CYBERSECURITY AND DATA PRIVACY IN THE AVIATION INDUSTRY
Author: Pushkraj Sonawane , Mohanish Kharkar , Pratik Kakade DOI: https://doi.org/10.68120/IC2425C1 Page Numbers:1 to 6
Keywords: Cybersecurity, Aviation industry, Data privacy.
Abstract: The two significant incidents of cybersecurity in the aviation industry discussed in this paper are the March 2020 hack at San
Francisco International Airport (SFO) and the 2018 hack of British Airways (BA) data. It finds out why they happen, how extensive they are, and how damaging they are, and it examines them, using known frameworks: the NIST Cybersecurity Framework, ISO/IEC 27001, and corporate governance principles. We comment on strategic insights and implications of the case of management in airports and air travel, as well as on investment and policy aspects. The analysis points out the role of poor practice in the identification of risks, protective measures, as well as governance in the incidents, and the necessity of taking an offensive stance in cybersecurity approaches. Each discussion question is taken into account, with the help of which the paper provides some insight into how the risks can be reduced with the help of formal frameworks, the policy of the board of directors, transparency of breach response, cost/benefits of any investment into security, and reputation. In conclusion, the idea that cybersecurity should be part of business strategy and corporate culture in order to secure important aviation infrastructure and customer information is hammered home.
INTRODUCTION:
The fast migration of airport and airlines functionalities to digitalisation has made the processes highly efficient and customer-friendly; however, it has completely made these organisations vulnerable to the growing cyberattacks. The airports and airlines have Sensitive financial and personal records are a sweet piece of target for any attacker. Two cases of the cyberattack that occurred in San 3 Francisco International Airport can be given in March 2020. The (SFO) and the July-September 2018 data breach in British Airways (BA).
In the event of the SFO incident, the hackers managed to hack the web portals of the airports, with the malicious code being installed in order to get the employee login details.The malicious hacks crept into the BA site and application and drained the information involving names, addresses and payment cards. The number of customers amounts to hundreds of thousands. These incidents confirm that cybercrime and the possibility of exploiting loopholes in cybersecurity measures can lead to mass data theft and reputation loss.Each of the breaches is described as a case in the paper with the help of an analytical framework (NIST CSF, ISO/IEC. The (27001 and corporate governance to study what has caused it to go wrong, and also give strategic implications on what to do to strengthen the security.
Our final question is asked as a list of fix-it discussion questions concerning how frameworks might have been different to prevent the breaches, how the right board policies can be implemented after the breaches, and the role of faith transparency, investment trade-offs offs and reputation clean-up process.
Case Background SFO Cyber Attack (March 2020)
Back in March 2020, the San Francisco International Airport suffered a cyber attack. Reported that its two subsidiary websites had been hacked by cybercriminals. The involved websites were the SFOConnectcom (employee news site to access airport resources) and SF Construction (information on airport works).
According to airport authorities, unknown attackers “inserted malicious computer code” on these websites to steal login credentials from users. The compromised users were primarily airport employees and contractors who accessed the sites from devices outside the airport network. The stolen credentials (usernames and passwords) were likely intended to facilitate further infiltration of airport systems (a form of “Magecart” style attack).
Airport officials discovered the breach after notice from security researchers and took both sites offline. They found that the code had allowed the attackers to capture Windows account credentials. San Francisco Airport (SFO) announced a data breach. They told users affected by the breach to reset their passwords. The airport quickly removed the harmful code, reset many passwords, and improved their security checks.
At first, it looked like the hackers did not use the stolen passwords to access other parts of the airport’s network. The breach showed that the airport’s web systems had weaknesses. There was no tool in place to detect harmful software. Also, websites not used by the public were not well protected, which made it easier for hackers to get in.
