Navigating Aviation Cybersecurity: NCC Group Experts on Talent Shortages and Industry Risks
Transcript
Hey guys, thanks for the throw. We're here with Lawrence Baker and Jeff Hall, who are both aerospace security experts with NCC group and we're talking about how aerospace security is evolving. 'cause well, it's like every other industry a moving target.
Gentlemen, welcome to Shah. Thank you. Thank you for having us, Michael.
Alright, Lawrence, what's the current state of aerospace cybersecurity? Because I don't think we hear about a lot of attacks, but for all I know, maybe they're getting inundated with attacks and they're just getting better at swatting them away. But, um, how much danger are we in and what is the current level of activity?
So aviation is a very complicated ecosystem of a number of different state holders. But an important thing to remember here is that we're dealing with a critical national infrastructure. We're dealing with some fee that is safety critical as well.
So clearly there are risks that need to be appropriately managed to ensure that citizens aren't armed. And there are, there's wide recognition of that and robust measures already in place. But as we know, cybersecurity threat and the landscape is constantly evolving and technologies are changing as well.
So the regulations that are in place need to adapt with time to deal with those emerging threats. In terms of the number of attacks we're seeing that there has been several, um, high profile, uh, attacks in the aviation sector, mostly targeted against airlines who tend to be the highest profile, uh, target. And it doesn't take me much time on Google to just quick search of that.
And you can identify, uh, quite a large number of aviation organizations that have been victims that obviously, you know, one attack's not the same as another attack. And there's is made different kinds of motivations for attackers to want to attack a particular type of organization. So yes, certainly there are lots of ransomware type attacks and uh, lots of, um, data breaches as well.
But as I said, many stakeholders maybe as a motivations and different types of harms that fifth threat actors want to, to cause. So maybe the ones that don't get reported are the ones that potentially more interesting. True that Jeff, it seems like there's more regulation coming down the pike, but what's going on here in the aerospace sector and how quickly will these things come about?
Because last time I checked it takes, I don't know, three to five years just to design and build an airplane. This is true. Um, and every time you do have a new administration change, there's always gonna be new cybersecurity regulations or policy that's gonna come down.
So that takes a while to promulgate and get out. But, uh, what I see is the three, or, well, not the three, but bigger, bigger trends are, uh, safety and security, which you basically have two sides of the coin where I, I think, I don't think I know, I've done a bunch of work on this and have a dissertation on safety and security in, in aerospace. So you can't have safety if you don't have security.
And another, uh, area is emerging technologies, you know, AI is coming down the pike. Everybody wants to jump on the AI bandwagon, but they need to really understand what comes with the AI security implications and how it could over affect or affect the overall system. 'cause aircraft and any aerospace system is just to collect, you know, systems of systems which make up the bigger product.
And uh, you have to look at it as a whole, Owen, how many of these attacks are kind of aimed at the retail side of the airline industry and they are being attacked just like anybody else who does any kind of e-commerce activity versus how many of these attacks are aimed at the systems on the plane itself, which is a much bigger safety concern. So I guess right, right now we see a lot, a lot of ransomware, um, things on the business side where they're just trying to disrupt your operation. Whereas direct attacks on aircraft, you'll never hear about them because if it happens, you know, governments get involved and they don't really do not want to, uh, get the information out until they really know what has happened and how, how we can, uh, mitigate the impacts.
Lauren's coming back to you. Um, what's your best advice, therefore to all the folks who work in this vertical industry about how to approach cybersecurity? And it would seem to me at least that, at least in that culture, the engineers are a lot more attuned to that notion and issue.
But are they, and what, or is there like a, a engulf that exists between the security folks and the rest of the business as there is in every other sector? So the, I think there is, there historically has been some challenges for people responsible for security and aviation organizations to get the resources and that the level of buy from if, from leadership within these businesses to, to manage these risks appropriately and government. So responding to that with a whole plethora of regulations, I think it's important that people aren't fixated on compliance.
