Listen to this episode

Elevating Airline Safety with Next-Gen Cybersecurity Measures

0:0045:37

Recorded March 2024. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Host Craig Petronella and Blake welcome Sige Brody, co-founder of Webair and part-time chief technology officer of Optinine, to the Petronella Technology Group podcast. Brody explains Optinine's focus on managed cloud, backups, disaster recovery, and outsourced accountability for infrastructure.

He describes his consulting work with Sidiation, a company performing vulnerability assessments on physical aircraft, and argues that aviation lags other industries on vendor diligence and security. He details attack vectors including unauthenticated radio frequency communications, GPS jamming and spoofing, and physical access to onboard systems, and he outlines how a ransomware strain could target avionics through vendor laptops. The conversation covers aviation cybersecurity rules, including a European regulation that, at the time of recording, was set to go live in October 2025, plus TSA requirements in place at the time of recording. Brody also calls zero trust overhyped marketing, stresses managing IT complexity, considers securing space-based infrastructure, and urges organizations to decide whether to own security accountability or outsource it.

Worth remembering

Key takeaways

  1. Brody explains that aircraft radio frequency messages are unencrypted and unauthenticated, so a powerful transmitter can feed planes false data they assume is accurate.
    “planes and the ground and satellite sending RF type of signals and these RF based messages are unencrypted and unauthenticated”
  2. Brody recounts a three-week period when over 20 commercial and business aircraft were GPS spoofing victims and thought they were about 80 nautical miles off.
    “there was a period of about three weeks where about over 20 commercial and business aircraft were the victims of GPS spoofing”
  3. Brody says aviation has almost no vendor diligence, so attackers could compromise the laptops vendors plug into aircraft and plant ransomware.
    “Now, unfortunately, there is almost no vendor diligence in this industry.”
  4. Brody highlights a European aircraft cybersecurity regulation, PartIS, that at the time of recording was set to go live in October 2025 with familiar requirements.
    “the requirements that IASA is putting out, which is called the PartIS and it goes live in October of 25”
  5. Brody describes how Optinine uses machine learning on backup configurations to spot suspicious changes that predict ransomware and automatically air gap offsite backups.
    “because those things are happening before the ransomware takes place, it would be a predictor of a ransomware attack”
  6. Brody argues zero trust has become an overhyped marketing term and warns against assuming that adopting it alone makes an organization secure.
    “Zero trust has been, you know, overly it's turned into this overhyped marketing term.”
  7. Brody urges organizations to decide whether they will own accountability for managing infrastructure and security or hold a vendor accountable through an SLA.
    “do we have an appetite to take ownership and accountability of managing X, y and Z”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Prepare to navigate the turbulent skies of cybersecurity with Sige Brody, CTO of Optinine, as we unpack the pressing dangers and defenses within the aviation sector. Discover how Optinine's managed cloud computing services are revolutionizing the way airlines protect their most valuable assets, with a focus on robust disaster recovery and business continuity. Our journey will reveal the startling reality that, while commercial airlines protect company data like Fort Knox, their fleets might be flying with a target on their backs due to unencrypted communications and GPS spoofing threats.

As the conversation ascends, we examine the tightening mesh of regulations set to envelop European aviation by 2025 and contrast them with the FDA's slower pace. This segment dissects the curious paradox of current cybersecurity measures, where the commercial airline industry's crown jewels remain exposed to potential cyber-attacks. With Sige's guidance, we'll explore inventive solutions to these vulnerabilities, such as how backup software can serve as an early warning system against ransomware by detecting unusual patterns.

Finally, we chart a course through the future of aviation cybersecurity, scrutinizing the overhyped nature of zero trust and the expanding roles of IT managers in smaller organizations. We'll touch down on the need for simplified security architectures and the thrilling new frontier of space-based infrastructure, pondering the security implications of satellites and other celestial tech advancements. Sige Brody ensures this episode is a first-class ticket to understanding the complex, ever-evolving realm of aviation cybersecurity.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.