British Airways Data Breach (2018)
In September 2018, British Airways said its app and website were hacked. The breach lasted from August 21 to September 5, 2018. About 380,000 people had their personal and payment info stolen. This included names, addresses, emails, credit card numbers, expiration dates, and CVV codes. No passport or travel details were leaked. Hackers first broke into the system of Swissport, a company that worked with British Airways. They used that access to put harmful code into the BA app and website. This code sent customer payment info to a fake website. British Airways didn’t notice the attack right away. A third party informed them on September 5. They removed the bad code within 90 minutes of finding out. BA then told the UK data regulator (ICO) and warned affected customers. They were criticized for the breach, and their stock price dropped. The media also heavily criticized the company.
About the breach, the ICO finally assessed BA with a 20-million-pound (1/4 of its suggested fine of E183 million (1.5% of its included revenue in 2017). The incident of BAis argued to be among the biggest ever airline data breaches, which signifies a material weakness related to its web security and governance for a long time.
These incidents are examples of an increasing trend: airlines and airports become a desirable target of cybercriminals because of the IT systems they currently have and use, and the data they contain that could be valuable. In both the SFO and British Airways cases, hackers took advantage of weak security. They used the time they had after stealing data to do more damage. These attacks shook customer trust and forced both companies to take urgent action. Looking at these events helps us understand the need for stronger cybersecurity.
Analytical Frameworks
Understanding Cybersecurity with the NISTFramework The NIST Cybersecurity Framework (CSF) is a guide to help protect important systems.It’s not mandatory, but it helps companies manage risks.
The framework has five main steps:
● Identify – Know what needs protection.
● Protect – Put security in place.
● Detect – Spot when something goes wrong.
● Respond – Act quickly to fix it.
● Recover – Get things back to normal. When we look at the SFO and BAbreaches using this guide, we see problems at every step.
● In the Identify stage, both companies didn’t fully know which systems or data were at risk. They also didn’t find the weak spots before the hackers did. Neither SFO nor BA had fully identified all critical assets or potential vulnerabilities before the breaches. For example, BAhad not updated an old JavaScript library on its website, leaving a known exploit unaddressed. Both organisations lacked a thorough inventory of their online assets and did not recognise this weakness, indicating a failure in the Identify function.
●Protect This covers safeguards like access control, encryption, and security best practices. In both cases, basic protective measures were absent or inadequate. Neither SFO nor BA used multi-factor authentication (MFA) on the accounts targeted by hackers. NIST emphasises MFA as a critical enhancement beyond passwords alone. Additional protections, such as endpoint encryption and secure coding, were also lacking. For instance, BA’s decision to log plain text credit card data for convenience (a human error noted by the ICO) represented a failure of protective design. SFO’s websites had no secure web gateway or anti-malware filters, allowing injected scripts to operate undetected.
● Detect This function pertains to identifying cybersecurity events promptly. Both organisations failed to detect the intrusions in real time. At SFO, the malicious code remained on the sites long enough to steal credentials before anyone noticed. BA similarly did not realise its systems were compromised until notified by an external party almost two weeks into the attack. This delay meant attackers had unrestrained access for an extended period. Effective intrusion-detection systems or real-time monitoring (components of the NIST CSF Detect function) were insufficient or inactive in both cases.
●Respond Once a breach occurs, the ability to contain and mitigate impact is key. Both SFO and BAreacted reactively. Their incident response teams were reportedly underequipped and undertrained. For example, BA officials were slow to identify all affected customers and did not publicise details promptly. NIST recommends clear communication plans, roles, and procedures for incident handling. BA’s response, which involved late notification to regulators and customers, showed that such plans were either absent or poorly executed. SFO had to scramble to remove malicious code and reset credentials, indicating they lacked a fully developed response plan.
● Recover After incidents, organisations should restore systems and learn from failures. Both breaches caused entrenched reputational damage. Recovery for BAinvolved regulatory fines and an extensive PR response. The negative publicity was “widespread and entrenched” (especially for BA). NIST’s Recover function would suggest formally updating recovery plans based on lessons learned. BA did revise some practices (e.g., removing stored card data) after the breach, but much of the damage to customer trust remained. In short, recovery in terms of regaining goodwill was costly and only partially addressed.
