Securing the Connected Aircraft: The Shift from Physical to Digital Airworthiness
Historically, “airworthiness” referred to mechanical integrity, covering everything from aircraft rivets to engines. Today, the definition has fundamentally shifted: Today’s aircraft need to be “digitally airworthy” to resist a rising tide of cyber attacks.
Here’s the problem: A modern aircraft is a “flying data center,” a node in a massive, interconnected global network. Here’s the paradox: The connectivity that drives operational efficiency (predictive maintenance, real-time flight paths, and passenger Wi-Fi) creates the very vulnerabilities that threaten flight safety.
Adding to the challenge is the “Black Hole” of aviation security. Unlike enterprise IT, where systems are constantly being scanned for cyber threats, aircraft systems have historically been opaque once the plane leaves the factory. “Usually what happens with airlines and aircraft is that it’s out of scope on what you can gather information on because it’s so complex,” said Roy Arad, Chief Revenue Officer (CRO) with Cyviation. This is precisely why Cyviation creates “digital twins” of aircraft to assess vulnerabilities to cyber attacks without having to probe actual onboard systems.
Today, the world’s aviation industry is in a race against time to bridge the gap between legacy airframe designs and modern, sophisticated cyber threats. This article explores the vulnerabilities, the actors, and the defensive strategies required to maintain the safety of the global fleet.
Four Key Vulnerabilities
There are four key cybersecurity vulnerabilities in modern onboard aircraft systems. These vulnerabilities are not just in the code; they can be found in the connections between the aircraft and the ground, and between the cabin and the cockpit.
The first and most dangerous vulnerability resides deep within the avionics hardware itself, specifically the firmware that dictates how the onboard systems function. If this can be compromised by a cyber attack, then the whole aircraft could be at risk.
Unfortunately, “Aircraft systems are subject to the same types of attacks that we all face day to day,” said Larry Stefonic, Founder and CEO of wolfSSL. (His company provides embedded security solutions, including DO-178 certified cryptography (wolfCrypt) and secure boot (wolfBoot) specifically for avionics.) “The biggest issue comes about when an insider is compromised and motivated to support an attack vector.”
The second key vulnerability is known as the “Erosion of Domain Isolation”. In plain language, onboard systems that should remain separate—such as Flight Control and In-Flight Entertainment—are increasingly sharing resources or pathways. This means that a cyber attack that affects one of these systems will “infect” others that share the same resources. “Modern aircraft increasingly rely on interconnected digital subsystems, yet many architectures were not originally designed with today’s cyber threat environment in mind,” observed Heath Peyton, VP, Aerospace & Defense at OmniTrust, formerly INTEGRITY Security Services. (They deliver cryptographic trust, post-quantum readiness, and compliance-aligned assurance for the full operational lifecycle of aerospace and defense platforms.) “As a result, single flaws in interconnected systems can expose critical flight safety capabilities.”
The third vulnerability is associated with the increasing number of portable “endpoint devices” that are finding their way into the cockpit. In particular, Electronic Flight Bags (EFBs) and maintenance tablets are becoming critical to flight operations, but are often commercial-off-the-shelf (COTS) hardware with inadequate cybersecurity.
“Aircraft are highly networked ecosystems where cockpit systems, Electronic Flight Bags (EFB), maintenance tablets and even passenger-facing devices interact continuously,” said Sriram Kakarala, Scalefusion’s Chief Product Officer. (Scalefusion helps aviation companies and OEMs secure and manage connected devices, including EFBs, kiosks, and digital signage.) “The biggest vulnerabilities lie in… endpoint devices: if EFB or maintenance tablets are misconfigured, they can be manipulated to alter flight-critical data.”
The fourth key vulnerability is the increasing digitization of aircraft systems, where every update, patch, or data load is an interaction opportunity that can be exploited. “Modern aircraft are increasingly software defined,” said Dr. Justin Pearson, Wind River’s Senior Director, Architecture & Business Growth for A&D. (Wind River enhances airworthiness security through its Helix Virtualization Platform.) “This fact expands the attack surface in multiple places such as domain separation gaps, aging protocols, third party and open source software, and ground interfaces—data loaders, portable media, and maintenance tooling.”
The Threat Hierarchy
When it comes to cyber attacks on aircraft systems, there is an entire hierarchy of hostile players to contend with. This being said, the barrier to entry for a catastrophic attack is high, because—contrary to action movie plots—a hacker cannot log into an aircraft’s avionics and take full control. However, the barrier for disruptive attacks is getting lower, as more and more low-end aircraft systems (like flight entertainment) become networked and externally accessible.
Now onto the Threat Hierarchy. On the top tier are state actors with high sophistication, deep resources, and strategic intentions. Their motivation isn’t usually money; it’s geopolitical leverage, fleet disablement, or intelligence gathering.
