In short
Podcast Summary: Aviation Cybersecurity with Serge Christiaans
Overview In this episode of *Software Engineering Daily*, hosts Gregor Van and Serge Christiaans delve into the critical issue of aviation cybersecurity. As aircraft systems become increasingly digital and interconnected, the vulnerabilities to cyber threats grow. The discussion centers around the importance of understanding these risks to ensure passenger safety and protect global transportation networks.
---
Key Themes and Concepts
- The Urgency of Aviation Cybersecurity
- Modern aircraft rely on complex digital systems for navigation, communication, and performance.
- These systems, once isolated, are now interconnected and susceptible to cyber threats (e.g., GPS spoofing, ransomware).
- Nation-state actors and sophisticated criminal groups pose significant risks, highlighting the need for robust cyber resilience in aviation.
- Guest Background: Serge Christiaans
- Former Dutch Air Force pilot with experience in electronic and hybrid warfare.
- Transitioned to commercial aviation and later focused on cybersecurity, obtaining a master’s degree during the COVID-19 pandemic.
- Currently leads the Aviation Cyber Academy, advocating for increased awareness and training regarding aviation cybersecurity.
- Cybersecurity Maturity in Aviation
- The aviation sector is considered moderately mature in cybersecurity compared to other industries like finance and healthcare.
- Emphasis on physical security has hampered the integration of cybersecurity measures.
- A cultural resistance to change exists due to concerns over compromising safety.
- Understanding the Attack Surface of Aircraft
- Modern aircraft can be likened to "flying server rooms" with numerous computers onboard.
- Threats can arise from navigation systems, engine management systems, and maintenance communications, all of which are potential targets for cyber attacks.
- The complexity of aircraft engines and their data communications presents unique vulnerabilities.
- Training for Cyber Incidents
- Only 20% of pilots receive formal training on potential cyber threats, relying mostly on memos and not practical simulations.
- Training is crucial for pilots to recognize, isolate, and respond to cyber incidents during flight.
- The Aviation Cyber Academy is developing a curriculum that includes simulator-based training for pilots to handle cyber scenarios.
- Hybrid Warfare and Cyber Threats
- Hybrid warfare combines conventional and cyber tactics, often aimed at disruption rather than direct destruction.
- Nations leverage cyber capabilities to create chaos without crossing the threshold of war, targeting critical infrastructure.
- The aviation industry must prepare for these tactics and enhance its cybersecurity measures accordingly.
- Cultural Shifts Needed in Aviation
- The concept of a "just culture" in aviation promotes reporting incidents without fear of punishment, allowing for learning and improvement.
- A shift from blame culture in cybersecurity is necessary for organizations to enhance their defenses and resilience.
- Encouraging incident reporting could prevent catastrophic failures and improve overall safety in aviation.
- Future of Cybersecurity in Aviation
- Increased nation-state cyber warfare anticipated to impact aviation significantly.
- Calls for collaboration among critical infrastructure sectors to share threat intelligence and improve cybersecurity measures.
- The importance of regulatory frameworks for mandatory cybersecurity requirements in aviation operations and aircraft certification.
---
Conclusion Serge Christiaans emphasizes urgent action is needed to address the cybersecurity challenges facing the aviation industry. As threats evolve, so must the training, culture, and regulations surrounding aviation cybersecurity to ensure safety and resilience in an increasingly digital environment.
---
Key Takeaways
- The aviation sector is at a critical juncture regarding cybersecurity, requiring immediate action and awareness.
- Pilot training on cybersecurity must be enhanced to effectively manage potential cyber threats.
- A cultural shift towards incident reporting without fear of blame is essential for learning and improving cybersecurity defenses.
- Future frameworks will likely mandate cybersecurity measures within aviation, highlighting the importance of proactive engagement in the industry.
For further information, you can access the episode directly on [Software Engineering Daily](https://softwareengineeringdaily.com/2025/12/11/aviation-cybersecurity-with-serge-christiaans/).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Aviation cybersecurity is becoming an urgent priority as modern aircraft increasingly rely on complex digital systems for navigation, communication, and engine performance. These systems were once isolated, but are now interconnected and vulnerable to cyber threats, ranging from GPS spoofing to ransomware attacks on airline infrastructure. As nation-state actors and criminal groups grow more sophisticated, the aviation sector faces a rapidly expanding attack surface, with life-or-death consequences. Understanding and addressing these risks is essential, not only for passenger safety, but for the resilience of global transportation networks.
0:40Serge Christians is a former Dutch Air Force pilot with a background in electronic and hybrid warfare. He later flew commercially for Singapore Airlines and is now the lead instructor and program director at the Aviation Cyber Academy. He joins the podcast with Gregor Van to discuss the convergence of aviation and cybersecurity, the aircraft as a digital attack surface, hybrid warfare, the urgent need for aviation cyber resilience, and much more. Gregor Vand is a security-focused technologist, having previously been a CTO across cybersecurity, cyber insurance, and general software engineering companies.
1:19He is based in Singapore and can be found via his profile at van.hk or on LinkedIn.
1:38Hello, welcome to Software Engineering Daily. My guest today is Serge Christian. Welcome, Serge. Hi, Gerger. Thank you very much for the invitation. Yeah, this is a very interesting one for us to do today, as we're going to get into based on the fact that you are a practicing pilot, but you're also a practicing CISO as well. So we're going to get into how this has all come about. So I think that's kind of where we should start. We always kind of start with guests career journey, if you like to call it that. It almost feels like you have two careers, both you've managed and you're still doing both today.
