\/ops.group\/blog\/cybersecurity-in-bizav-a-growing-operational-risk\/","title":{"rendered":"Cybersecurity in Aviation: Growing Operational Risk"},"content":{"rendered":"<h4 class=\"p1\">Aviation is under fire<\/h4>\n<p class=\"p1\">A <a href=\"https:\/\/www.thalesgroup.com\/en\/worldwide\/aerospace\/press_release\/aviation-sector-sees-600-year-year-increase-cyberattacks?utm_source=chatgpt.com\"><span class=\"s1\">recent study<\/span><\/a>\u00a0recorded a 600% increase in attacks on the aviation sector year-on-year. 71% of these involved credential theft or unauthorised access to critical systems.<\/p>\n<p class=\"p1\">The FBI also <a href=\"https:\/\/www.forbes.com\/sites\/emilsayegh\/2025\/07\/06\/fbi-sounds-alarm-as-airline-cyber-threats-escalate\/\"><span class=\"s1\">warned<\/span><\/a> on June 28 that a cybercriminal group called \u2018Scattered Spider\u2019 had turned its attention toward the aviation sector, using impersonation to compromise security.<\/p>\n<div id=\"attachment_28351\" style=\"width: 539px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-28351\" class=\"wp-image-28351 size-full\" src=\"https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/FBI.png\" alt=\"\" width=\"529\" height=\"473\" srcset=\"https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/FBI.png 529w, https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/FBI-300x268.png 300w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><p id=\"caption-attachment-28351\" class=\"wp-caption-text\">The alert was issued on X.<\/p><\/div>\n<p class=\"p1\">Protecting ourselves from these attacks has become a <b>multi-million dollar<\/b> industry.<\/p>\n<p class=\"p1\">High profile attacks in recent months have impacted both <a href=\"https:\/\/www.bbc.com\/news\/articles\/c87e0ydy3d4o\"><span class=\"s1\">Aeroflot<\/span><\/a> and <a href=\"https:\/\/www.stuff.co.nz\/travel\/360751635\/full-extent-qantas-cyber-attack-has-been-revealed-57m-customers-affected\"><span class=\"s1\">Qantas<\/span><\/a>, the latter likely carried out by none other than Scattered Spider &#8211; the group the FBI are worried about.<\/p>\n<h4 class=\"p1\"><b>The FAA is paying attention<\/b><\/h4>\n<p class=\"p2\">There has been a response to this growing risk.<\/p>\n<p class=\"p2\">There is an obvious intent to <b>include cyber security in future regulations.<\/b> While not yet law, recent advisories and bulletins make it clear that operators are expected to begin taking proactive steps.<\/p>\n<p class=\"p2\">A good place to start is <a href=\"https:\/\/www.faa.gov\/regulations_policies\/advisory_circulars\/index.cfm\/go\/document.information\/documentID\/1042159\"><span class=\"s1\">AC 119-1A<\/span><\/a> which provides an overview of cyber security requirements, risk assessments and best practices. Also keep an eye out for cyber threat alerts which can be published by SAFO, Notam or other notices.<\/p>\n<p class=\"p2\">The FAA is also actively working with ICAO and other agencies to <b>harmonise future cyber protection practices<\/b> under Annex 17 (Security).<\/p>\n<h4 class=\"p1\"><b>What about business aviation? <\/b><\/h4>\n<p class=\"p1\">The examples above relate to attacks on larger airlines and IT infrastructure. A valid question remains then, what does this all mean for biz av?<\/p>\n<p class=\"p1\">While not a traditional target, many business aviation operators <b>lack<\/b> <b>dedicated IT departments or cyber defence teams. <\/b>We also frequently carry high-net worth individuals on sensitive operations which may motivate nefarious cyber activity.<\/p>\n<p class=\"p1\">Recent reports from the industry show that biz av isn&#8217;t immune:<\/p>\n<p class=\"p1\">In 2020, a major manufacturer of business jets <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dassault-falcon-jet-reports-data-breach-after-ransomware-attack\/\"><span class=\"s1\">confirmed<\/span><\/a> a cyber-security breach that compromised personal and aircraft ownership information.<\/p>\n<p class=\"p1\">Another example from May this year involved a Europe-based private jet operator which <a href=\"https:\/\/cybernews.com\/security\/private-charter-ransomware-attack-data-leaked\/\"><span class=\"s1\">appeared<\/span><\/a> on a ransomware group&#8217;s leak site. Sensitive crew info was shared, which reportedly included passport photos.<\/p>\n<p class=\"p1\">It\u2019s clear that business aviation is <strong>not under the radar<\/strong> &#8211; therefore we must remain measured but cautious in our approach to emerging cyber threats.<\/p>\n<h4 class=\"p1\"><b>EFBs &#8211; A Soft Target?<\/b><\/h4>\n<p class=\"p1\">Feedback from industry experts and OPSGROUP members suggest that a closer look at the electronic security of EFBs warrants a <strong>closer analysis.<\/strong><\/p>\n<div id=\"attachment_28347\" style=\"width: 1210px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-28347\" class=\"size-full wp-image-28347\" src=\"https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/20230416_172530_1200x1200.webp\" alt=\"\" width=\"1200\" height=\"900\" srcset=\"https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/20230416_172530_1200x1200.webp 1200w, https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/20230416_172530_1200x1200-300x225.webp 300w, https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/20230416_172530_1200x1200-1024x768.webp 1024w, https:\/\/ops.group\/blog\/wp-content\/uploads\/2025\/08\/20230416_172530_1200x1200-768x576.webp 768w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><p id=\"caption-attachment-28347\" class=\"wp-caption-text\">The role of EFBs in cyber crime warrants a closer analysis.<\/p><\/div>\n<p class=\"p1\">Eye-opening research, such as the <a href=\"https:\/\/www.securityweek.com\/airbus-app-vulnerability-introduced-aircraft-safety-risk-security-firm\/\"><span class=\"s1\">work conducted<\/span><\/a> by Cyber Security Consultancy Pen Test Partners, has highlighted that EFBs could act as an additional gateway for cyber crime if not <strong>correctly managed.<\/strong><\/p>\n<p class=\"p1\">Look out for an dedicated article on this subject soon.<\/p>\n<h4 class=\"p1\"><b>An extra tip &#8211; don\u2019t forget your SMS<\/b><\/h4>\n<p class=\"p1\">If your flight department operates under an SMS, it may be wise to include cyber security.<\/p>\n<p class=\"p1\">This means treating digital threats like any other hazard &#8211;<b> reportable, measurable and mitigable.<\/b><\/p>\n<p class=\"p1\">It\u2019s important we take steps now to keep our operations secure.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Aviation is under fire A recent study\u00a0recorded a 600% increase in attacks on the aviation&#8230;<\/p>\n","protected":false},"author":49,"featured_media":28365,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[2304,2305],"class_list":{"0":"post-28341","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-briefings","8":"tag-cyber","9":"tag-cybersecurity"},"_links":{"self":[{"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/posts\/28341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/users\/49"}],"replies":[{"embeddable":true,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/comments?post=28341"}],"version-history":[{"count":20,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/posts\/28341\/revisions"}],"predecessor-version":[{"id":28392,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/posts\/28341\/revisions\/28392"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/media\/28365"}],"wp:attachment":[{"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/media?parent=28341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/categories?post=28341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ops.group\/blog\/wp-json\/wp\/v2\/tags?post=28341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}