Sector Overview

Airport and aviation operational technology environments are among the most operationally complex in critical infrastructure — combining safety-critical legacy systems dating to the 1970s with modern, IP-connected ground operations infrastructure and passenger systems that share physical proximity, and increasingly, network adjacency.

An international airport’s OT estate spans at least six distinct domains:

  • Air Traffic Management (ATM): Primary and secondary surveillance radar (PSR/SSR), mode-S transponder systems, VHF radio communication, ACAS/TCAS collision avoidance, ILS (Instrument Landing Systems), VOR/DME navigation aids, ATIS automatic terminal information
  • Airfield Ground Lighting (AGL): Runway and taxiway lighting control systems, approach lighting, PAPI approach slope indicators — all controlled via SCADA with safety certification requirements
  • Baggage Handling Systems (BHS): Conveyor control PLCs, automatic sorting systems, explosive detection system (EDS) integration, baggage reconciliation systems
  • Gate and Jetway Systems: Passenger boarding bridge (PBB) controllers, fixed electrical ground power (FEGP), pre-conditioned air (PCA) systems
  • Fuel and Ground Support: Aircraft refuelling management systems, ground support equipment tracking, de-icing fluid management
  • Building Management and Security: Access control integration with airside/landside boundaries, CCTV, perimeter detection, HVAC for terminal buildings

The critical characteristic of this environment for security practitioners: these systems were designed and certified in isolation from each other and from IT networks, but operational efficiency pressures have progressively driven connectivity — particularly for data analytics, performance monitoring, and fleet management — in ways that were not anticipated in the original security design.

The Attack Surface

Air Traffic Management Systems

Modern ATM is moving away from purely analogue systems toward digitised infrastructure. EUROCONTROL’s SWIM (System Wide Information Management) programme, the FAA’s NextGen architecture, and equivalent modernisation programmes in Asia-Pacific all introduce IP connectivity into environments where prior network isolation was the primary security control.

Primary radar systems remain predominantly proprietary protocol, but the data distribution layer — systems that take radar returns and distribute them to controller workstations — increasingly uses commercial networking equipment and standard protocols. The Controller Working Position (CWP) displays that show controllers live radar plots are in some implementations running on commercial hardware with commercial operating systems.

The ATC radio infrastructure is a documented targeting area. VHF communication systems in several European airports have historically used unencrypted digital voice (ACARS, DCDU ground-ground links) that is accessible to anyone with appropriate receiving equipment. While active interference requires proximity and specific capability, the eavesdropping surface is significant.

Documented incidents include GPS spoofing events affecting multiple civil aviation environments — most associated with conflict-adjacent zones but demonstrating the vulnerability of navigation infrastructure to radio frequency interference from distance.

Baggage Handling Systems

BHS control systems are among the most accessible OT environments in airports from an IT security perspective. The business pressure to integrate BHS with airline departure control systems (DCS), airport operations centres (AOC), and baggage reconciliation databases has created network connections that run between the airport IT network and BHS PLC environments.

The PLC controllers managing conveyor belts, diverters, and sorting mechanisms are typically Siemens, Rockwell Allen-Bradley, or Schneider products — the same platforms targeted in documented ICS attacks against other sectors. They typically run without authentication on the physical network layer, relying on network segmentation as the sole access control.

A BHS attack sufficient to disable baggage sorting at a major hub airport would cause significant operational disruption — diversions, delays, aircraft on-ground situations — with cascading effects across connected airline hub networks. This is a plausible ransomware target: operational disruption sufficient to pressure payment decisions without requiring a safety-critical impact.

Ground Support Equipment and Fuel Systems

Aircraft refuelling systems at major airports are managed via automated fuel management systems (FMS) connected to airport operations databases. These systems manage fuel truck dispatch, fuel volume tracking, and invoice generation — and they connect via airport networks that, in many cases, share infrastructure with passenger WiFi, retail concession systems, and airline check-in networks.