2:14So tell us about how are you doing these two jobs effectively? Okay, well, I started my career at the military academy in the Netherlands, in the Air Force, and then flying in the Netherlands for the Dutch Air Force for about 16 years. I was also involved in electronic warfare, hybrid warfare, and plenty of operations and NATO operations abroad. Then I moved to commercial aviation, flying 737s in the Netherlands. But as an ex-military pilot, that was so insanely boring. I started my own IT company parallel to that. And that company actually started growing into more cybersecurity as cyber became an issue.
2:51Around 2010, 2011, when we saw the first cyber attacks, I was still flying then, but also in my spare time serving customers, mostly SMEs and managing their infrastructure. Then at some point I moved to Singapore, flying for Singapore Airlines or scoot actually for the Airbus 320. COVID happened. I took that opportunity to do a master's in cybersecurity. And then during COVID, I had several full-time CISO roles responsible for Asia Pacific regions, stocklisted multinationals, which was very different from flying. But I'd say my military academy management skills were very useful. It was, again, very interesting.
3:29I learned a lot. But then at some point, I looked in the mirror and I thought, nah, dude, you want to fly again. You miss it. And I did. So I started flying again. But now all the knowledge that I had on cybersecurity and my CISO experience, I found myself in the middle of aviation cybersecurity. And when digging into that, it's actually a very small world. Not many people are in that intersection. And I really felt I needed to do something with the knowledge I have on both sides. So I'm helping the aviation industry on plenty of different occasions. I speak a lot at conferences, raising the flags on awareness, but especially airplane cyber and the threat service that an airplane poses.
4:13Because there are many people, also high-level management of airlines that actually do not understand this risk and what we need to do, which is actually comparable to what I found when, as a CISO working for large companies, it's the same problem all over. they don't understand the business risk of cyber which is the largest risk that any company has not even aviation or an airline cyber is your biggest risk if you don't understand that that your company can go down in a week regardless of how great your clients feel about you or how low your prices are or how great your product is you will go down if you have a ransomware attack that you haven't prepared.
4:55Yeah. I mean, I think probably quite obvious to many, but worth calling out is just the stakes are incredibly high in aviation because you just don't have the same kind of time to deal with the problem. So we're going to get into kind of what that even means, cyber in the air. Just before we kind of go there, a couple of questions, I guess, is I have quite a few pilot friends, actually, and there's obviously a lot of downtime between where you fly to and from. So I guess this is how you're able to kind of do both at once. And is it kind of difficult to mentally switch between flying and then being a sister?
5:26How does that look? Well, not for me. It's like switching languages. If you speak both languages well, you switch without knowing. You sometimes even think in the other language without knowing. Or compared to driving in Singapore, I drive on the left side. Here in Europe, I drive on the right side. I just get in a car and I just do it. Sometimes if I'm tired, I approach a roundabout and need to think, okay left or right what is it but in general i don't have that problem because i speak both languages good i think that's a good way of describing it and then if we just sort of think about just to kind of lay the land here like cyber security in aviation how would you describe i mean you've touched on it i think just in what you were saying a few minutes ago but how would you describe kind of the maturity of cyber security compared to other critical infrastructure sectors?
6:17Well, actually, we have statistics on that. There is research on that. And it seems that aviation is about in the middle, which aligns with my experience as well. In general, of course, the financial sector, the financial services, healthcare, energy sector, they're more mature in general. And manufacturing is way less mature in general. And we're about in the middle. And one of the main reasons is, of course, that in the aviation industry, We focus on physical security threats in general. And we don't like change because everything we change might change our safety posture as well. It's all about safety.
6:53What we do now is safe. And everything we change might compromise that safety. Because in aviation, safety is written in blood, we say. It's based on experience. With an open culture, we want to learn of everything that happens so we can prevent it from happening again. so then when everything is balanced is coordinated and it works like this and we have a high safety level you don't want to change it a lot because you're introducing more risks and that's a part of our culture that doesn't help getting more cyber resilience that's one of the things i'm fighting at the moment got it okay that makes a lot of sense so let's dive into what it even means cybersecurity in aviation.
7:36Some of our listeners will be familiar with the term attack surface, like in terms of just conventional, you know, what an attack surface in cybersecurity, i.e. what an attacker might see and be able to think about attacking. How does that look in terms of aircraft? Like what does an attack surface of an aircraft even look like? And what are things that people might just not realize even exist as part of that attack surface? Okay, let's start with describing a modern aircraft as a flying server room with hundreds of computers on board. If you look at it like that, that is a huge attack surface on its own.
8:15There's a lot of digital stuff on board, but also cyber physical elements that are hybrid. And it's the hybrid things and the hybrid attacks, by the way, as well, and hybrid warfare that's actually falling in between. Nobody understands that one except the ex-military guys. It's not cyber and it's not warfare and it's not in the newspapers. But that's a different topic. Talking about threat services of my airplane, it's all the computers, all my navigation systems, my flight management systems, big and small computers, GPS receivers, ACAR, SETCOM. It can all be spoofed. It can all be exploited even my maintenance systems can be compromised and one of my biggest worries where nobody talks about is actually my engines my airplane half of the price goes half of the money goes to the engines these things are insanely complex if i open up a few of these hatches you're going to be amazed what you see there it's a miraculous piece of high-tech and these things are constantly sending data to the manufacturer.
