---
title: "Aviation Cybersecurity. Hacking Aircraft"
description: "Discover the critical cybersecurity challenges in aviation, including supply chain vulnerabilities, interconnected system risks, and the urgent need for…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Aviation Cybersecurity. Hacking Aircraft - Christian Espinosa",
      "description": "Discover the critical cybersecurity challenges in aviation, including supply chain vulnerabilities, interconnected system risks, and the urgent need for…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/c478fc3b-79dc-4837-97d2-6df7df344f12/aviation-cybersecurity-hacking-aircraft-card.png",
      "datePublished": "2020-06-03T01:14:35+00:00",
      "dateModified": "2026-06-26T05:32:07.587Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/aviation-cybersecurity-hacking-aircraft"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Aviation Cybersecurity. Hacking Aircraft - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The risk of successful hacks of aircraft is increasing. Aircraft are complex systems with long supply chains and legacy systems and protocols."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Aviation Cybersecurity. Hacking Aircraft

June 3, 2020 5 min read 1,071 words 

I contributed to the Atlantic Council's report, "Aviation Cybersecurity: Finding Lift, Minimizing Drag," by Pete Cooper. They interviewed me and I was on a panel. I know about penetration testing and risk assessments for commercial aircraft. There's a picture of me there.

![](/__l5e/assets-v1/202f044c-8938-4e28-97a0-d2d023d97281/aviation-cybersecurity-hacking-aircraft-hero.webp)

The takeaways

1.  01 
    
    They interviewed me and I was on a panel.
    
    What to do next Ask your security lead this week for the one-page view of interviewed in your environment, and read it end to end.
    
2.  02 
    
    Managing the entire supply chain of components and systems that go into an aircraft is important.
    
    What to do next Ask your security lead this week for the one-page view of managing in your environment, and read it end to end.
    
3.  03 
    
    If a supplier has a vulnerable or compromised system, it can get onto an aircraft and be used to attack other systems.
    
    What to do next Add attack to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    It needs to be done on supplier components, systems, and the integrated systems on the aircraft itself.
    
    What to do next Run a 20-minute tabletop with your team this month using needs as the scenario.
    

I contributed to the Atlantic Council's report, "Aviation Cybersecurity: Finding Lift, Minimizing Drag," by Pete Cooper. They interviewed me and I was on a panel. I know about penetration testing and risk assessments for commercial aircraft. There's a picture of me there.

Here’s the interview:

### **How do you envision the future of your segment, and how do connected technologies play a role?**

We have to change how we do supply chain management, third-party penetration testing, and aircraft domain (enclave) management. These things are critical for the safety of "e-Enabled" aircraft. Managing the entire supply chain of components and systems that go into an aircraft is important. If a supplier has a vulnerable or compromised system, it can get onto an aircraft and be used to attack other systems. We need a risk management framework for all aircraft suppliers, and we need to follow it.

Third-party penetration testing should be mandatory. It needs to be done on supplier components, systems, and the integrated systems on the aircraft itself. A third party is necessary because they are impartial. Penetration testing lowers risk. It finds flaws and vulnerabilities that automated scanning tools miss. All suppliers for aircraft manufacturers should have mandatory, thorough third-party penetration testing.

Aircraft systems are placed in domains. Systems in each domain have specific Design Assurance Level (DAL) requirements, based on system criticality pertaining to hazard analysis or effect on safety of flight. Cybersecurity risk is introduced by the interconnections of these domains, such as data flows between systems at a lower DAL to systems on a domain with a higher DAL. These data flows and rationale for their existence need to be assessed thoroughly.

### **What are the major concerns your sector has from a cyber safety, policy, or security standpoint?**

The major concerns are cybersecurity awareness, skills shortage, and policy. With cybersecurity awareness, many stakeholders do not understand the true risk connected systems pose to aircraft safety. Risk is often viewed in terms of the current state of affairs, but aircraft systems are complex and are not easily “patched”.  As an example, everyone thought WPA2 was secure, until KRACK, and that Bash was secure until Shellshock.  If a threat tree used to assess risk determined a “low” risk rating for a system using Bash, for instance, how does a major Bash exploit like Shellshock alter this risk rating and what other systems are now exposed in that same threat tree?

Skills shortage is another concern in the aircraft manufacturing industry.  The EASA and FAA certify aircraft via type certifications to determine airworthiness of an aircraft “design”.  The FAA and EASA have done a great job with this in the past, but do they have the cybersecurity expertise to determine if the cybersecurity aspect of the aircraft is properly designed? Aircraft are complex systems with thousands of components from hundreds of suppliers. Adequate cybersecurity skills, training, and experience are required to properly assess aircraft cybersecurity and focus on what has been proven to reduce cybersecurity risk, especially from a fundamental secure design aspect.

