The Government Accountability Office (GAO) warned this month that the United States aviation infrastructure could be increasingly subject to a cyberattack. The new report, “Aviation Cybersecurity: FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls,” noted that although the Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) collaborate on aviation cybersecurity, there are still potential gaps.
“While FAA has clearly defined roles and responsibilities, TSA does not. FAA hasn’t fully reported its cybersecurity spending or implemented its cybersecurity strategy, among other things,” the GAO emphasized.
Even as seven FAA entities are responsible for implementing its cybersecurity strategy, it hasn’t been fully put into practice, in part because the agency lacked a comprehensive process to monitor and evaluate the implementation of its goals.
“This GAO report focuses on key elements of cybersecurity governance at TSA and FAA, including strategic planning documents, budgeting, and monitoring project implementation. These recommendations are all sound, but I would caution against using this report to draw too firm a conclusion on aircraft security,” said Doc McConnell, head of Policy and Compliance at cybersecurity provider Finite State, and a former CISA branch chief.
“Aviation has a complex attack surface, with interconnections, communications, and data sharing among airlines, airports, traffic controllers, and governments at the local, state, federal, and international levels,” McConnell told ClearanceJobs. “That type of shared responsibility model means that no one organization is going to have a perfect understanding or control over the risk.”
Outdated Roadmap
The issue is made worse by the fact that the TSA last defined its goals and objectives for prioritizing cybersecurity in its 2018 Cybersecurity Roadmap.
“The roadmap is outdated and no longer aligned with the latest Department of Homeland Security Cybersecurity Strategy. The roadmap also does not identify the offices responsible for implementing it or define the agency’s cybersecurity-related roles and responsibilities in overseeing airport and aircraft operator security programs,” the D.C.-based watchdog added in its report.
Are Planes and Travelers at Risk?
The GAO further warned that although interconnected systems that reside onboard an aircraft and on the ground in the National Airspace System, due to increased interconnectivity, these systems are inherently more vulnerable to exploitation and are at an increased risk of being targeted by malicious actors.
“We’re already there. The question is whether anyone is measuring it,” said Eliran Almog, CEO of CYVIATION, an aviation cybersecurity company with Boeing as a strategic partner.
Almog told ClearanceJobs that connectivity is the current operating baseline, not a future risk.
“The industry’s answer has been domain segregation, which is sound in principle but is a static defense against a dynamic threat,” said Almog, who noted that the clearest live example is GNSS: spoofing and jamming around the Eastern Mediterranean, Black Sea and Persian Gulf has gone from anomaly to daily occurrence, with crews reporting false position fixes.
“That’s an attack on a safety-critical navigation input, happening on commercial routes now – and it proves the aircraft is attackable without anyone touching its network,” Almog warned.
Does that mean an aircraft could be hacked, and we could face a real-time ransomware attack against a commercial aircraft?
“Among cybersecurity professionals, this has been a concern for nearly 20 years,” explained Damon Small, board member at cybersecurity provider Xcape. “As avionics become more sophisticated and rely more heavily on technology – think ‘fly-by-wire’ – the risk of that technology becoming an attack vector increases.”
However, direct compromise of flight-critical avionics remains less likely as a near-term scenario, and the GAO found no reported successful cyberattacks against avionics.
Yet, increasing connectivity creates more opportunities for attack, and the demonstrated risk is concentrated in ground infrastructure, suggested Jacob Krell, senior director for Secure AI Solutions & Cybersecurity at Suzu Labs.
Krell told ClearanceJobs that the hacking may target other aspects of the commercial airline industry.
“Collins Aerospace’s check-in platform was hit across several European airports in September 2025, forcing manual processing,” said Krell. “The Port of Seattle’s 2024 incident disrupted baggage, kiosks, and ticketing. Thales reported 27 major ransomware attacks by 22 groups between January 2024 and April 2025, alongside a 600% year-over-year increase in aviation-sector ransomware attacks. Of eight selected FAA systems the GAO reviewed, only one had a current security-authorization assessment.”