9:20So this is also part of my threat service. If somebody could switch these things off in flight, then I'm not an airplane anymore. I mean, I can do without a computer. I have backups on this, backups on that. We have workarounds. That's all fine. As long as I'm still an airplane, I have fuel and I have a landing gear to land on, then I'm fine. But without engines, I'm a glider. So that's an interesting one. Let's just stick on engines for a second. you mentioned that the engines are sending telemetry to the manufacturers so in theory is there a risk around that communication the other way around where something goes wrong at the manufacturer and is able some kind of communication is able to be sent to the engine that does something nefarious i mean is that a possibility theoretically yes it's the same as your phone somebody could switch it off somebody could ddos it or make it unusable or find a switch what nation-state threat actors are doing right now with our critical infrastructure mainly china they're creating switches that they can push so they create chaos yeah interesting so i mean looking at sort of general connectivity could you actually explain i believe there's this acronym arinc systems perhaps you could just explain a what does that stand for and it's i believe it's a protocol and like yeah could we just dive into that protocol a little bit and like how has that increased the threat landscape as well?
10:44So AirRink is a protocol that was, I think, in 1927, the last century, radio communication protocol that was designed for standardization purposes. And in airplanes, we have an AirRink 429er. That was the first communication bus, actually. Let's call it a communication bus, that was built into the digital backbone of airplanes to communicate, to enable communication between different systems on board. Now, the Erring 429er was designed in the 70s, last century. Long time ago, there were not really physical wars going on. Cyber didn't exist. The first computers, I think we had MS-DOS back then, just came out.
11:25The word cyber security didn't even exist. So these things were designed for reliability and not for message injection or spoofing attacks. Now, next to that, the long operational life cycles we have in aviation means that we have a lot of vulnerable old systems. flying around for many years to come that doesn't mean there's no improvement there are developments we have in the airwink 629er which is more secure more safe and we have the 664 the afdx which is a full duplex which can handle encryption which all is a big improvement but it's only for the newer airplanes so for example when you say newer airplane are we talking like a350 or does it It has to be, I guess, A350 is one of the newest aircraft.
12:08But do A320s have that newer? Like if they rolled out the factory today, do the A320s get that new protocol or a new bus? Yes, that's a funny thing. Every time I ask Airbus, they don't tell me. And every time I ask Boeing, they don't tell me. And the same goes for Embraer. I visit a lot of aviation events, talk to the chief pilots and the test pilots of these airplanes. But I think you can imagine that this is propriety information. and they're not going to give it out to the first idiot with a Boeing cab visiting their booth. It's very difficult to find out. We have to believe that they are doing their absolute best and that they have a very well-equipped cyber team and they're looking at it.
12:46But at the end of the day, I cannot do a penetration test on my airplane because for that, it actually needs to be in the air. You can understand. It's physically, no pun intended, air gapped that nice. But if you want to do a pen test, you have it in the hangar. you need to have the engines running as well because then you know all the systems are online and even then the air ground switch will be on the ground side not all will be working so it's very difficult to do that yeah okay interesting so let's talk about actual cyber attacks mid-flight so i mean i believe you do actually train pilots to understand what a cyber attack might look like mid-air and i guess how to sort of deal with that so could you just walk us through your sort of what kind of things do you teach pilots in this sense like what are they looking out for and then crucially what are they supposed to then like what are some at a high level like what kind of steps are they supposed to step through to help mitigate that whilst they're literally flying a plane at 35 000 feet yeah well first of all there's only about 20 percent of pilots globally that receive actual training in this all the other ones receive memos it's not being trained in simulators for the simple reason that aviation authorities are not asking for it.
13:58We do what we need to do to be compliant. We don't have time for other stuff. When I'm in a simulator for four hours, there's a very intense program. There's no ten minute space to have a look at GPS spoofing or jamming. It's just not in the program. And that's exactly the same reason because the upper management doesn't understand this is needed. There is no awareness of the risk, the business risk of cyber. So it needs to be top down. The board needs to decide, yes, we need to train this. Then it goes to the training department. They will make a training program. Then we go in the simulator and then we learn how to react on this.
14:36Until that happens, nothing happens. And there's only 20 % of pilots that are being actually trained. The other ones all, and there's also scientific interview data on that one. The other ones are uncomfortable in a situation like that because they don't actually know what's going on. Yeah. Can you walk us through like just what a cyber attack might kind of present as in the cockpit, for example? Yeah. In aviation, we're being trained on emergencies and we practice these emergencies and we learn how to identify them. Quite often, the airplane helps you identifying them. Let's say I have an oil pressure on my left engine that's going below limits, and the airplane will pop up a message, a notification, if you will, that says, hey, have a look at your engine pressure because it's not going great.
15:21And then I make a decision, we look at it, and we take out a checklist, or we divert, or whatever we feel we need to do to keep the operation and the people and the airplane and my crew safe. Now, cyber attack on your airplane is actually something you never saw before, most likely. By now, everybody has seen a GPS jamming or a GPS spoofing, but there are still plenty of pilots who do not understand yet the difference between it because they have not been properly trained. Or the results or the long-term effects on your airplane of a spoofing attack. So what we normally do, the basic rules for handling any emergency in any airplane, anywhere in the world, is aviate, navigate, communicate.
