{"id":1081,"date":"2020-05-10T20:13:09","date_gmt":"2020-05-10T18:13:09","guid":{"rendered":"https:\/\/www.cyberinflight.com\/?p=1081"},"modified":"2020-05-11T14:42:56","modified_gmt":"2020-05-11T12:42:56","slug":"aerospace-cybersecurity-building-resilience-in-the-hailstorm","status":"publish","type":"post","link":"https:\/\/www.cyberinflight.com\/?p=1081","title":{"rendered":"AEROSPACE CYBERSECURITY: BUILDING RESILIENCE IN THE HAILSTORM"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"417\" src=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-1024x417.jpg\" alt=\"\" class=\"wp-image-1095\" srcset=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-1024x417.jpg 1024w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-300x122.jpg 300w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-768x313.jpg 768w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-1536x626.jpg 1536w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/PourLinkedin-2-2048x835.jpg 2048w\" sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/figure>\n\n\n\n<p><strong>1. THE COVID-19 CRISIS: A LAND OF OPPORTUNITIES FOR HACKERS<\/strong><\/p>\n\n\n\n<p>The world economy has been hit by the COVID-19 pandemic, and the air industry is among the industries most severely impacted by this crisis. Airlines and OEMs, in particular, have started to announce cost reduction plans, which are probably not possible without downsizing their workforces, in order to survive until the end of the crisis. On top of the operational difficulties triggered by the crisis, <strong>the<\/strong> <strong>weakening of industrial players is seen by cyberthreat actors as an opportunity to be seized<\/strong>. The cyberattack level has soared in the last two months, and all but a handful of hackers have shown how far they are from following any code of conduct and how unethical their behavior can be, particularly when striking medical institutions and hospitals. Factors such as the economic downturn, mandatory home work for millions of employees, and difficulties setting up strong cybersecurity rules in a short timeframe make it the right moment for hackers to weaken companies that already have a knee on the ground.<\/p>\n\n\n\n<p><strong>2. CYBER-RESILIENCE CANNOT BE BUILT IN A DAY<\/strong><\/p>\n\n\n\n<p>By hitting airline revenues directly, this crisis may mechanically impact their level of defense. The airline industry\u2019s level of IT investment in the last 5 years has shown a remarkable compound annual growth rate (CAGR) of 10.4%, from $21.5 bn in 2014 to $35.2 bn in 2019. The airline cybersecurity budget represents a decent portion of this IT budget. It has been estimated that <strong>the cybersecurity budget of airlines followed an outstanding CAGR of at least 50% in the last 5 years<\/strong> from $0.5 bn in 2014 to $3.8 bn in 2019 (2019 figure is an estimate by CyberInflight. 2018 figure, provided by SITA, is at $2.75 bn).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph1-2.png\" alt=\"\" class=\"wp-image-1087\" width=\"596\" height=\"423\" srcset=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph1-2.png 849w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph1-2-300x213.png 300w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph1-2-768x545.png 768w\" sizes=\"(max-width: 596px) 100vw, 596px\" \/><\/figure><\/div>\n\n\n\n<p>Does the level of investment in cybersecurity actually reflect the airline industry\u2019s levels of maturity and resilience? It is certainly a good indicator. In 2019, <strong>the cybersecurity\/IT budget ratio was estimated at 11%,<\/strong> when national security agencies usually advise a ratio between 5% and 15% depending on the industry. At first sight, this 11% could be seen as fair for the airline industry. In comparison, the cybersecurity investment level in the airport industry is estimated around $1.5 bn in 2019, which represents a 14% cybersecurity\/IT ratio. This difference could be explained by the fact that airports have been targeted by cyberattacks more frequently due to easier physical access to their facilities. Airports have had to answer this level of exposure by increasing their levels of cybersecurity maturity. The airline industry would probably need to reach a similar cybersecurity\/IT ratio to be on the safe side. In addition, an important point to mention regarding cybersecurity investments is that <strong>it takes time to raise a company\u2019s level of maturity,<\/strong> and probably several months at least to see the outcome of a cybersecurity investment. The cyber\/IT ratio grew from 4.6% in 2016 to 7% in 2017 and 9% in 2018. It may take time for these increasing investments to be totally effective and for cyber-resilience \u2014which is mainly linked to the culture and maturity of a company\u2014 to be achieved. Ultimately, it is important to keep in mind that a company\u2019s level of cyber-resilience not only depends on the level of investment, but also on how well these investments have been made.<\/p>\n\n\n\n<p><strong>3. THE REGULATORY FRAMEWORK: ON THE CUSP OF A MORE PROFUND CHANGE<\/strong><\/p>\n\n\n\n<p>Simply by measuring maturity based on the cyber\/IT ratio, it is difficult to foresee whether this maturity level could increase in the coming months and years, as current priority is oriented toward the survival of the industry and its companies. Nevertheless, it seems that cybersecurity will remain high in company\u2019s agendas, as forcing people into quarantine has revealed that strict cyber-hygiene rules must be timely and properly deployed. <strong>Basic cybersecurity practices appear to be the foundation of the sustainability of any organization<\/strong>. As an unexpected benefit, the COVID crisis will probably help to raise the entire industry\u2019s cybersecurity awareness.