Moreover, ransomware does not need to seize control of an aircraft to create a safety concern.
“Compromising the planning layer that controllers and traffic managers will increasingly depend on could degrade situational awareness, disrupt routing, and force large-scale ground stops,” Krell continued. “As AI becomes embedded in traffic-management workflows, the distance between an IT outage and an aviation-safety event shrinks.”
GAO Recommendations
To address the cybersecurity threats, the GAO called for the FAA and TSA to improve cyber threat intelligence collection, processing, dissemination, and reporting; to improve monitoring and detection; and to improve privileged user control, monitoring, and visibility, as well as capabilities for detection and mitigation of threats, internal and external. The watchdog further called for the development and implementation of “Zero Trust Architecture” capabilities.
The GAO also made five recommendations:
- The Administrator of TSA should update the TSA Cybersecurity Roadmap to define the roles and responsibilities for the TSA entities responsible for carrying out the goals and objectives described within it, including for the aviation subsector, and align the roadmap with the DHS Cybersecurity Strategy. The TSA Administrator should communicate its Cybersecurity Roadmap to appropriate non-federal stakeholders.
- The Administrator of the FAA should update the agency’s cyber budget data request process to ensure that it includes all cybersecurity spending from program offices.
- The Administrator of the FAA should ensure that the agency’s updated Zero Trust Implementation Plan includes detailed steps for transitioning all operating environments to a zero trust architecture.
- The Administrator of the FAA should ensure that the agency’s updated Zero Trust Implementation Plan fully aligns with NIST best practices for migrating to a zero trust architecture.
- The Administrator of the FAA should direct the agency’s Cybersecurity Steering Committee to take steps, as the agency implements its revised Cybersecurity Strategy, to ensure it carries out monitoring as planned and incorporates lessons learned from its past experiences.
Expert Reactions
The Departments of Homeland Security and Transportation have agreed with GAO’s recommendations to TSA and FAA, respectively, the watchdog acknowledged.
“The GAO’s recommendations are fantastic. The roadmap that was originally laid out in 2018 is incredibly out of date, and it absolutely needs to be revisited,” said John Strand, owner of Black Hills Information Security.
Strand told ClearanceJobs that the overall recommendations are solid, but added, “One thing people often forget is the reality of the systems we’re talking about. Many of them are decades old, and for good reason they go through extremely rigorous validation. These are systems where reliability is everything. They have to work with virtually no downtime, and every change has to be thoroughly tested before it can be deployed.”
The other downside is that this validation process moves slowly.
“It takes years to introduce newer technologies, stronger security controls, and modern defensive capabilities into aircraft systems,” Strand continued. “That’s one of the biggest challenges the aviation industry faces today. Improving security isn’t just about identifying what needs to change. It’s about finding a way to modernize these critical systems without compromising the reliability that passengers depend on.”
Suzu Labs’ Krell further told ClearanceJobs that he has seen this pattern play out across sectors deploying AI, where capability ships fast, only for security to follow on a timeline nobody funds.
“The FAA is introducing AI-enabled traffic-management platforms that will influence routing and traffic-management decisions across a system handling more than 40,000 daily flights, and the agency’s zero-trust plan did not include detailed transition steps for its research and development operating environment,” Krell suggested. “Updating documents and aligning with NIST is necessary. It isn’t sufficient for the pace at which AI is adding attack surface.”
The recommendations may be directionally right but are still too narrowly scoped.
“Network monitoring and identity management at the FAA are foundational hygiene – necessary, but they address ground infrastructure,” said Almog. “The aircraft itself is missing. A modern airliner is a networked asset: e-enabled avionics, EFBs, satcom, ACARS, maintenance laptops plugging directly into aircraft data buses. Almost none of it is continuously monitored the way a corporate network is. GAO also frames this as a federal-agency problem, when the risk is distributed across operators, MROs, lessors and ground handlers who have no visibility requirement at all.”