16:03The first thing you do, whatever is going on, fly the bloody airplane. Use your primary instruments. Keep on flying. Don't focus. Don't look inside at instruments or try to get manuals out or start a discussion with your first officer while the airplane is going down. That's not a good idea. Aviate first. Then navigate. Where are you going? Where are you heading? Where do you want to go? make sure you have a heading where you're not going into a mountain for instance or you're not going over a busy airport get out of dangerous airspace and then the last one communicate this not only to air traffic control but to your crew to your cabin to your passengers if you have time in the right order now for any cyber attack things will be happening that you don't understand you will have contradicting information like this system says my position is here and this system says my position is there so where am I I don't know or hey suddenly my engine data is blank maybe your engine is being hacked I don't know or in hybrid warfare maybe your ACARS is spitting out a message from operations that you're not expecting so you need to think you need to start thinking so what we need to do is to isolate disconnect the dispected system and try to resolve the problem after isolation and then the last one is to document we need documentation about this because every attack is probably new.
17:32And because one of the more important things of cyber resilience is sharing cyber threat intelligence. We need to document this so we can immediately tell all the other pilots in the world that this is happening in this area, most likely by this threat actor. So sharing is caring. It's very important. Stronger together. You're a developer who wants to innovate. Instead, you're stuck fixing bottlenecks and fighting legacy code. mongodb can help it's a flexible unified platform that's built for developers by developers mongodb is acid compliant enterprise ready with the capabilities you need to ship ai apps fast that's why so many of the fortune 500 trust mongodb with their most critical workloads ready to think outside rows and columns start building at mongodb.com slash build we're going to get on a bit to sort of culture in a bit as well this is this idea of just culture versus blame culture but we'll get there so yeah i think that's very interesting just to sort of think for a second just about yeah that situation where as you're calling out a pilot can never know for sure if what's going on is an attack and so that's like i guess half the problem and then the second problem is then that distraction and your overarching way of training this situation is as you say like fly the plane that's the first thing don't take your eye off what you should just be doing which is flying the plane but obviously you're having to make a whole bunch of other mental assessments i mean you mentioned acars which i'm a hobbyist sim flyer so that's this sort of like messaging system i guess where literally an airline can or i mean i think pilots can also send messages like you know toilet broken so when they land people know to come and fix it and that kind of thing yeah the acars is our onboard fax very old system it's not encrypted it anybody can read it i can build a little soft radio here and you can even receive it and read it there's no classified information going over that thing but operational information for sure and you can also send up and imagine the chaos you can do that with false messaging that are not verified in the military we verify all messages in civil aviation not like that yet working on it so we're going to move on to i mean you've been using this phrase a lot hybrid warfare i think i'd just like to understand that one a bit more like what are we you know when we talk about critical infrastructure hybrid warfare let's start with kind of you've touched on obviously nation states already russia china iran for example i mean we're not maybe here to dig into exact nations so much but just sort of the understanding what is this landscape and what is hybrid warfare at all and i guess how does especially commercial i mean i guess are we talking commercial aviation comes into this or military aviation drones like just what is all this okay classic warfare we call kinetic warfare kinetic warfare is when things are kinetically flying around like missiles bullets rockets and it's about destruction hybrid warfare there's actually nothing flying around it's not peace but it's also not kinetic warfare so it's everything in between cyber warfare is a part of hybrid warfare but there are many other gray shades in hybrid warfare like disrupting transport train systems in a country quite often the goal of hybrid warfare is disruption it's showing power below the threshold of war which means that in nato it's going to be very difficult to call out article 5 if it's hybrid warfare we need to agree on that all of the member states which is a problem because for some this might not be a act of war for others it's a very clear act of war so blowing up a bridge might be an act of war but a cyber attack on the bridge control system might not be but both have the same effect the bridge is unusable for logistics and for ammunition and to go to the front line so that is hybrid warfare creating chaos and a cyber attack on my airplane is probably not aimed at killing us but creating chaos about showing hey look see what we can do better be careful it's threatening and it's what putin's doing all the time of course he's threatening with nuclear weapons but he's also attacking the whole digital infrastructure critical infrastructure of every country in europe next to all the disinformation campaigns that he's throwing out that is also warfare it's hybrid warfare but it's still warfare I understand.
22:03And I mean, especially given a lot of airlines today are still effectively extensions of countries. Most countries have a national airline. I mean, in the UK, British Airways is not owned by the government, but I think most people still associate British Airways as sort of being the national airline, for example. And then obviously we have the big nation players like Emirates, Qatar, etc. So does that play into it where, as you say, causing chaos, showing a signal through cyber warfare on commercial aircraft is by extension targeting a government, for example? I would say so. Yeah, it's a show of force, definitely.
22:39Don't forget in China, all Chinese companies are owned by the Chinese government. Well, not owned, but at least controlled. And if you look now at Flight 24, you see Chinese airplanes just flying over Russia, no problem at all. So we need to avoid conflict zones, conflict areas, because there are trigger-happy people down there with high-tech equipment built to shoot you down. And that has happened before. And it will happen again. And I mean, if we sort of look at the cyber side, does proximity come into this as well? As you call it, flying in certain airspace, I think it's clear why flying in an airspace would make you more at risk of a literal missile, for example.
