Skip to content
Cybersecurity

Aviation Cybersecurity. Hacking Aircraft

Discover the critical cybersecurity challenges in aviation, including supply chain vulnerabilities, interconnected system risks, and the urgent need for…

I contributed to the Atlantic Council's report, "Aviation Cybersecurity: Finding Lift, Minimizing Drag," by Pete Cooper. They interviewed me and I was on a panel. I know about penetration testing and risk assessments for commercial aircraft. There's a picture of me there.

Here’s the interview:

How do you envision the future of your segment, and how do connected technologies play a role?

We have to change how we do supply chain management, third-party penetration testing, and aircraft domain (enclave) management. These things are critical for the safety of "e-Enabled" aircraft. Managing the entire supply chain of components and systems that go into an aircraft is important. If a supplier has a vulnerable or compromised system, it can get onto an aircraft and be used to attack other systems. We need a risk management framework for all aircraft suppliers, and we need to follow it.

Third-party penetration testing should be mandatory. It needs to be done on supplier components, systems, and the integrated systems on the aircraft itself. A third party is necessary because they are impartial. Penetration testing lowers risk. It finds flaws and vulnerabilities that automated scanning tools miss. All suppliers for aircraft manufacturers should have mandatory, thorough third-party penetration testing.

Aircraft systems are placed in domains. Systems in each domain have specific Design Assurance Level (DAL) requirements, based on system criticality pertaining to hazard analysis or effect on safety of flight. Cybersecurity risk is introduced by the interconnections of these domains, such as data flows between systems at a lower DAL to systems on a domain with a higher DAL. These data flows and rationale for their existence need to be assessed thoroughly.

What are the major concerns your sector has from a cyber safety, policy, or security standpoint?

The major concerns are cybersecurity awareness, skills shortage, and policy. With cybersecurity awareness, many stakeholders do not understand the true risk connected systems pose to aircraft safety. Risk is often viewed in terms of the current state of affairs, but aircraft systems are complex and are not easily “patched”.  As an example, everyone thought WPA2 was secure, until KRACK, and that Bash was secure until Shellshock.  If a threat tree used to assess risk determined a “low” risk rating for a system using Bash, for instance, how does a major Bash exploit like Shellshock alter this risk rating and what other systems are now exposed in that same threat tree?

Skills shortage is another concern in the aircraft manufacturing industry.  The EASA and FAA certify aircraft via type certifications to determine airworthiness of an aircraft “design”.  The FAA and EASA have done a great job with this in the past, but do they have the cybersecurity expertise to determine if the cybersecurity aspect of the aircraft is properly designed? Aircraft are complex systems with thousands of components from hundreds of suppliers. Adequate cybersecurity skills, training, and experience are required to properly assess aircraft cybersecurity and focus on what has been proven to reduce cybersecurity risk, especially from a fundamental secure design aspect.

Policy is another concern with aircraft manufacturing. Once a type certificate is issued for an aircraft, according to policy, the design cannot typically change. How does this policy address cybersecurity issues in a timely manner, such as applying patches to aircraft systems to mitigate cybersecurity risk? And, what effect does a “patch” to a component on an aircraft have against the entire system?  Aircraft are very similar to SCADA systems; both used to be treated as standalone, air-gapped systems, but they have both evolved to be connected to the Internet, which introduces many threats via new entry points into the system. Attacks on the once thought secure SCADA environments are now commonplace. Stuxnet, the Ukrainian Power Outage, etc. Efforts need to be made to ensure attacks such as these do not become commonplace on aircraft.

As technology evolves, how is your sector anticipating and avoiding future threats over the lifetime of those technologies?

Proper risk assessment is critical for aircraft safety. The challenge is when the likelihood of an attack against a system that may cause catastrophic impact deemed “rare” or “out-of-scope” later becomes “trivial” due to a new exploit discovery. This evolving risk and how to address it creates opportunities with a certification process that is based on a point-in-time design.  To overcome some of these challenges, some aircraft manufacturers perform risk analysis with the assumption a system with an external entry point will be fully compromised by an attacker. This helps ensure that any system with a connection, or path, from the component considered fully compromised is properly assessed for risk and thoroughly tested.

Software on aircraft is typically treated as a “part”. This facilitates configuration control because existing parts management infrastructure and procedures are used. A known configuration that is tightly controlled is much easier to assess from a risk perspective, than a system lacking configuration control.

The aviation cybersecurity report launch was held November 7, 2017, in Washington DC. The launch included a panel discussion on Hacking Aircraft. This session was recorded and is shown here.

About Me Christian Espinosa after finishing the Broken Arrow Skyrace

Me after finishing the Broken Arrow Skyrace

I'm the founder and CEO of Blue Goat Cyber, where I lead medical device cybersecurity work supporting 250+ FDA submissions. I sold my first cybersecurity company, Alpine Security, in 2020. I've worked as a network and systems engineer, white hat hacker, trainer, consultant, and entrepreneur in cybersecurity since 1993, and I've held more than 20 industry certifications, including CISSP, CISA, LPT, ECSA, PMP, and CCSP. I'm a US Air Force veteran with a BS in Engineering from the US Air Force Academy and an MBA from Webster University. I hold multiple patents on cybersecurity attack and defense simulation. Recent work includes penetration testing and security assessments of commercial aircraft, medical device penetration testing, and incident response. When I'm not doing that, I climb mountains, travel the world, teach wilderness survival, and race ultramarathons and Ironman triathlons (24x finisher).

Christian Espinosa, headshot

About the author

Christian Espinosa · Founder, Blue Goat Cyber · Author · Speaker

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.