In summary, each NIST function reveals shortcomings. If SFO and BA had fully implemented the CSF, they would have conducted rigorous risk identification and protective controls (such as MFA and secure coding), enabling faster detection of anomalies. NIST’s emphasis on a “common language” and regular updates means organisations should continuously improve defences as threats evolve. he security breaches at San Francisco Airport (SFO) and British Airways (BA) show that the NIST Cybersecurity Framework (CSF) was either not used or not used properly. That’s likely why the attacks were not noticed in time.
ISO/IEC 27001 and the Information Security Management There’s another system called ISO/IEC 27001. It’s a standard way for companies to protect their important data. It works from the top down, meaning leaders are involved in keeping things secure. This system includes things like risk assessments, rules for who gets access, written security procedures, and regular internal checks.
In both the SFO and BA cases, there’s no clear sign that this system (or anything similar) was being used. ISO 27001 requires companies to look for security risks and fix them using specific tools listed in the standard.
But SFO and BA didn’t seem to have any solid process to find weak spots. For example, BA didn’t update an old JavaScript file that had known problems. That shows they didn’t have a way to manage or fix outdated software. If they had followed the ISO 27001 system, they would’ve done regular checks and cleanup to avoid that kind of risk.
● Access Control Policies Annexe Aof ISO 27001 involves access control policies on users. The access controls are weak, as demonstrated by the stolen credentials. Neither SFO nor BA had implemented such policies as leastprivilege or MFA. ISO 27001 would impose writing the rules of access and review regularly, which could have avoided the harvesting of passwords as the only authentication method.
● Occurrence of Risk and Procedure Monitoring. The theme of the standard is an orientation of treating risks and observing their efficiency. Such a store of some sensitive information in plain text was a failed treatment when BA made it a habit to do so. That as an unacceptable risk or misconfiguration would have been identified by the implementation of ISMS, verification would have happened through the control.
● On the same point, SFO does not have endpoint security, meaning they did not treat and test such systems well. Overall, ISO/IEC 27001 is supposed to safeguard information resources through applying a comprehensive risk approach evaluation and ongoing improvement. With an established ISMS compliance coupled with ISO 27001, SFO or BA would have established formal processes to determine what is lacking and not there, and implement security standards (like encryption and authentication). Control testing.
In other words, a certified ISMS would have ensured proactive security management, whereby the security would have been managed in advance. With a possible initiative of preventing or reducing such violations. They also did not have ISO controls that would make security interventions consistent and responsive.
Corporate Governance
Cybersecurity should become a part of corporate governance. Decent governance addresses cyber-hazards as a rational strategic issue and not only a simple problem in IT. An advisory issued by CISA highlights the fact that cyber risk is presently a business risk under the ownership of boards and CEOs. Both plane crash situations had a faulty board-level review.
● Board-Level Oversight In his his article entitled Developing Information-Based Risk Assessment in a Post-9/11 World- Incorporation of Serious Discussions, Chris Thompson pointed out that information-based risk identification is an emerging trend in the corporate world and discussions on such identification should be taken seriously because they may very well be our saviors in this post-9/11 world. Mandates the board to be updated regarding risks and the occurrence of cybersecurity incidents. Nevertheless, it is reported that the top management and the board of directors of BA did not focus on cyber spending or awareness. Similarly, it appeared that SFO considered cybersecurity routine ITtasks as opposed to a board mandate. CISAobserves that boards are supposed to empower CISOs and fund them, and that the decisions made on cyber are clear. Executive accountability findings on BA indicate the board had overlooked even fundamental security measures, which ICO attributed to a “profound organisational failure in digital risk management”.
● Cybersecurity Culture Corporate governance extends to culture. BA treated compliance (e.g., GDPR) as a boxticking exercise rather than an imperative. The ICO report criticised BA for lacking encryption and strong authentication as if they were optional, reflecting a failure of tone at the top. In contrast, boards should foster a culture where managing cyber risk is seen as a core responsibility.