23:21But does it then also increase sort of that attack surface in terms of where you are flying? Actually, it doesn't because these missiles are able to fly hundreds of miles. I don't even have to fly near the border. They can even hit me here and over at Amsterdam if they want. But that must be an intentional order given by some high-up commander. Quite often, it's just trigger-happy, untrained soldiers on the ground that see a target and think, oh, crap, this is not ours, and they fire. So if your military is badly trained and with a corrupt command and control structure, which we have in Russia, everybody's trigger happy.
24:00There's no discipline. Yeah. So moving away from pure aircraft for a second, actually looking at airports as well. Now, I mean, I think maybe the one that our audience might be aware of recently, which was not a cyber attack, but it clearly showed that what could happen was obviously CrowdStrike and how CrowdStrike managed to inadvertently take out airports, control systems, well not control systems, but a lot of display systems and just logistic systems so people simply couldn't fly. Is that something you advise on or deal with as well? So not in the air, but actually on the ground as well? Well, I think one of the basics of cybersecurity, all CISOs will preach that is stay away from single points of failure.
24:45It's not aviation related. It's a single point of failure and you need to have a plan B. And remember, I think it was Heathrow that shut down for a few days due to an electrical substation? Yes. Single point of failure. Very effective DDoS actually, but not intended like that. Yeah. So those are basics. In general, whenever I am consulting anybody in aviation, we fall back to the basics. It's basic cyber hygiene. And that's not only in aviation. That's in every sector, every industry. Everybody needs to go back to basics. Simple vulnerability reduction, simply identity management. It's not rocket science.
25:27We have all the knowledge. We have all the tools. We can implement it. but somebody has to put the money aside organize it and say this is how we're going to do it and up till then we are vulnerable everybody not only aviation back to basics basic cyber hygiene is what we need to focus on for the next couple of years yeah i think that's very interesting where people maybe think it's more complicated than it needs to be quite frankly to keep on top of this stuff where even though it's an airport and it's a critical piece of infrastructure in a country the people actually running the airport unfortunately might still be a bit behind when it comes to as you call out just basic cyber hygiene so very interesting let's move on to i know that you've got a sort of a lot of thoughts around leadership and culture in this space and i think this is very interesting to sort of cross over here where the way that the aviation industry operates cyber security could probably learn a few things so i think the big one here is this idea of just culture, which is juxtaposed with blame culture.
26:30So I think let's go there and maybe you could help us understand what is just culture? Why has it sort of been in aviation a while? How does that maybe translate over to, or should be translating over to cybersecurity as well? A very interesting crossover. I gave a presentation last year at Black Hat about what cyber security teams can learn from aviation just culture. And it's actually very simple. Just culture is a culture where you encourage incident reporting without fear of punishment to enable the organization to learn and to improve. Because humans make mistakes. We are human. We make mistakes by default.
27:08And that is okay as long as you don't do it intentional. Basically, there's a gray area in that, but this is basically what it is. So if I make a hard landing, I make a mistake, okay, then I report it so other people can learn. If I am being spoofed with a new system and I see data that I've never seen before on my instruments before, I report it so everybody can learn. And then I don't want it to stay inside my company. I want the companies to share. I want the aviation sector to share. And not only sovereign, I need global sharing. That's why we need CII sex to get all this information out there with our friendly allies.
27:46But back to just culture, that's basically what it is. And we see a lot in large companies, not aviation companies, but maybe also aviation companies like airports, where people are clicking a phishing email and, oh, I think that was wrong. Oh, I better go home now. Maybe nobody sees it. Right. And then without knowing it, within 17 minutes, your whole network is compromised and infected. If this person would have called their CISO, they might have been able to mitigate and keep it within the house. Yeah. So it's about the culture and the culture goes top down. It's leadership by example. I think that's a good way of explaining it.
28:24There's a website that some of the audience may know called Aviation Herald, AV Herald. And that's sort of, at least that's where I as a layman go to just sort of check up on reported incidents. You know, they get classified, crash, obviously being the worst. And then, you know, I think accident and then incident or something like that. And the funny thing is, I've noticed how the airline, again, let's just say British Airways, for example, a lot of things pop up from British Airways. And some people might look at that and go, wow, they have so many issues. And actually, I am much happier seeing that than the airline I never see.
28:59I don't know which one to name, but you know, there are certainly airlines that virtually never pop up. And that to me is, that's a reporting problem. So actually, there's just safety in reporting, effectively. Capital One's tech team isn't just talking about multi-agentic AI. They already deployed one. It's called Chat Concierge and is simplifying car shopping. Using self-reflection and layered reasoning with live API checks. It doesn't just help buyers find a car they love. It helps schedule a test drive, get pre-approved for financing, and estimate trade-in value. Advanced, intuitive, and deployed.
29:30That's how they stack. That's technology at Capital One. So how often do you see a Chinese or a Russian airline pop up? Exactly. Or an airline that is part of any dictatorship. None. Doesn't happen. Because they carefully cherish their ego and their image and their reputation. And of course, let's not forget A.V. Herald. I think it's a British publication, isn't it? It could be. Yeah. I'm not actually super sure. But yeah. Anyway, they're well linked with information into British Airways apparently, which might give you as a reader the wrong idea. Luckily, there is a global international cap statistics to keep it all within proportion.
