# Aviation Cybersecurity Under the Microscope: Federal Agencies Face Scrutiny Over Coordination, Budget, and Implementation Gaps
A comprehensive federal audit into aviation cybersecurity has revealed significant gaps in how two key federal agencies coordinate their efforts to protect the nation’s airspace infrastructure. The review examined the roles, responsibilities, funding management, and strategic implementation of cybersecurity measures across departments responsible for overseeing both civilian aviation operations and transportation security.
## Background: Why Aviation Cybersecurity Demands Attention
The modern aviation ecosystem relies on a vast and expanding web of interconnected digital systems. From ground-based air traffic control networks to the onboard systems of thousands of aircraft operating globally, every component of the aviation chain depends on secure, resilient cyber defenses. Unlike many other critical infrastructure sectors, aviation bridges multiple federal jurisdictions, creating a unique governance challenge that demands seamless cooperation between agencies.
Legislators recognized this complexity and embedded a specific review requirement into a major federal reauthorization bill passed in 2024, directing an independent oversight body to evaluate how well the relevant agencies are managing cybersecurity risks across the aviation domain.
## Findings: Role Clarity and Collaboration Gaps
One of the most striking findings centered on how responsibilities are defined and communicated. The agency tasked with overseeing the safety and efficiency of national airspace has clearly delineated its cybersecurity objectives, assigning specific roles and responsibilities to fulfill its mission. In contrast, the agency primarily responsible for transportation security — including activities at airports and in the immediate ground environment — has not established a comparable level of internal clarity around its cybersecurity duties.
This disconnect has had tangible consequences. Stakeholders from the airline industry and related aviation groups reported confusion about what the transportation security agency’s cybersecurity responsibilities actually entail, especially once passengers board aircraft and systems transition from ground-based oversight to airspace management. That ambiguity, according to the review, creates blind spots where risks could go unidentified or unaddressed.
## Budget Transparency: A Growing Concern
Financial management of cybersecurity resources emerged as another area of concern. Between fiscal years 2024 and 2026, the aviation safety agency requested funding ranging dramatically — from tens of millions to over ten billion dollars — to support cybersecurity operations and the management of aviation controls. However, the review raised questions about how transparently and clearly those funds are being allocated, particularly in research and development activities.
Cybersecurity budgets are inherently volatile, shifting constantly in response to evolving threat landscapes. Without clear visibility into how appropriated dollars are being spent from initial deployment through ongoing maintenance and updates, oversight bodies and legislators cannot confidently assess whether resources are being aligned effectively with actual risk levels.
## Strategy Implementation: Partial Progress
The aviation safety agency had outlined a cybersecurity strategy supported by seven key objectives. The review found that only three of those objectives had been fully implemented. The areas where progress was most evident included threat intelligence gathering, detection and mitigation capabilities, and investment in cybersecurity research and development.
However, significant gaps remained in areas critical to a mature security posture. Cybersecurity monitoring and incident response capabilities were found to be underdeveloped. Controls governing privileged user access — the individuals and systems with elevated permissions to sensitive aviation networks — also needed strengthening. These shortcomings point to a broader need for adopting more rigorous zero-trust security principles, which assume that no user or system should be inherently trusted regardless of its location within a network.
## The Transportation Security Agency’s Shortcomings
The transportation security-focused agency received its own set of recommendations, rooted in the same coordination challenges highlighted throughout the review. Its primary shortcoming involved the lack of a clearly articulated cybersecurity roadmap that defines its role relative to the aviation safety agency and makes that information readily accessible to industry stakeholders. Without such a roadmap, both internal teams and external partners operate with an incomplete understanding of the security architecture protecting aviation systems.
## Looking Ahead: What Congress Can Do
Perhaps the most encouraging finding was that both agencies expressed agreement with all recommendations issued by the review. Still, the authors emphasized that alignment on paper must translate into action on the ground. As the aviation sector grows more digitally interconnected each year, the stakes of a cybersecurity failure increase proportionally. No major cyber incident has yet disrupted air traffic control or ground transportation systems, but experts caution that proactive preparation is essential — reactive responses to a catastrophic event could have consequences that ripple across global aviation networks.
Congress, which originated the legislative mandate for this review, is expected to play a pivotal role in ensuring that agencies follow through on their commitments and implement the recommended changes across their entire operational environments, not just within the specific systems that were audited.
—
## Frequently Asked Questions (FAQ)
**Q: What prompted this review of aviation cybersecurity?**
A: A provision within the 2024 federal aviation reauthorization legislation directed an independent oversight body to examine how agencies responsible for aviation safety and transportation security manage cybersecurity risks across the aviation ecosystem.
**Q: Which two federal agencies were evaluated?**
A: The review examined the agency responsible for overseeing national airspace safety and efficiency, and the agency primarily tasked with securing transportation systems, including those operating at airports.
**Q: Why is coordination between these agencies important for aviation cybersecurity?**
A: Aviation operations involve a continuous chain of digital systems that span both ground and air environments. Security measures managed by one agency directly affect the systems and processes overseen by the other. A gap in coordination can leave vulnerabilities unaddressed as passengers and aircraft move between different operational domains.
**Q: What was the biggest finding regarding agency roles and responsibilities?**
A: One agency had clearly defined and communicated its cybersecurity roles, while the other had not, leading to confusion among industry stakeholders about who is responsible for specific security functions within the aviation network.
**Q: Were the agencies receptive to the recommendations?**
A: Yes. All recommendations issued during the review were agreed to by both agencies, signaling a willingness to address the identified weaknesses.
**Q: What are zero-trust principles, and why were they mentioned?**
A: Zero-trust is a security framework that operates on the assumption that no user, device, or system should be automatically trusted, even if it is already inside a network perimeter. The review recommended that agencies adopt these principles to strengthen access controls and reduce the risk of unauthorized activity within aviation systems.
**Q: How much funding was requested for aviation cybersecurity?**
A: Between fiscal years 2024 and 2026, funding requests ranged from approximately $42 million to over $11 billion, reflecting the broad scope of cybersecurity activities needed to protect aviation infrastructure.
**Q: What role does Congress play going forward?**
A: Because the review was initiated through legislation, Congress is expected to monitor implementation of the recommendations and provide policy guidance to ensure agencies fully address the identified gaps across their entire operational environments.
—
## Conclusion
Aviation cybersecurity sits at the intersection of national security, public safety, and global commerce. The findings from this federal audit underscore that even well-resourced agencies can struggle with role clarity, budget transparency, and the full implementation of cybersecurity strategies. As digital systems become more deeply embedded in every phase of flight — from check-in to cruising altitude — the need for coordinated, transparent, and comprehensive cybersecurity practices has never been more urgent. The recommendations now in hand offer a clear path forward, but their ultimate effectiveness will depend on sustained commitment from both agencies and the legislative bodies that hold them accountable.
Thank you for reading