● Investment and Prioritisation Directors must balance cybersecurity budgets against other business needs. In these cases, evidence suggests cybersecurity budgets were constrained. Good governance would evaluate security spending as an investment in resilience, not just a cost centre. Frameworks like ISO 27001 and NIST CSF should be endorsed by the board and integrated into the risk appetite statements.
In summary, corporate governance failures contributed to these breaches. Neither SFO nor BA had a governance structure that elevated cyber risk to board agendas. Industry guidance (e.g. NACD Director’s Handbook co-developed with CISA) stresses that cyber must be a “fundamental matter of good governance”. The SFO and BA incidents underscore that neglect at the governance level leaves organisations vulnerable.
●Strategic Implications The SFO and BA breaches have broad strategic implications for the aviation industry. Key lessons and recommended actions include:
● Board-Level Accountability Boards must treat cybersecurity as a strategic governance issue rather than a technical afterthought. Regular reporting on cyber risk, incidents, and compliance should be mandatory. Directors should insist on cybersecurity metrics alongside financial and safety metrics. This aligns with CISA’s call for boards and CEOs to “own” cyber risk as an enterprise risk.
●Enhanced Security Investments Organisations should invest in modern security infrastructure. Examples include Security Information and Event Management (SIEM) systems to correlate and alert on threats, Endpoint Detection and Response (EDR) tools for monitoring workstations, and next-generation firewalls. These tools support the NIST Protect and Detect functions by identifying anomalous activity. As NIST points out, a risk-based approach allows firms to allocate resources effectively. Despite budget constraints, the cost of breaches (investigations, fines,remediation) typically far exceeds prevention costs.
●Employee Training and Awareness Human error remains the top factor in breaches. In 2025, 95% of breaches involved some human mistake. Regular, targeted training is crucial: simulated phishing exercises, clear guidelines on credential handling, and enforcement of strong password/MFApolicies. SFO’s attack relied on phishing out credentials, and BA’s breach also exploited social engineering; better-trained employees might have raised early alarms.
●Third-Party and Vendor Risk Management Both cases likely involved external partners (contractor networks at SFO, a cargo vendor at BA). Enterprises must rigorously vet and monitor their vendors’security practices. This includes requiring suppliers to comply with standards (e.g., ISO 27001 or NIST CSF alignment) and conducting periodic audits. Attackers often pivot through weak supply chain links. A systematic vendor risk program is needed to map dependencies and set security criteria for third parties.
●Regulatory Compliance and Penalties Since GDPR and similar laws, protecting personal data is both an ethical and legal mandate. Companies must implement privacy by design and report breaches promptly. For example, GDPR requires notifying authorities within 72 hours of detection.Non-compliance can lead to fines up to 4% of global turnover. The BA case saw an ICO fine (eventually £20m) for lacking basic protections. Organisations should thus view compliance not as a burden but as part of a risk mitigation strategy.
● Crisis Communication and Transparency:| In the aftermath of a breach, how a company communicates is critical. Firms should have a crisis communication plan that includes timely disclosure to regulators, customers, and the public. As we discuss later, being transparent and proactive can help preserve trust.
In sum, the strategic implications of these breaches involve ashift in mindset: cybersecurity must be built into enterprise strategy, with board oversight, adequate funding, and an organisational culture that values and rewards security practices.
DISCUSSION
1. How would using frameworks like NISTand ISO/IEC 27001 reduce breaches?
Frameworks like the NIST CSF and ISO 27001 provide structured, comprehensive approaches to managing cyber risk. For example, NIST’s CSF explicitly requires organisations to identify and inventory their assets, threats, and vulnerabilities. If SFO and BA had applied this rigour, they would have systematically logged their critical systems and patch status, likely catching BA’s outdated JavaScript library before it was exploited. ISO 27001 similarly enforces regular risk assessments and updates to controls. Under ISO 27001, BA would have identified that logging plain-text card data was an unacceptable risk. These frameworks also mandate Protective controls: ISO 27001 Annexe A includes cryptographic controls and access management, while NIST stresses multi-factor authentication as a standard protective measure. Had SFO required MFA for employee logins, stolen passwords alone would not have sufficed to breach systems.
