Spread the love

Armis - logoRecent cyberattacks in the transportation and logistics area have thrown the aviation industry into the spotlight. Cyberattacks in the transport sector worldwide have further exposed critical vulnerabilities in Australian airport operations.

With flight delays, cancellations, and other airport services being offline, attacks that impact the industry highlight the pressing need for airports to bolster their cybersecurity defences.

The Broader Implications for Critical Infrastructure

The increase in severity and number of cyber security incidents underscore the fragile nature of the aviation industry and its susceptibility to cyber threats. The Security of Critical Infrastructure Act 2018 (SOCI) outlines clear regulatory obligations and recognises critical infrastructure assets, including airports and airlines, as prime targets for cyberattacks.

Airports rely on complex networks of interconnected systems, including Information Technology (IT), Operational Technology (OT), and Internet of Things (IoT) devices. The IT systems encompass traditional computing and data processing, and OT systems control cyber-physical operations like baggage handling and air traffic control. At the same time, IoT devices include sensors, cameras, and intelligent systems increasingly embedded within the airport and airline infrastructure. The convergence of these technologies creates a highly interconnected environment where a breach in one system can have cascading effects across the entire airport.

Given the essential role that airports and airlines play in global transportation and trade, the consequences of a cyberattack can be far-reaching, impacting not only travellers but also airlines, logistics, and supply chains. Such attacks highlight the need for airports and airlines to rethink their cybersecurity approach, focusing on gaining visibility, security, and control over all devices and assets.

Ten Steps Airports Can Take to Enhance Visibility, Security, and Control

  1. Comprehensive Asset Inventory: Transportation and logistics operators must create a detailed inventory of all IT, OT, and IoT devices connected to their networks. This includes everything from servers and workstations to baggage handling systems, surveillance cameras, and HVAC systems. Understanding the scope of their digital infrastructure and the interconnections between them is the first step toward securing it. Tools that offer automated discovery and continuous monitoring of assets can help ensure that no device goes unnoticed.
  2. Zero Trust Architecture – Adopting a Zero Trust approach by assuming that every device, user, and application is a potential threat until proven otherwise. Airports and carriers should implement multi-factor authentication (MFA), identity and access management (IAM) solutions, and continuous monitoring to ensure that only authorised personnel and devices can access sensitive systems to the level their job requires.
  3. Real-Time Monitoring and Threat Detection—Airports and airlines must deploy advanced threat detection systems to monitor real-time asset behaviour and network traffic and identify suspicious activities. These systems should be capable of detecting known and unknown threats using behavioural analysis, anomaly detection, and artificial intelligence/machine learning techniques. Early detection is critical to mitigating the impact of a cyberattack and preventing widespread disruption.
  4. Network Segmentation—Segmenting the network is crucial for containing potential breaches. By isolating critical systems, such as air traffic control and baggage handling, from less critical systems, airports can prevent a cyberattack from spreading across the entire network. Implementing strict access controls and limiting communication between segments can further reduce the risk of attackers’ lateral movement.
  5. Patch Management and Vulnerability Assessment – Keeping systems up-to-date with the latest security patches is fundamental to cybersecurity. Airports and airlines should implement a robust patch management process that ensures vulnerability detection, deduplication, prioritisation, assignments and timely updates to all software and firmware. Regular vulnerability and security assessments can help identify and address potential weaknesses in prioritising a “business risk” before attackers can exploit them.
  6. Incident Response Planning –  A well-defined incident response plan is critical for minimising the impact of a cyberattack. Airports and carriers should have a dedicated incident response team with clear protocols for identifying, containing, and remediating threats. Regular drills and simulations can help ensure staff are prepared to respond effectively during cyber incidents.
  7. Collaboration and Information Sharing – Airports and carriers should collaborate with government agencies, industry partners, and cybersecurity organisations to share information about emerging threats and best practices. One of the key sources includes the Trusted Information Sharing Network (TISN), administered by the Australian Government, which enables critical infrastructure owners and operators to share information on threats and vulnerabilities.
  8. Employee Training and Awareness – Human error remains one of the leading causes of cybersecurity breaches. The transportation and logistics industry must invest in regular training programs to educate employees about the latest cyber threats and the importance of following security protocols. Employees should be trained to recognise phishing attempts, suspicious links, and other common attack vectors.
  9. Physical Security Integration—Cybersecurity and physical security should be integrated to provide a holistic approach to protecting airport and airline infrastructure. This includes securing access to critical areas, such as server rooms and control centres, and monitoring physical access to IoT devices. Combining physical and cyber threat intelligence can provide a more comprehensive view of potential risks.
  10. Resilience and Recovery Planning—Airports must also focus on resilience and recovery in addition to preventing cyberattacks. This includes developing backup systems, redundant communication channels, and disaster recovery plans that can help restore operations quickly during a cyber incident. Regular testing of these plans is essential to ensure their effectiveness.

The increase in cyberattacks impacting the passenger transport area should serve as a wake-up call for the aviation industry. The need for robust cybersecurity measures becomes more urgent as the transportation industry becomes increasingly digitised. In a time when cyberattacks can disrupt global transportation networks, securing critical infrastructure starts with a robust cyber asset attack surface management (CAASM) program that encompasses the entire digital footprint of all operations.

 

 

 

Written by: Carlos Buenaño, CTO, OT, Armis

 

 

BIO: 
Carlos Buenaño is the Chief Technology Officer for the Operational Technology (OT) vertical at asset intelligence cybersecurity company Armis. With more than 30 years of progressive experience in the control systems and telecommunications field, Carlos’ history includes positions such as Principal Systems Engineer, Senior ICS Cybersecurity Consultant, Solutions Architect and Technical Account Manager and Principal Solutions Architect. Carlos has been actively involved in several brown and green field industrial control systems projects in Manufacturing, mining and Oil and Gas, from the concept definition to the commissioning stages of the projects. The last 5 years of his career have been focused on operationalising cybersecurity Solutions on industrial networks. He possesses a degree in Electronic Engineering and a master’s degree in telecommunications.

 

 

 

 

 

=====================================