A new audit reveals that federal agencies tasked with safeguarding U.S. travel infrastructure against major cyberattacks have only partially implemented critical security upgrades.
Despite sharing responsibility with the Transportation Security Administration to regulate cybersecurity for critical infrastructure, the Federal Aviation Administration has failed to update its surveillance monitoring and identity management systems. The TSA has yet to establish or execute a clear plan to secure passenger-facing equipment and networks, according to the report.
The resulting mixed signals and conflicting directives, spanning FAA standards and TSA guidelines, frustrate industry stakeholders and leave systemic vulnerabilities exposed just as state actors and cybercriminals actively seek to disrupt the U.S. travel ecosystem.
Compounding these challenges, aviation operators are bracing for upcoming reporting mandates under the Cyber Incident Reporting for Critical Infrastructure Act, currently being finalised by CISA.
As onboard Wi-Fi, satellite communications, and integrated operational cabins expand the industry’s digital footprint, new security gaps emerge daily. Yet even modern overhaul initiatives fall short. While the FAA’s ongoing NextGen program aims to optimise air traffic control systems, it entirely omits crucial cyber and physical security upgrades.