Moreover, NIST’s Detect function encourages continuous monitoring. With a SIEM or intrusion detection system in place, anomalies (like unusual data exfiltration) could have triggered alerts. Both breaches went undiscovered for weeks; adherence to framework guidelines on monitoring would have caught intrusions sooner. Finally, both frameworks emphasise Response and Recovery planning. ISO 27001 demands incident response procedures and lessons-learned reviews, while NIST calls for established communication channels during an incident. These might have led to faster mitigation when the SFO and BAbreaches occurred. In summary, formal adoption of NIST CSF and ISO 27001 would likely have led to better-prepared organisations. They provide a “common language” and lifecycle approach that, if fully implemented, can significantly reduce the chance and impact of breaches.
2. If you were on the board, what policies would you formulate after the breach?
As a board director, immediate policy actions would focus on strengthening governance and incident readiness. First, I would mandate a comprehensive incident response plan. This includes clearly defining which events constitute a reportable incident and establishing reporting chains. We would ensure roles are assigned (e.g. CISO leads response) and conduct regular tabletop exercises. Board members should also require independent cybersecurity audits and risk assessments. This policy would call for periodic (e.g., annual) third-party reviews of security controls against standards like ISO 27001 and penetration tests to uncover vulnerabilities. Second, the board must establish clear security policies around authentication and data encryption. For example, enforce MFA for all sensitive systems (particularly for remote logins) and require encryption of personal data at restand in transit. Relatedly, access control policies would limit user privileges to only what is needed, reducing the “blast radius” if a credential is compromised.
Third, I would implement a vendor security policy. Any third-party provider must demonstrate compliance with security benchmarks (potentially ISO 27001 certified). Contracts would include audit rights and breach notification requirements.
Fourth, budgetary policies: cybersecurity should be treated as an ongoing investment, not an ad-hoc expense. The board would allocate dedicated funding for security tools (SIEM, advanced endpoint protection) and staffing. We would tie a portion of executive compensation to security metrics (e.g., timely patching, incident response drill performance) to ensure leadership ownership.
Finally, a transparency policy: the board would commit to the timely disclosure of breaches to regulators and customers, in line with legal requirements. We would also develop a PR strategy to manage public communication during crises. In summary, board policies would span planning, technical controls, vendor management, budgeting, and communication. Each would be guided by best practices (e.g., NIST and ISO guidelines) to ensure the company is more resilient to future attacks.
3. How would transparency and timely disclosure help in a breach situation?
Transparency is crucial for maintaining trust. Legal frameworks like the EU’s General Data Protection Regulation (GDPR) require companies to report breaches to authorities within 72 hours. By promptly informing regulators and affected individuals, companies. Comply with regulations, avoiding additional fines, and also demonstrate responsibility. For example, BA reported the breach to the ICO on September 6, 2018, meeting the 72- hour notification window. This adherence helped limit regulatory penalties (though BA still received a fine, the process aligned with the rules).
Beyond compliance, public trust is at stake. Customers feelbetrayed if a breach is hidden or covered up. Studies suggest that evasive or delayed responses can severely erode consumer confidence. A clear, honest admission—even if bad news—can mitigate panic. For instance, BA issued formal apologies and offered affected customers compensation, which, while costly, was necessary to show accountability. Forbes notes that losing customer trust can have long-term costs to brand value. By contrast, transparent handling can preserve some goodwill. Quick disclosure also empowers customers to take protective actions (e.g. cancelling cards) and prevents rumour-driven speculation.In short, transparency is part of crisis management best practices: it satisfies legal duties and can reduce reputational harm. Companies should thus develop communication plans that ensure rapid, honest notification of stakeholders,
regulators, and the public when breaches occur.