The ground support equipment (GSE) domain is increasingly connected for fleet management and maintenance scheduling. Electric GSE charging infrastructure, in particular, uses OCPP (Open Charge Point Protocol) — the same protocol used in public EV charging networks — with security characteristics consistent with that space: limited authentication, minimal encryption in older implementations.

Threat Actor Targeting

Aviation infrastructure has been explicitly named in advisories concerning nation-state targeting:

Volt Typhoon pre-positioning activity in US critical infrastructure, documented by CISA and NSA in multiple 2024-2026 advisories, includes aviation sector targets. The group’s focus on living-off-the-land techniques and long dwell times within network infrastructure is consistent with reconnaissance of ATM and airport network topology rather than disruptive attack.

IRGC-affiliated actors including CyberAv3ngers have demonstrated the capability and intent to target critical infrastructure OT systems. While documented incidents have focused on water/wastewater and energy sectors, the same tool families (IOCONTROL, Havoc-based payloads) are applicable to airport OT where internet-exposed systems exist.

Hacktivist-adjacent ransomware groups — motivated by geopolitical rather than purely financial goals — have targeted transport infrastructure in Europe in several documented incidents, including attacks on national rail operators and port logistics systems. Airport ground operations represent a natural escalation of this pattern.

Regulatory Framework

United States: TSA’s Aviation Cybersecurity Initiatives (ACI) and subsequent directives require airport operators and aircraft operators to report cybersecurity incidents, maintain cybersecurity incident response plans, and implement access controls. The January 2024 directive extended cybersecurity requirements to airport operators previously focused only on air carriers. The specific technical requirements follow the NIST Cybersecurity Framework with aviation-specific guidance from CISA’s Cross-Sector Cybersecurity Performance Goals.

European Union: ENISA’s guidance for the aviation sector, EUROCONTROL’s ECSC (EUROCONTROL Cybersecurity Strategy for Civil Aviation), and NIS2 Directive requirements for critical infrastructure all apply. NIS2’s sector classification places air traffic management as essential entities, requiring incident reporting within 24 hours of awareness.

International: ICAO’s Aviation Cybersecurity Strategy and ICAO Doc 10226 provide the international framework, though implementation varies significantly by jurisdiction.

Practitioner Guidance

Segmentation audit: Map all data flows between BHS, ATM data distribution, gate systems, and airport IT networks. OT security assessments in aviation consistently find undocumented connections between these domains — connections created for operational reasons without security review.

Protocol monitoring: Deploy passive network monitoring in BHS PLC environments using industrial protocol inspection. Look for unexpected PROFINET, EtherNet/IP, or Modbus traffic traversing segment boundaries, or standard protocols appearing in OT subnets.

Vendor access controls: Airport OT environments have extremely high vendor access density — ATM system maintenance, BHS maintenance, gate system servicing — all typically managed via dedicated remote access channels. Audit these channels for multi-factor authentication, session recording, and privileged access management integration.

Radio frequency monitoring: Implement RF monitoring for GPS jamming/spoofing events in the vicinity of ILS and navigation aids. Aviation-specific RF monitoring platforms are available from several specialist vendors and are increasingly included in airport security technology procurement.

Incident response planning: Develop OT-specific incident response playbooks for BHS failure, airfield lighting control loss, and ATC data distribution disruption scenarios. Coordinate with the appropriate national CSIRT (CISA in the US, NCSC in the UK) on aviation-specific incident reporting requirements before an incident occurs.

Aviation OT security is a sector where the gap between regulatory requirement and operational implementation remains wide. The combination of safety-critical systems, high connectivity pressure, and a threat actor set with demonstrated interest makes this a priority area for OT practitioners with airport clients or operator responsibilities.

Tags
aviationairportair traffic managementATCbaggage handlingOT securityICAOTSAACASILSVHFSWIMEUROCONTROL