“The most meaningful attacks on aircraft require a lot of motivation and skill,” Stefonic said. “As such, we think that state actors are the primary threat… Stealing personal information is less motivating to attackers when it comes to aircraft vs enterprise.”
“State-sponsored actors can compromise flight control systems and cause catastrophic failures,” added Peyton. “They can also create subterfuge such as spoofing GPS, [and] glean information through surveillance.”
Tier 2 of the Threat Hierarchy belongs to industry insiders. These are the people with legitimate access to aircraft. They can pose a massive risk to onboard aircraft systems, whether their actions are deliberately malicious or due to insufficient training/negligence.
“An often unseen group are the employees or contractors,” said Donald van Tongeren, a consultant with MBS Electronics. (They provide systems for secure software loading (LSAP) and helps organizations implement standards like ARINC 645/667 and ATA Spec 42. “Such people have direct access to safety critical systems and are able to bypass technical controls. Sadly, there also have been recorded cases of malice by such people, for reasons such as revenge, coercion, ideology or even extortion.
The bottom tier of the Threat Hierarchy belongs to hackers (disruption) and criminals (ransomware). “If it’s a commercial airline, what we see today is that what I call pranksters,” Arad said. “They’re not deliberately trying to crash a plane, but they are checking to see what they can affect.” Meanwhile, criminals are taking aim at “the business jet industry for financial gain through ransomware attacks.”
Ranking the Threats
Clearly, there are all kinds of cyber threats facing onboard aircraft systems. So which attack vectors are the most immediate risks to flight safety? According to the experts, maintenance laptops, EFBs, and firmware are the Top Three to worry about Maintenance laptops often run outdated operating systems (OS) such as Windows 95/XP to support legacy diagnostics. Because these OS are no longer supported by Microsoft, they are easy entry points for malware that can then be “injected” into the aircraft.
“We definitely think it’s one of the weakest links,” said Arad. “We definitely see that as an attack vector.”
In general, “Maintenance-related vulnerabilities present the most immediate and realistic risk,” Peyton observed. “If those pathways are compromised, the attacker may gain priority access over aircraft behavior.”
EFBs may not seem a natural risk choice in this article, because these systems do not fly the plane. However, we are including them because EFBs are used by pilots to make flying decisions. “If an EFB is misconfigured, altered data or malware could directly affect crew decision-making,” said Kakarala. ”So, from a practical standpoint, EFB compromise is the highest immediate risk.”
As for firmware attacks? If an attacker were ever able to compromise flight-critical firmware, they could exert significant influence over aircraft behavior—despite the multiple safeguards designed to prevent such a scenario. “If an attacker were ever able to compromise flight-critical firmware, they could exert significant influence over aircraft behavior—despite the multiple safeguards designed to prevent such a scenario,” Stefonic told Aerospace Innovations magazine.
The Impact of AI
As anyone who has ever received a highly-tailored phishing email (like this author) knows, AI is revolutionizing the world of cybersecurity. (Phishing is a cyber attack where a bad actor poses as a trusted entity—like a bank or colleague—to trick a victim into revealing sensitive information or installing malware, often by clicking on a link in an email.) In the world of onboard aviation systems, AI is serving as an accelerant for both the attackers (offense) and the defenders.
On the offensive side, AI is ‘democratizing’ sophisticated hacking. Even the rawest of hackers can now execute complex attacks, with social engineering (phishing) emails becoming indistinguishable from genuine communication.
“You can ask AI pretty much anything, and I’m betting the hackers are asking it how to take over inflight entertainment systems,” said Arad. “Attackers leverage AI to automate reconnaissance across connected avionics and simulate vulnerabilities,” Kakarala added. “They leverage it to craft highly effective phishing campaigns targeting crews and maintenance staff.”
On the defence side, “AI enables behavioral monitoring, anomaly detection and predictive threat alerts for aircraft endpoints and airport devices,” said Kakarala. “Using an AI-driven device or user telemetry allows IT teams to identify deviations in device behavior… before they can escalate.”
One area where the offense may have an advantage is cryptography. Because of their massive processing power, both AI and quantum computing(when it eventually arrives) pose a threat to current encryption standards. “Another risk area could be cryptanalysis possibilities,” van Tongeren said. “ SHA-2 or higher is the indicated standard: If the hash function is broken we need to step over to new technologies and maybe even start post-quantum transition thinking.”
Are New Standards Realistic?
In a bid to improve airborne cybersecurity, new standards like the Radio Technical Commission for Aeronautics’ DO-326A (Airworthiness Security Process Specification) now require manufacturers to prove “airworthiness security.” The question is, how realistic is this requirement for legacy fleets, and how well is the industry adapting to it? After all, legacy aircraft lack the compute power for modern encryption and were designed with “trust” as a default setting.