30:06I mean, we see this in obviously cybersecurity. To some degree, we've got obviously the Verizon DBIR, which comes out every year. I think the thing there, though, is it's less attributed to specific companies, or at least in the report, it's more about stats. But the point is that can only exist because of reporting. Someone in a company has reported the incident or the breach of what happened. But I think it's fair to say we're still way off in cybersecurity in terms of reporting. reporting oh yes so in cyber security i see the traditional blame culture which discourages reporting of security incidents prevents the organization from learning and you're unable to improve your defenses i see it a lot in asia as well not only in aviation but blame culture is pretty much standard especially behind closed doors there's no learning there's no wanting to learn it's all about kpis and making money and it's often very subtle it's very difficult to see as an outsider as well blame culture because people are being laid off being fired on the spot then you ask them why are you fired ah yeah you never find out really because they don't want to lose face as well but the blame culture is pretty much standard and in aviation like i said before aviation safety is written in blood we learn from accidents if we don't learn from accidents then there's more blood gonna be needed to write and that's not good yeah i mean obviously i've worked in Asia Pacific for a while now and certainly in cyber security.
31:32It was challenging on the basis that companies don't even sometimes want help with an issue because they simply don't even want to talk about the issue. Exactly. Losing face is more dangerous than solving a problem. Yeah. So yeah, I mean, obviously props to Verizon. I mean, I believe the Verizon DBIR came out with the fact, well, it had its own pretty major hack at one stage. And instead of sort of sweeping it under the carpet, so to speak, they went completely the opposite side and said, look, we're going to be the people that hold the flag for reporting. So I think that's very interesting. And as you call out, aviation has had to, or at least aviation outside of say dictator, state, country sponsored airlines, they kind of have to learn from each other.
32:18Otherwise, as you call out, unfortunately, people literally die. And that's sort of why it's been so critical. So how these airlines in authoritarian regimes often learn is by reading our open source reports and learn from that. So they learn from us, they leech. And internally, if somebody makes a mistake, that person is simply being fired on the spot. That's how a blame culture solves problems. Yeah. So we're going to move along to, we always have to talk about AI these days. But here, this is not bad. We've gone well over half an hour without even mentioning AI. But where are you seeing AI, especially, obviously, we're talking here about cybersecurity, cybersecurity in aviation systems.
33:01Is there anything kind of being rolled out here to do with AI in terms of threat detection or anything along those lines? I mean, what are you seeing in that space? Well, splitting the aviation industry in two parts. One, the airplane, and the other one just simply the rest, the airport, the airlines, which are also just buildings with people and computers and networks and their own vulnerabilities. On the airplane side, I do not see any AI being implemented from where I can see it. I'm sure Boeing and Airbus and Embraer, they're all working on it. But I do not at the moment see any implementation of it in my airplane systems today.
Read the full transcript
33:40Having said that, on the other side, of course, airports, airlines are working on their own AI applications for airlines. That is mostly about efficiency, operational efficiency, fuel efficiency. And on the other hand, of course, client retention, passenger retention, passenger appreciation and all that side of the business. As in cyber, I think the same again for any other industry. we're trying to use AI to threat detection, behavior analysis, threat intelligence processing, automated incident response, the same as in every other industry. But again, for my airframe, I don't see anything yet.
34:18Okay. Moving on from say AI, but 5G, you know, 5G, I believe is rolling out. Well, is 5G rolling out within the airframes themselves, or is it more just that 5G as a standard is having effects on say instrumentation or what does 5G do in this case? I can imagine that engine manufacturers are very happy with it because with 5G chips in their engines, they can send loads of data way faster. And that's all telemedicine they need for preventive maintenance, of course. It's very important data. Furthermore, I don't see this in or around my airplane a lot. I guess most of the data when I'm airborne or all data will not go by 5G because at 12 kilometers, there's simply no reception.
34:58So it will go via ground stations and then it might be further on routed by a 5G. But those are our ground systems. I don't consider that aviation systems at all. It's just a ground-based communication system with all the risks that come with it. Because imagine if you can, let's say you can control all the hardware being used for 5G with backdoors. Wouldn't that be great? What a great threat service that is. I'm just saying Huawei. Yeah, I mean, it's widely reported, obviously, that that could be quite a threat. Unfortunately, still a lot of people that don't understand. Below the radar, it's hybrid warfare.
35:33It's not warfare, but it's still hybrid warfare. And we need to understand that we are being threatened. We need to understand who is the enemy here. And that's where threat intelligence is crucial and sharing threat intelligence. Yeah. And moving on from 5G, so we're just sort of hitting the key emerging technologies in this space. Drones, you know, we can't ignore drones. So let's just talk about those for a second. And we're not necessarily talking about military drones, very much commercial drones as well. but like they're kind of being integrated into control airspace these days you know i mean certainly i find it fascinating in singapore i see so many commercial drones now you know they're used for surveying you know there's one i live near some water and one pops up every morning to kind of survey the water stations or something to that effect i mean these things are huge how is that affecting sort of especially again in the cyber security lens like what kind of extra threats or sort of challenges is adding well stepping away from cyber security and just for aircraft safety like birds you don't want drones next to your airplane now anybody can buy a drone for a hundred dollars or euros or pounds or whatever and fly this thing around and it's amateurs flying this cheap stuff around airplanes that is the real risk in singapore we love our technology it's widely being implemented for the benefit of the whole society but it's all controlled it's very tight controlled there's no airport in the world allows drones close by but how do you check until it's too late so i have quite often i hear on the radio somebody reports a drone nearby and it's just some idiot with a camera trying to make a great shot for his instagram feed or whatever but it's not safe and we shouldn't do that but it's more a legal problem because we need regulations on that.
