Skip to main content
Software Engineering Daily

Aviation Cybersecurity with Serge Christiaans

49 min episode · 2 min read
·

Episode

49 min

Read time

2 min

AI-Generated Summary

Key Takeaways

  • Pilot Cyber Training Gap: Only 20% of pilots globally receive actual simulator training for cyber attacks; the remaining 80% receive only memos, leaving them unprepared to identify GPS spoofing versus jamming or respond to contradictory instrument data during flight operations.
  • Aircraft Engine Vulnerability: Modern aircraft engines continuously transmit telemetry data to manufacturers, creating a potential attack vector where nation-state actors could theoretically send commands to disable engines mid-flight, transforming aircraft into gliders with catastrophic consequences for passenger safety.
  • Just Culture Implementation: Aviation's just culture encourages incident reporting without punishment, enabling organizational learning. Cybersecurity teams should adopt this approach since blame culture prevents employees from reporting phishing clicks, allowing network compromise within seventeen minutes instead of immediate mitigation.
  • Legacy Protocol Risks: ARINC 429 communication bus, designed in the 1970s before cybersecurity existed, remains vulnerable to message injection and spoofing attacks. Newer protocols like ARINC 664 support encryption but only exist on recently manufactured aircraft, leaving decades of vulnerable systems operational.

What It Covers

Serge Christiaans, former Dutch Air Force pilot and CISO, explains how modern aircraft function as flying server rooms with hundreds of computers vulnerable to GPS spoofing, engine hacking, and nation-state cyber warfare targeting critical aviation infrastructure.

Key Questions Answered

  • Pilot Cyber Training Gap: Only 20% of pilots globally receive actual simulator training for cyber attacks; the remaining 80% receive only memos, leaving them unprepared to identify GPS spoofing versus jamming or respond to contradictory instrument data during flight operations.
  • Aircraft Engine Vulnerability: Modern aircraft engines continuously transmit telemetry data to manufacturers, creating a potential attack vector where nation-state actors could theoretically send commands to disable engines mid-flight, transforming aircraft into gliders with catastrophic consequences for passenger safety.
  • Just Culture Implementation: Aviation's just culture encourages incident reporting without punishment, enabling organizational learning. Cybersecurity teams should adopt this approach since blame culture prevents employees from reporting phishing clicks, allowing network compromise within seventeen minutes instead of immediate mitigation.
  • Legacy Protocol Risks: ARINC 429 communication bus, designed in the 1970s before cybersecurity existed, remains vulnerable to message injection and spoofing attacks. Newer protocols like ARINC 664 support encryption but only exist on recently manufactured aircraft, leaving decades of vulnerable systems operational.

Notable Moment

Christiaans reveals that aviation manufacturers refuse to disclose which aircraft models contain secure communication protocols, making penetration testing impossible since tests require engines running mid-flight, creating an effective air gap that prevents security validation of critical flight systems.

Know someone who'd find this useful?

You just read a 3-minute summary of a 46-minute episode.

Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from Software Engineering Daily

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

You're clearly into Software Engineering Daily.

Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for up to 3 shows.

Start My Monday Digest

No credit card · Unsubscribe anytime