On this issue, the experts are guarded in their assessments. “Retrofitting older avionics with defensive cybersecurity is challenging but not impossible,” said Stefonic. “We’ve been able to support our customers in retrofitting cybersecurity to their systems, which are flying today.” Peyton added, “The requirement is realistic as a framework, but challenging to fully realize for legacy fleets. Many in-service aircraft were not designed to provide continuous, provable cybersecurity assurance.”
For those legacy planes that cannot be ‘digitally rebuilt’, the cybersecurity industry is using external processes to secure the aircraft. “Legacy fleets are managed via operational and organizational controls rather than design assurance,” said van Tongeren. “By implementing procedures and ‘new’ ARINC 645/667 compliant ground systems, these legacy fleets can be considered to be secure.”
Taking a Big Picture view, Dr. Pearson noted that, “DO-326B makes ‘airworthiness security’ a formal certification concern. The industry is adapting unevenly to this requirement: legacy platforms are taking a more incremental approach, prioritizing risk assessments, architectural mitigations, and compensating operational controls.”
Defence in Depth, From Code to Cloud
Protecting onboard aircraft systems from cyber attacks requires a five-layer ‘defence in depth’ approach, starting with code and working up to the cloud.
Layer 1 – Code-Level Prevention (Static Analysis): The most cost-effective cybersecurity comes from writing code that doesn’t have bugs in the first place. Since bugs do occur, ferreting them out requires rigorous static analysis testing before the software ever reaches the aircraft.
“Prevention is better than the cure,” said Sean Evoy, one of Adacore’s Product Managers. (AdaCore specializes in software development and verification tools for mission-critical, safety-critical, and security-critical systems.) “Static analysis helps teams identify and fix software weaknesses before attackers can exploit them. It highlights cases where data is not properly validated, helping prevent untrusted or ‘tainted’ inputs from influencing critical functions.”
Layer 2 – The Secure Boot and Chain of Trust: In this layer, the goal is to ensure that the software being loaded onto the plane aligns exactly with the manufacturer’s intentions. To protect against malware being added along the way, “The critical challenge is providing a chain of custody for software,” Peyton said. “Effective defense means securing software and configuration updates, starting with signed and encrypted software packages.”
Layer 3 – Partitioning and Virtualization: In this layer, the emphasis is on using advanced operating systems to create unbreakable walls between systems, so that a hack that has penetrated an aircraft’s Wi-Fi system cannot jump to the flight computer. “Keeping safety domains isolated can limit worst case scenarios even if spoofed data enters the system,” said Dr. Pearson.
Layer 4 – Continuous Endpoint Management: It is clearly time to manage endpoint devices like EFBs, maintenance laptops, and tablets with the same level of cybersecurity as corporate laptops. “This is why Scalefusion focuses on continuous endpoint visibility, proactive policy enforcement and remote remediation,” said Kakarala. “We identify deviations in device behavior like unauthorized app installation before they can escalate.”
Layer 5 – Digital Twinning for Vulnerability Assessment: Mirroring a physical aircraft’s onboard systems using constantly-updated digital twins is an accurate and safe way to find and fix vulnerabilities on the ground. “We research such issues using digital twins—that way we don’t affect airworthiness,” Arad said. “We don’t even have to have physical contact with aircraft to determine any vulnerabilities and recommend mitigations.”
The Verdict: Capable but Incomplete
Having covered the points above, Aerospace Innovations asked the expert how they would grade the aviation industry’s defences against cyber attack, and whether the advantage currently lies with the attackers or the defenders?
Their verdict is that the aviation industry has a strong safety culture that is committed to robust cybersecurity, but that the evolutionary development of cyber attacks is outpacing the speed of certified solutions. “Overall, I would characterize the current state as capable but incomplete,” said Peyton. “Attackers often retain an advantage due to lower cost of attack versus the high cost and complexity of assurance in long-lived systems.”
As well, “Connectivity in aviation is expanding faster than defence measures,” Kakarala said. As a result, “Currently attackers often hold the advantage. However, with centralized management, the balance is shifting toward defenders.”
So what will it take to turn things around? Roy Arad wonders if the aviation industry will have to experience a cyber ‘close call’ akin to the failed attempt by Richard Reid to blow up an aircraft with a bomb in his shoe. “Since that point in time, we’ve been taking off our shoes at airport security,” he said. “I do think that it’s a matter of time until an equivalent cyber incident will occur, that will change how we view onboard aircraft system safety.”
A Final Thought
In the realm of airborne cybersecurity, the advantage currently leans slightly toward the attacker due to the complexity of legacy systems. However, the aviation industry’s superpower has always been its ability to systematize safety, and this will likely turn the ‘cyber tide’ to its advantage down the road.
“When standards, guidance material and regulations are followed, the advantage is clearly with the defenders,” said van Tongeren. “The biggest ‘threat’ thus lies in not understanding or feeling the threat.”
“There is a lot of work to do!” Stefonic concluded. “That said, cybersecurity is a core foundation to safety in this era.”
By James Careless