37:21And next to that, we also need tools to punish the people who do. I would be great if we could have a laser gun shooting down illegal drones around my airplane, preferably automated. That would be great. Problem solved. But we don't have the legal tools for that yet. So the legal frames are still in the making. But the next couple of five years, we're going to see a lot of regulations around drones. It's still all very much in the beginning of the development. And then I'm not even talking about warfare and hybrid warfare drones that are being used for surveillance, intelligence gathering, or just disrupting with GPS jamming and spoofing.
37:59Just fly around an airport and jam everything for a couple of hours. ADS-B interference, of course. There's a lot you can do with a drone to create chaos and to disrupt. And disrupting an airport is disrupting the economy very directly. Yeah. So we're going to move along to more of the training and education side. I mean, I know this is something that you work in a lot. I think you said towards the beginning of the episode, just that a lot of pilots are simply not getting any kind of training when it comes to the cyber side of things. But I believe there is some form of simulator based cyber training.
38:38Could you just speak a bit to that? And like, how realistic is this to actually mimic the problems and just where does it kind of even start in terms of bringing cyber training into the simulator side of things and i mean i guess for those who are not super familiar with aviation simulator training has always been a huge part of modern flying you know you have to do sort of set hours i believe on simulators and practice catastrophic situations and this kind of thing but that's sort of to my understanding always been or until recently without this lens of but it could be a cyber attack it's just oh my engine failed and for pure mechanical reasons and now we need to deal with that which is different to my aircraft is under cyber attack so yeah could you just speak a bit to that yeah you say correctly that simulator training is actually the only way that pilots learn you need to see feel and do it we do a lot of cbt training as well but that is basically all compliance you don't learn much from that that's just not how it works Not everybody is a visual learner, especially pilots.
39:41Since there are a lot of complex procedures, you need to hands-on train these procedures. Only then you will fully understand what it means, how it works, and why the procedure is designed as it is. So if we need to train cyber scenarios or hybrid warfare scenarios, we need to do that in a simulator. That is very obvious. Unfortunately, nobody does that in the world yet. And for that reason, I started last year the Aviation Cyber Academy in Singapore with a curriculum for our masterclass in cybersecurity for pilots where we start with the basics. Then we talk about airplane threat services. We identify it all.
40:19Then we move over to your specific airplane. And then we do scenario-based training, two hours in the simulator afterwards. And then it gets interesting because the simulators were not designed to simulate cyber attacks and hybrid warfare attacks. So I need to be very creative in showing the right cues and data for them to understand what's really going on. So there's a lot of creativity involved yet, but I'm sure that the simulator builders are now working on creating more realistic scenarios in their simulator as well. But yeah, it has to be simulator training. hybrid warfare scenarios actually has to be recognized and trained as well those are actually much easier because i can simulate of course a unverified message coming from an illegal center a non-verified center that's much easier and what sort of general uptake or reception have you sort of found i mean you're very much on the ground in singapore doing this training i mean are you finding these are pilots coming from other countries to come and do this or at the moment Is it more Singapore-based thing?
41:23I'm just curious sort of how the industry is receiving this. Okay, well, the industry is actually not receiving it at all at the moment. For the same reason, I stated in the beginning that the airline top management does not see cyber yet as a primary business risk. I talked to pilots. They would love to go through the training because we always feel we need to understand what's going on. But then again, they don't pay the training and you need to have it on your roster, on your schedule. The simulator needs to be reserved. You need to have an instructor. The whole training part of that and the organization part of that needs to be done as well.
41:58So for now, it's ready to roll. And I'm waiting for airlines to show up and tell me that we need this. Because right now, 91 % of crew reports that they are concerned about flight safety impacts of not being trained rigorously enough about what's going on here. They just don't understand. And I can't blame them because this is quite complex stuff. Yeah, that's very interesting. And I mean, obviously, I hope as a passenger, as much as anything, that this is taken more seriously by airlines. Yeah. So, I mean, we're coming up for time a little bit, but I'd just like to get your take on, I guess, sort of the next, I know this is always a bit of a crystal ball, the next five years, for example, in sort of aviation, cybersecurity.
42:43What are some things that maybe you think are very likely to actually advance and then maybe what is a couple of things that you would like to advance but you're not convinced that even within five years they're going to change okay well i'm very much convinced that nation-state cyber warfare will increase because it's a very cheap and below the threshold way of disrupting your enemies so we're going to see more cyber warfare also affecting aviation. And we can see Putin now is getting more bold. He's now blowing up supermarkets even in Europe. No shame at all. And it's very difficult to attribute that to him.