4. How to balance cybersecurity investment with other priorities?
Balancing security spend against other business needs is essentially a risk management question. Organisations should adopt a risk-based approach, aligning cybersecurity budgets with the value of assets and the level of threat. The NIST CSF endorses this approach, allowing companies to tailor security “appropriately” to their risk environment. This means analysing potential breach costs (fines, remediation, lost sales) versus the cost of preventive controls. Studies show that severe breaches can inflict millions of dollars in losses; for example, industry estimates put the average breach cost in the multi-million-dollar range. In a Forbes Technology Council analysis, experts argue cybersecurity should be viewed as a strategic investment that protects revenue and brand value. Empirical data indicate that many organisations underinvest in security. A 2025 report found only 3% of companies felt their budget fully covered all cybersecurity needs.
Meanwhile, 52% wanted more funding for security personnel and 57% for new technology. This suggests a disconnect between perceived risk and spending. Boards must recognise that underfunding security to save costs often leads to far greater losses when an incident occurs. A practical way to balance is to treat security dollars as insurance: determine a reasonable budget to reduce risks to an acceptable level. For critical systems (like customer data portals), higher security investment is justified. For less critical functions, basic controls may suffice. Regular risk assessments can help reallocate resources as priorities change.
In summary, companies should not view cybersecurity as a burden but as protecting a key business asset. Decisionmakers can use models (e.g., FAIR – Factor Analysis of Information Risk) to estimate expected losses from cyber events and compare them to security program costs. When done transparently, boards can integrate cybersecurity budgets into overall strategic planning. This way, security investment is balanced with other priorities in line with
quantified risk.
5. What is the reputation impact of breaches, and how do organisations manage them?
Breaches can severely damage an organisation’s reputation. Customers expect companies to safeguard their data; when this trust is broken, they may lose confidence in the brand. The BA breach generated widespread media coverage and negative press. Immediately after BA disclosed the attack, its parent company’s share price fell by about 2%, reflecting investor concern. News articles emphasised BA’s apology and the unprecedented nature of the hack, highlighting a blow to the airline’s image. Similarly, the SFO’s incident raised questions about the airport’s security competence among employees and contractors. To manage reputational harm, organisations typically take several steps. First, they publicly acknowledge the incident and apologise, which humanises the response. BA’s CEO issued apologies and offered credit monitoring, signalling care for customers.
Second, they implement remedial measures and communicate them: after the BA hack, the company announced system upgrades and waived some fees to compensate affected passengers. Third, PR campaigns and advertisements may be used to rebuild trust over time. According to Forbes, preventing loss of customer trust is extremely hard— “Rebuilding a brand’s reputation is a complex and expensive endeavour”. Therefore, proactive reputation management is essential.
In practice, companies often set up dedicated web pages or hotlines for breach inquiries, update customers via email or media, and engage with regulators and law enforcement publicly to show compliance. They also monitor social media and the press to counter misinformation. Over the long term, firms invest in highlighting security improvements and may obtain third-party assurances (like security certifications) to reassure stakeholders. Ultimately, managing reputation after a breach requires transparency, empathy, and concrete actions to demonstrate learning and improvement.
6. Are existing cybersecurity measures at SFO and BA adequate given evolving threats?
The SFO and BA breaches suggest that their prior security measures were not adequate for the current threat landscape. In both cases, attackers exploited relatively simple vulnerabilities: unpatched software and single-factor logins. This indicates that routine security hygiene (patch management, MFA, encryption) was lacking. Today’s cyber threats are more sophisticated: attackers use automated tools, AI-driven social engineering, and novel exploit kits. For example, recent reports warn of deepfake phishing and AI-generated malware. The fact that 95% of breaches involve human error shows that social engineering is an ever-present vector, necessitating continual user education and technical controls (like advanced email filtering).
