Cybersecurity takes top investment priority in air traffic industry, according to SITA
11/01/2019 by WiT

Airports and airlines are amongst travel’s most rigorous when it comes to physical security checks – from baggage scans, restrictions on liquids, and random passenger searches. However, the development of technology in the air industry has meant that threats to safety are no longer just physical, but online too.

Last October, Cathay Pacific dealt with “the worst ever airline data hack”, which affected over 9.4 million customers. It wasn’t alone. In the past year, British Airways, Delta Air Lines and Singapore Airlines have also experienced cybersecurity breaches, involving the exposure of personal details and payment information of passengers worldwide.

Now more than ever, there is enormous pressure on airport technology providers, as well as individual airlines and aircrafts to buffer themselves from hacks and data breaches, which threaten to jeopardise the personal data of millions of travellers worldwide.

Fortunately, the air transport industry is becoming far more proactive, when it comes to fortifying their digital walls, going from basic security compliance to developing more proactive ways to monitor and handle potential online threats.

Online security investments are taking off in air travel

According to SITA’s 2018 Air Transport Cybersecurity Insights report, airports and airlines are already very much aware of the immediate need to boost online security. In fact 95% of airports report having major plans to redevelop cybersecurity initiatives by 2021.

This is coupled with a small but significant shift in spend on cybersecurity in the air transport industry over the past couple of years. Both airports and airlines have boosted spend by 2% (as a proportion of their IT budgets) between 2017 and 2018, with a higher increase expected this year. While a fractional jump, 73% of survey respondents ranked regulatory compliance and data privacy regulations as being of utmost priority.

In fact, 41% of those that have organisations that have listed cybersecurity in their global risk register have already implemented core safeguards, while 43% of organisations have expressed intent to implement measures by 2021.

Online safety is being inhibited by real-world obstacles

While the vast majority of organisations have already made cybersecurity a leading priority, there are central delays to progress. First and foremost, a lack of empowerment by top-level executives will inevitably slow an organisation’s ability to adapt quickly to changing security needs. There is also a general lack of resources (affecting 78% of organisations), budget (70%) and skills (56%) required when preventing and handling threats.

This reveals that while dangers exist online, there are real-world, organisational obstacles that are limiting progress in this domain. Setting up dedicated departments and recruiting those with cybersecurity expertise must be a strong priority across all organisations going forward.

According to SITA, employee awareness of any company’s data security policies should be the top priority, stating, “Employees are the weakest link in the fight against cyber attacks.”

For example, only 31% of organisations included in the survey have a dedicated Chief Information Security Officer (CISO) responsible for handling information security, while 22% of organisations leave this up to their Chief Information Officers. 13% leave information security issues up to C-level executives to handle, while other teams or staff members handle the remaining 34%.

As of now, only 44% of organisations have implemented a formal “Information Security Strategy”, with 48% planning to develop one by 2021. This reveals that while cybersecurity is of stronger priority, efforts to address it are largely fragmented between different companies.

The shortcomings reveal an industry-wide need “to complement internal resources with external expertise.” By doing so, organisations can set a clear cybersecurity strategy going forward. It will help them identify what the business processes are and what key areas require attention.

In fact, ‘employee awareness and training’ and ‘achieving regulatory compliance’ are the most common spending priorities today, in the realm of security.

93% of survey respondents have formal cybersecurity training programs for employees – 45% of whom have implemented these programs company-wide, while 24% have done it for part of the organisation, and 24% plan to roll it out by 2021.

Creating a dedicated department to handle online security measures is therefore critically important, to set a higher industry-wide standard for how data protection measures are handled.

Implementing a dedicated Security Operations Centre (SOC)

The most robust way to combat online threats, according to the report, is the establishment of a Security Operations Centre (SOC) – an organisational unit dedicated to handling security issues. Doing so would make organisations far more proactive in monitoring and handling potential threats that surface.

“A SOC is often the first component security executives look at when building up their cyber defence capabilities. Only 33% of responding organisations have a SOC implemented today, but a further 47% of respondents plan for such investment by 2021.”

Of those that have implemented a SOC, only 7% manage it in-house, while the remaining 26% have outsourced to external providers. This is an effective means of overcoming shortages in resources and skills required to implement cybersecurity strategies within organisations themselves.

“We’ve seen that there are very few airlines and airports that are investing in-house… they can’t keep up with the technology and the investments are really high,” said Sumesh Patel (president APAC, SITA).

The majority of these centres are still primarily focused on protecting organisations’ digital infrastructure (90%), with some focus on the back-office (52%) and business applications (39%).

“The back-office and business applications…[are] where airlines and airports are still learning,” said Patel. “They don’t yet know exactly what areas can cause issues.”

For example, business applications involve interactions with multiple stakeholders, meaning no singular organisation has total control. These areas require a deeper understanding of how applications behave, and which interactions need to be monitored most closely to detect any breaches.

By contrast, protecting digital infrastructure is considerably easier as there are already best practice methods in place, which organisations can readily adopt and implement.

Thus, tackling a new world of online security is still in its early stages as investment priorities begin to shift more assertively towards online security. While external threats remain as the biggest security priority, cyber threats of all forms now prominently feature. The onus is therefore on the air transport industry to be proactive in developing protection measures for travellers beyond physical airports and airplanes.

Lead image: Getty Images

BACK