43:25So we will have more hybrid warfare, more nation-state cyber warfare, absolutely, which only makes my point that we need to continue being more resilient and ramping up our security. And for that, of course, critical infrastructure ISACs are absolutely necessary, not just get all aviation together. That's way too small. We need to have all our critical infrastructure CISOs together and we need to start sharing today. It's not a luxury, it's a necessity. Yeah. And I mean, I think you sort of, I guess, touched on it with your cyber simulator training. It's one of these sort of, I guess, chicken and egg problems where you've just sort of predicted that all the problems are going to get worse.
44:04So you'd think that there are more opportunities for there to be more, I guess, commercial businesses coming into the space. Like the way that cybersecurity has as an industry exploded over the last 20 years, an explosion of, say, EDR providers and this kind of thing. Do you see there being a version of the next five years where aviation cybersecurity suddenly is a hot thing? And, you know, I would say or I'm questioning like the incumbents. Let's just take CrowdStrike as an example. like could you see a crowd strike having an aviation offering for example where an edr sits on a plane or anything like that well yes and no i don't think crowd strike is going to do that because they simply don't have access to the architecture of the airplanes i would love to say that within five years i hope boeing airbus embraer and all the big names are working very hard on that and can show me at one day a brochure and a diagram saying this is how we fix it this This is how we increase our resilience.
45:03Very unlikely they'll give me a call, but I really hope they're working on that. On the other side of aviation, the non-airplane side of aviation, of course, CrowdStrike can do whatever they do and what they're good at doing by creating more cybersecurity and resilience. That part of the aviation sector, I do not find very interesting because it's the same challenges like manufacturing, finance or healthcare. It's just a building with a lot of network and most likely some OT attached to it as well. Which, by the way, OT, Operation Technology, has their own challenges. But that aside, yeah, I really hope that there will be more vendors.
45:38But as you know as well, 20 years of cybersecurity, a multi-million cyber vendor market. And it's all very sexy with nice tools. But we forget the basics. I am teaching cyber hygiene basic. That's what we keep forgetting because it doesn't sell. so the market is created to create money not to create security in general i see a lot of products on the market that are being sold to people that don't need it confusing cso's maybe they're inexperienced because there's also young cso's and they walk around on these floors of large cyber security events and they're being attacked on all sides by vendor you need this you need that we can do this yes we can do it month later oh actually it doesn't fit now cannot to connect no actually configuration doesn't work yeah sorry boss yeah big problem and once it's connected it's already legacy because you can't get rid of it anymore and that's a big problem and that's why an airplane like a boeing or an airbus it has a lot of third-party hardware and software as well and connecting all that stuff is a challenge absolutely and that's why there are standards so changing these standards again talking airing changing these standards has a huge impact because everybody, every vendor, every third-party heart and software provider has to adapt, which costs money, which makes the product more expensive, which makes the airplane more expensive.
47:02It's all connected. Yeah, I think that's a really good call out. And we obviously saw the, obviously it wasn't cyber related, but it was sort of technology related. We saw sort of the outcome of this in those Boeing 737 MAX crashes where effectively technology had changed, but it changed at a pace that hadn't for various reasons cost reasons etc pilots had been trained on that technology change and the outcome was catastrophic unfortunately and i think what you're getting at is the fact that for anything to change inside an aircraft we're not talking like a lead time of like a year it's like 10 years from sort of start to finish of especially if we think of again let's just go back to the crowd strike example for a second it touched the kernel of windows which is in theory why it's able to protect things but it's also in theory why it's actually got the most risk if it goes wrong because it can sink the whole system so i think in aircraft that would obviously be just doubly problematic if you have systems that technically could fail the whole aircraft as well absolutely great example and then next to that you buy an airframe for 30 40 years we have the same problem like the maritime sector these big container ships they've been around for 40, 50 years, man.
48:16Most of them still run on MS-DOS. I tell you, MS-DOS. Talk about cybersecurity and resilience. I mean, hacking on container ship, really, it's not that difficult. Yeah, well, maybe we'll need to find ourselves a maritime expert as well to bring on the show at some point, yeah. And then next to that, we're going to have a lot of extra frameworks, new frameworks, regulation frameworks. They will mature significantly, I think. ICAO will probably set the standards. The standards will probably become mandatory with enforcement mechanisms. Right now, it's all more advisory, but we need to enforce because you can imagine, let's say one country is taking that chaos standard serious and the country next to it is not.
48:56It's not working. We have to do it all together. Cybersecurity is teamwork. So enforcement is going to be needed. Otherwise, it's not working. And then in Europe, EASA and the FAA, they will also implement, I think, binding cybersecurity requirements for aircraft certification and airline operations. we can't ignore it anymore. We can't afford it. Yeah. Well, I think that's a great place to leave this today. I mean, I think this has just been a fascinating conversation and obviously a lot of knowledge and understanding imparted from you today, sir. So I really appreciate you coming on Software Engineering Daily.
49:30And I think, I imagine 99 % of our audience have learned something new today. So thank you so much for coming on. My pleasure. Have any questions, find me on LinkedIn and I gladly answer them. Fantastic. Thank you so much. Thank you.
From the publisher
Aviation cybersecurity is becoming an urgent priority as modern aircraft increasingly rely on complex digital systems for navigation, communication, and engine performance. These systems were once isolated but are now interconnected and vulnerable to cyber threats ranging from GPS spoofing to ransomware attacks on airline infrastructure. As nation-state actors and criminal groups grow more sophisticated,
The post Aviation Cybersecurity with Serge Christiaans appeared first on Software Engineering Daily.