<\/p>\n\n\n\n<p>Among the strongest drivers of the adoption of cybersecurity, the influence of international regulatory bodies is considered key. The <strong>year 2019 was marked by a set of initiatives launched by international regulators regarding cybersecurity<\/strong>. Among the most significant ones, one can mention:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The publication of Aviation Cybersecurity Strategy by ICAO (October 2019)<\/li><li>The adoption of Assembly Resolution A40-10 addressing cybersecurity in civil aviation by ICAO (Oct. 2019)<\/li><li>The creation of the Aviation Cyber Security position paper by IATA, outlining IATA\u2019s cybersecurity vision and mission (Jun. 2019)<\/li><li>The establishment of the Security Advisory Council (SAC) by IATA (Jun. 2019)<\/li><li>The first Aviation Cyber Security Roundtables (ACSR) held by IATA (Apr. 2019)<\/li><li>The rulemaking task from EASA, called RMT.0648, created in May 2016 with a Notice of Proposed Amendment (NPA2019.01) process performed between Q1 and Q3 2019<\/li><li>Several interesting initiatives launched by ACI in 2019.<\/li><\/ul>\n\n\n\n<p>A stronger and clearer cybersecurity framework is under construction and set to be introduced beginning in 2021, particularly in Europe. Hopefully, the crisis won\u2019t delay the decision-making process of regulatory bodies, as the <strong>2019 initiatives show a compelling momentum for air cybersecurity regulations<\/strong>. The current crisis\u2019 slowdown of air traffic and restructuring of priorities could also be seen as the right moment to pave the way for a solid regulatory framework.<\/p>\n\n\n\n<p><strong>4. IN-FLIGHT CYBERSECURITY: BREAKING THE GLASS CEILING<\/strong><\/p>\n\n\n\n<p>In its \u201cAerospace Cybersecurity Market Intelligence\u201d report, CyberInflight identified in-flight cybersecurity (IFCS) among one of the next trends. Despite the downturn, the evolution of the mindset regarding cybersecurity and the development of the regulatory framework could be seen as solid driving forces to encourage the deployment of IFCS components once the crisis softens. The crisis could help <strong>break the existing glass ceiling that has prevented many cybersecurity solutions suppliers to penetrate this market<\/strong> and to embed their products in aircraft.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph2-2.png\" alt=\"\" class=\"wp-image-1097\" width=\"485\" height=\"345\" srcset=\"https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph2-2.png 703w, https:\/\/www.cyberinflight.com\/wp-content\/uploads\/2020\/05\/Article_graph2-2-300x214.png 300w\" sizes=\"(max-width: 485px) 100vw, 485px\" \/><\/figure><\/div>\n\n\n\n<p>To date, the cybersecurity of in-flight systems communications (IFE and IFC systems in particular) is mainly implemented within legacy equipment. With the development of cyberthreats, airlines could consider the <strong>introduction of independent dedicated cybersecurity components<\/strong> from third parties to monitor, detect and react to cyberthreats. The take rate of in-flight cybersecurity is definitely set for significant growth, as it is considered to be fairly low today. The adoption of dedicated embedded cybersecurity components (hardware and\/or software) is already happening in business and military aviation and other vertical-mobility markets such as maritime and rail.<\/p>\n\n\n\n<p>While IFCS may represent a small fraction of airlines\u2019 cybersecurity expenses compared to items such as employee awareness and training, regulatory compliance or the setup of SOC infrastructures, it is expected to show the greatest growth rate in the coming years.<\/p>\n\n\n\n<p>Find the complete details in our report. CyberInflight\u2019s market research report features key findings regarding the aerospace cybersecurity market. Table of contents and excerpt available here: <strong><em>link<\/em><\/strong>. For more information, please contact us at <strong>contact@cyberinflight.com<\/strong>.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. THE COVID-19 CRISIS: A LAND OF OPPORTUNITIES FOR HACKERS The world economy has been hit by the COVID-19 pandemic, and the air industry is among the industries most severely impacted by this crisis. Airlines and OEMs, in particular, have started to announce cost reduction plans, which are probably not possible without downsizing their workforces, &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.cyberinflight.com\/?p=1081\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;AEROSPACE CYBERSECURITY: BUILDING RESILIENCE IN THE HAILSTORM&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1081","post","type-post","status-publish","format-standard","hentry","category-non-classe"],"_links":{"self":[{"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/posts\/1081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1081"}],"version-history":[{"count":7,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/posts\/1081\/revisions"}],"predecessor-version":[{"id":1098,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=\/wp\/v2\/posts\/1081\/revisions\/1098"}],"wp:attachment":[{"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyberinflight.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}