If there's a real risk here that some budgets may be frozen and some of the resources devote, uh, um, devoted instead to compliance, uh, reduces the amount of budget available for cybersecurity operations. So really the first key step is for security managers affect or the regulations to leverage those regulations to their advantage to make the business case for why there needs to be additional resources made available for them to manage the risk. So they increase the, the resource available for protecting the operation.
But you know, fundamentally the, the principles that security managers need to follow are well established regulators don't try to reinvent well, they use industry best practice. What security managers need to be mindful of are, are really do things. First of all, yes, you might use a standard framework for compliance, but you also need to demonstrate that compliance.
So you don't want that to become a big bird. So what can you do to automate that when you go about doing a security program, making sure that you are not having to divert those valuable funds to towards compliance to demonstrate to your regulator you are compliant. The other key thing I I would focus on is, is you know what you know, right?
So, you know, don't be scared. Some of the regulation is complicated. There are specific requirements of and reporting and what and whatnot, but fundamentally the principles are the same.
Security, um, controls you need are broadly the same. So you can lean into that. But the other flip side of, you know, what you know is, you know, be mindful of your limitations.
So yes, you are dealing with operational technology, safety, critical technology. So you need to make sure you involve the right stakeholders and do it apply security controls in that right context for the aviation domain. So this would establish regulations, communities for aviation security and that there they deal with, you know, terrorism sabotage, criminal organizations and what do they have in place, what management systems do they have, how do you interact with them?
'cause attackers don't care about whether it's the cyber domain or the physical domain or hot between the two as they need to, to achieve, to achieve their objective. So you don't wanna have an organ organizational silo, which means that actually the IT security team can't work with the aviation security team. So knocking down those barriers, ensuring that there's a complete depreciation of the full spectrum of attacks that can occur out there.
And the same thing for aviation safety, cybersecurity types can now fix safety. Yes. Um, you need to do details effect modeling and risk assessments of that and work in collaboration with the, the aviation safety teams to make sure that those risks are appropriately managed.
Yeah. Jeff, in your experience, are there specific types of attacks that the aviation industry is more worried about than others? Or are they all pretty much the same for everybody else?
Or are there unique attributes here that really, you know, challenge these folks? I think the ones that kind of probably make them stay up at night or really consider hard are things that would definitely affect safety of flight and their aircraft. But a lot of ground systems out there are very susceptible things were never designed with security in mind.
And when they look, I'd say they, when airlines or organizations look, look at their whole safety posture, a lot of times things that aren't on the aircraft don't get a lot of, uh, scrutiny. Um, other than things that make them money, you know, PCI compliance, um, just overall ticketing, you know, the whole business side of it. But, um, you go to the aircraft side, it's, there's so many different things you can come and, and either, and it doesn't have to be a catastrophic event, it could be something that just keeps them from leaving the ground and the problem will just compound over time depending on how many aircraft there are.
And then that gets into a whole money figure. So it starts costing the airline a lot, a lot of money on either side, whether it's the, you know, business administrative side or the aircraft side. Lawrence, I am not an engineer and I do not pretend to be one, but it seems to me if I look at a plane, there must be thousands of subsystems on each of those planes, then each of them needs to be protected.
So is that part of the challenge here to jumps point is just that there's, the attack surface is so broad, even though it's actually on a physical plane. The, the attack surface is broad. And I guess there are new attack vectors being introduced as technology moves on and we get I guess increased demand and increased ways of providing connectivity to the aircraft.
Like, you know, many other enterprises, airlines and the manufacturers of aircraft wanna get data back from the aircraft and that means there's a trade off there between security, um, and getting that, that data back from the aircraft. But, you know, the, the, this associated with aviation and aircraft in particular are widely recognized and, uh, various regulation, uh, standards, specification, uh, requirements which are needed for certification of aircraft that, um, kind of reflect the risks to the aircraft. And that is, I would say, well in hand and well recognized.