Moreover, supply chain vulnerabilities and state-sponsoredenemies exist as a risk factor in the aviation sector. This implies that the granite sleeping bag of a defender cannot be used. It is essential to assume that breaches will occur in organisations and design architectures to accommodate them (zero trust, segmentation, etc.) Continuous monitoring. Both BA and SFO will have to keep modifying their security posture on a continuous basis. The case in point is a poor library (Modernizr) found in BA, which was considered a known vulnerability since 2012.in use. Such matters would be spotted through frequent threat intelligence and patching programs nowadays. Similarly, SFO needs to 20 consider that their web properties can be the targets and deploy superior. Defences (such as web application firewalls and content policy). Concisely, cybersecurity is a shifting target. Measures that once were considered “good enough” quickly become obsolete. Therefore, SFO and BA must adopt dynamic, forwardlooking security strategies (guided by updated NIST/ISO frameworks) and invest in innovation to stay ahead of attackers. Only by treating cybersecurity as a living process can they hope to defend against the changing face of cybercrime.
CONCLUSION:
The SFO and British Airways incidents underscore that cybersecurity is not purely a technical concern but a fundamental business risk. All the breaches demonstrated the lack of risk management, technology, and governance. A proper course of action calls for a blend of cybersecurity with organisational strategy at the boardroom level, down to the level of a playground. Front lines. The structural risk administration will identify and address problems in the analytical systems (NIST CSF and ISO 27001) reduce such vulnerabilities before they are exploited. Corporate governance principles emphasise that cyber risk, as well as financial and safety, are the priorities of executives. Risks. The main lessons are that it can be well-prepared with the availability of the latest protection firewalls (patching, encryption, MFA), constant observation and the importance of giving time to these activities. And snappy incident response. These are expensive to invest in the short term, but nothing to what a breach can do to the business. The strategic implications of what we have discussed are accountability of boards, investment in security, training, monitoring of the vendors, and compliance, offering an improvement schedule towards resilience. When the discussion addressed 21 questions, it was noted.
The issues of frameworks and transparency are potent tools, minimising the damage of a breach, and re-establishing trust. To sum up, the aviation industry should be prepared to live in a world where cyber threats are ubiquitous.SFO and BA have now realised that security should penetrate every operation. Through their strong cyber preparedness and technique of consciousness, they will be in a better situation to safeguard their customer information and essential information. The cost of complacency is clear from these cases: lost trust, regulatory penalties, and compromised safety. Moving forward, constant vigilance and proactive strategy are the only ways to stay secure in a digitalised aviation industry.
REFERENCES:
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer Security Incident Handling Guide (NIST SP800- 61 Rev. 2). National Institute of Standards and Technology.
CISOMAG. (2020, April 14). San Francisco Airport websites hacked; employee login credentials compromised. Retrieved from CISO MAG websitecisomag.com.
Easterly, J. (2025, January 8). Corporate cyber governance: Owning cyber risk at the board level. Cybersecurity and Infrastructure Security Agency (CISA) blog cisa.gov.
Edwards, M. (2024, December 19). The Ultimate Guide to ISO 27001. ISMS.online.
Forbes Technology Council. (2024, May 15). Return on investment of cybersecurity: Making the business case. Forbescouncils.forbes.comcouncils.forbes.com.
French, L. (2025, March 11). 95% of data breaches involve human error, report reveals. SC Mediascworld.com.
HBR.org. (2015, May). Customer data: Designing for transparencyandtrust.Harva rdBusinessReviewcouncils.forbes.com. (Discussion of trust and transparency in data protection.)
Hickman, T., & Timmons, J. (2020, October 16). UK ICO fines BA £20m for data breach. White & Case LLP whitecase.com.
Mahn, A. (2018, October 23). Identify, Protect, Detect, Respond and Recover: The NIST Cybersecurity Framework. National Institute of Standards and Technology (NIST) blognist.gov.
NIST. (2023). Multi-Factor Authentication. NIST Small Business Cybersecurity Cornerist.gov. (Definitions of MFA and its importance.)
Sandle, P. (2018, September 7). BAapologises after 380,000 customers hit in cyber attack. Reutersreuters.com.
SC Media. (2025, March 11). 95% of data breaches involve humanerror, reportreveals .Cyber Risk Alliancescworld.com.