Policy is another concern with aircraft manufacturing. Once a type certificate is issued for an aircraft, according to policy, the design cannot typically change. How does this policy address cybersecurity issues in a timely manner, such as applying patches to aircraft systems to mitigate cybersecurity risk? And, what effect does a “patch” to a component on an aircraft have against the entire system?  Aircraft are very similar to SCADA systems; both used to be treated as standalone, air-gapped systems, but they have both evolved to be connected to the Internet, which introduces many threats via new entry points into the system. Attacks on the once thought secure SCADA environments are now commonplace. Stuxnet, the Ukrainian Power Outage, etc. Efforts need to be made to ensure attacks such as these do not become commonplace on aircraft.

### **As technology evolves, how is your sector anticipating and avoiding future threats over the lifetime of those technologies?**

Proper risk assessment is critical for aircraft safety. The challenge is when the likelihood of an attack against a system that may cause catastrophic impact deemed “rare” or “out-of-scope” later becomes “trivial” due to a new exploit discovery. This evolving risk and how to address it creates opportunities with a certification process that is based on a point-in-time design.  To overcome some of these challenges, some aircraft manufacturers perform risk analysis with the assumption a system with an external entry point will be fully compromised by an attacker. This helps ensure that any system with a connection, or path, from the component considered fully compromised is properly assessed for risk and thoroughly tested.

Software on aircraft is typically treated as a “part”. This facilitates configuration control because existing parts management infrastructure and procedures are used. A known configuration that is tightly controlled is much easier to assess from a risk perspective, than a system lacking configuration control.

The aviation cybersecurity report launch was held November 7, 2017, in Washington DC. The launch included a panel discussion on Hacking Aircraft. This session was recorded and is shown here.

### About Me![ Christian Espinosa after finishing the Broken Arrow Skyrace ](https://1kggaz45g7tf2360kdj0h7g1-wpengine.netdna-ssl.com/wp-content/uploads/2020/02/christian-after-finishing-the-broken-arrow-skyrace.jpg) 

Me after finishing the Broken Arrow Skyrace

I'm the founder and CEO of Blue Goat Cyber, where I lead medical device cybersecurity work supporting 250+ FDA submissions. I sold my first cybersecurity company, Alpine Security, in 2020. I've worked as a network and systems engineer, white hat hacker, trainer, consultant, and entrepreneur in cybersecurity since 1993, and I've held more than 20 industry certifications, including CISSP, CISA, LPT, ECSA, PMP, and CCSP. I'm a US Air Force veteran with a BS in Engineering from the US Air Force Academy and an MBA from Webster University. I hold multiple patents on cybersecurity attack and defense simulation. Recent work includes penetration testing and security assessments of commercial aircraft, medical device penetration testing, and incident response. When I'm not doing that, I climb mountains, travel the world, teach wilderness survival, and race ultramarathons and Ironman triathlons (24x finisher).

Frequently asked

### What is the core idea behind "Aviation Cybersecurity. Hacking Aircraft - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Faviation-cybersecurity-hacking-aircraft&text=Aviation%20Cybersecurity.%20Hacking%20Aircraft) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Faviation-cybersecurity-hacking-aircraft) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Faviation-cybersecurity-hacking-aircraft) [Email](mailto:?subject=Aviation%20Cybersecurity.%20Hacking%20Aircraft&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Faviation-cybersecurity-hacking-aircraft)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Risk Comprehension Is a Basic Cybersecurity Skill, Yet Most Practitioners Lack It - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/risk-comprehension-is-a-basic-cybersecurity-skill-yet-most-practitioners-lack-it)
-   [
    
    ### Medical Device Hacking and the Vulnerability of Connected Medical Devices - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/medical-device-hacking-and-the-vulnerability-of-connected-medical-devices)
-   [
    
    ### Leetspeak: The History of Hacking Subculture's Native Tongue - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/leetspeak-the-history-of-hacking-subcultures-native-tongue)

[← Previous essay 

Why Small Businesses Are Still the #1 Cybercrime Target in 2026 - Christian Espinosa

](/blog/70-of-cyber-attacks-will-be-against-small-businesses-in-2020)[Next essay → 

Ransomware – Should You Pay? - Christian Espinosa

](/blog/ransomware-should-you-pay)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)