What is often less appreciated is that wider infrastructure. So, you know, not only is it safety effects, but it's resiliency effects. So we're worried about, you know, this is critical of national infrastructure.
There are threat actors out there who want to disrupt, um, the way that certain societies work. And one of the ways of doing that is by disrupting air travel. And you know, some of these systems are old and fragile and and readily exposed to the internet and they were designed many, many years ago.
So the real challenge actually is how do you not, uh, disrupt standard commercial operations but ensure adequate security, adequate resiliency of commercial, uh, aviation for systems that also, uh, run operated by, by stakeholders who quite frankly are operating on very thin margins. So they don't have the luxury of spending lots and lots of money of putting, you know, expensive technologies to secure them. You know, what, what is enough?
Uh, that that's always the challenge. What is an appropriate standard for that context? Mm-hmm Jeff, we've been dealing with a cybersecurity skill shortage in general for a long time now.
And it seems to me the number of people who know how to secure embedded systems is even smaller and the number of people who know how to secure embedded systems within an airplane is probably a really tiny number. So, uh, where do we get the expertise from to kind of address these issues? Because it is pretty clear that there's just not enough of in available given the number of airlines.
That's a really good point. Um, I've dealt with this, I worked in the government for 10 years prior to coming to NCC group and it got to the point there where colleges were just starting then to shift their curriculum to include cybersecurity for all engineering disciplines, just so they could be aware of it, not they're gonna be experts in it, they'd be aware of it. And everybody kept coming to me because I ran, I ran a branch for cybersecurity and avionics and I said, what are we gonna do?
And I said, I think we should just grow young engineers that are interested or any, any people that are new into the business that are having interest and show a little bit of aptitude, we can train them and get them to where we need to be. And uh, be a whole lot, whole lot easier in trying to go recruit because you can recruit forever and ever and you may not get really what you're looking for. Alright, Lawrence, you cannot walk down the street today without somebody reaching out and saying, here, check out my great new AI thing.
Can we apply AI to any of this to kinda help level the playing field? So I mean, it's a double-edged sword, isn't it? So certainly on the defensive side, as with any other sector, AI has its part to play, particularly on the monitoring side.
I think what's more interesting from the an aviation perspective is the desire for increased levels of automation and how AI can play its part in that. So obviously there are concerns around security of ai, so it's about ensuring design, uh, secure by design. So how do you ensure that uh, AI based systems that are used for autonomous operations, particularly safety critical mission critical systems, are adequately secure?
How do you get that assurance? Um, so one area that I'm particularly interested is how do you move towards, uh, a high assurance approach for these systems and how can you use AI to do that? So for example, we we specialize as a business in producing assurance cases is how can you automate that?
And AI, I'm sure has a, a big role to play in that. So we can rapidly turn around, generate robust, uh, security cases, safety cases, um, using AI technology. Alright, Jeff, I'm gonna throw the last question to you, but do you think AI benefits the attackers more, the defenders more since that's an ongoing debate out there?
Hmm, that's a tricky question. Right, right now I, I believe it's, uh, in the defender's court, but as with anything with attackers, they find very novel ways to circumvent and come at you from angles that are very rarely ever considered. 'cause there's avionics, there's so many different pathways, you can only think of so many.
I think that's where AI might, may really shine where they come in and start looking at a system by system and say, okay, how many different pathways can you find that are viable to get into a system? Then you look at this larger system of systems and I'm sure it's exponentially, you know more, but it's uh, start with small and work big. All right.
Well folks, you heard it here. We have talked in the past about software defined vehicles and when you think about it, an airplane is just another type of a software defined platform that we need to secure. The good news is they are secure and there's a highly committed bunch of people that are gonna make sure that it's safe to fly.
The trouble is, there's just not enough of them right now. Gentlemen, welcome. Thank you for being on the show.
Thank you. All right. And back to you guys in the studio.