Navigating the Turbulent Skies of Aviation Cyber Regulation
M. Weigand, S. Wagner
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
This talk, "Flying Blind," delivered by Michael Weigand and Stewart Wagner at DEF CON 32, delves into the critical and often overlooked realm of cybersecurity within both civil and military aviation. The speakers, drawing from their extensive experience in the Air Force, civil aviation entrepreneurship, and Capitol Hill policy, expose a concerning gap: the widespread absence of fundamental cyber defenses in commercial aircraft. They highlight that despite increasing interconnectedness and software dependence, commercial jets operate without basic protections like antivirus or intrusion detection systems, and pilots lack any alerts for malicious activity.

Key moments
- 0:00 Talk Introduction: 'Flying Blind' on Aviation Policy & Cyber
- 0:24 Speakers' Backgrounds: Military Cyber & Digital Transformation
- 1:36 Talk Agenda Overview: Civil Aviation, Weapon Systems, Regulations
- 3:00 Alarming State: No Cyber Defenses in Commercial Aircraft
- 4:00 Fundamental Vulnerability: Physical Access to Aircraft Avionics
- 6:15 Stewart's Air Force Hackathons Against Fighter Jets Begin
Navigating the Turbulent Skies of Aviation Cyber Regulation
Speakers: M. Weigand; S. Wagner
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=bLgQNSQANx0
Overview
This talk, "Flying Blind," delivered by Michael Weigand and Stewart Wagner at DEF CON 32, delves into the critical and often overlooked realm of cybersecurity within both civil and military aviation. The speakers, drawing from their extensive experience in the Air Force, civil aviation entrepreneurship, and Capitol Hill policy, expose a concerning gap: the widespread absence of fundamental cyber defenses in commercial aircraft. They highlight that despite increasing interconnectedness and software dependence, commercial jets operate without basic protections like antivirus or intrusion detection systems, and pilots lack any alerts for malicious activity.
The presentation argues for a paradigm shift, moving from a reactive, fatality-driven approach to safety to a proactive, data-informed strategy for cybersecurity. A significant development discussed is the recent FAA Reauthorization Act, which for the first time mandates cybersecurity and continuous monitoring for new aircraft designs. However, the speakers emphasize that policy changes alone are insufficient, advocating for a deeper integration of telemetry and data-driven insights—lessons gleaned from the defense sector’s "digital transformation" efforts, including hackathons against fighter jets.
This talk is crucial for anyone concerned with national security, critical infrastructure protection, and the future of air travel. It underscores the urgent need for the aviation industry to adopt modern cybersecurity practices, leverage operational data more effectively, and foster collaboration between operators, manufacturers, and regulators to secure the skies before a catastrophic cyber event forces a reactive response.
Background
▶ Watch: Talk Introduction: 'Flying Blind' on Aviation Policy & Cyber (0:00)
The current state of cybersecurity in civil aviation presents a stark contrast to other critical infrastructure sectors and even modern consumer technology. Michael Weigand highlighted that commercial aircraft are increasingly fly-by-wire, meaning they are highly dependent on computers and software for flight control and operations. Despite this, a startling reality persists: no commercial aircraft currently flies with a running antivirus, intrusion detection (IDS), or intrusion prevention system (IPS). Furthermore, pilots lack any form of crew indication, warning, caution, or advisory light to signal malicious messages on the data bus or compromised firmware/software. This absence leaves crews "flying blind" to potential cyber threats that could impact flight safety.
The industry's reliance on "solid flight worthy technology" often translates to the use of older systems, which inherently lack modern security features. Unlike mobile devices where software delivery is typically cryptographically signed and robust supply chain processes are in place, much of commercial aviation's software ecosystem lacks these foundational security controls. A fundamental principle of cybersecurity—that physical access to a computer allows for compromise—is particularly concerning in aviation. Commercial jets travel globally, and a variety of personnel, from maintenance crews to ground staff, have physical access to avionics, creating numerous potential points of compromise.
Historically, significant advancements in aviation safety policy have often been driven by tragic events and fatalities. The speakers expressed a mission to flip this paradigm, advocating for proactive cybersecurity measures rather than waiting for a catastrophic cyber incident. In this context, the recent FAA Reauthorization Act, passed every four years, marks a pivotal moment. A subsection, specifically "section 360 something," now addresses cybersecurity. Crucially, Congress has directed the FAA to change the type certification process, making cybersecurity and continuous monitoring of avionics a mandatory requirement for any new aircraft design seeking approval. Previously, this was merely a suggestion. The act also calls for studies to assess the adequacy of personnel, funding, structures, and committees to ensure diverse voices from industry, OEMs, airlines, unions, and technologists are heard in the implementation of these new rules.
Stewart Wagner provided a contrasting perspective from his experience as the Air Force's Chief Digital Transformation Officer. His role focused on "learning from data off of operational systems," specifically telemetry data from weapon systems like fighter jets, munitions, ships, and submarines. This military context, where data is proactively collected and analyzed for system health, reliability, and even cyber resilience, serves as a powerful model for what civil aviation could achieve. Stewart's work involved leading a series of hackathons against fighter jets, not solely for cyber exploitation, but to demonstrate the immense potential of operational data for capability development and system improvement. This stark difference in data utilization and proactive security engagement between the defense and civil aviation sectors forms the core of the talk's argument for urgent change.
Key Findings
▶ Watch: Talk Agenda Overview: Civil Aviation, Weapon Systems, Regulations (1:36)
The talk unveiled several critical findings regarding the state of aviation cybersecurity and the path forward:
- Profound Lack of Basic Cyber Defenses in Civil Aviation: The most alarming finding is that commercial aircraft, despite their increasing digital complexity, operate without fundamental cybersecurity tools like antivirus, intrusion detection systems (IDS), or intrusion prevention systems (IPS). Furthermore, flight crews lack any onboard alerts to indicate malicious activity on data buses or compromised software/firmware, leaving them vulnerable and uninformed.
- Data Collection Deficit and Silos: Civil aviation significantly lags behind other advanced industries, particularly big tech, in the automatic collection and utilization of operational data, or telemetry. Many aerospace companies mistakenly believe they collect sufficient data. The speakers argue that there is a critical need for significantly better instrumentation of fly-by-wire assets to gather data essential for safety, reliability, and security. Moreover, significant data silos exist between operators, Original Equipment Manufacturers (OEMs), and regulatory bodies, preventing a holistic understanding of system health and security posture.
- Pivotal Policy Shift with FAA Reauthorization: The latest FAA Reauthorization Act introduces a groundbreaking mandate: cybersecurity and continuous monitoring of avionics are now a mandatory requirement for new aircraft type certification. This moves aviation policy from a suggestive approach to a regulatory imperative, marking a crucial step towards proactive security.
- Lessons from Defense on Data-Driven Resilience: The Air Force's "digital transformation" efforts, spearheaded by Stewart Wagner, demonstrate the immense potential of leveraging operational data. Through hackathons against fighter jets, the defense sector has shown how collecting and analyzing telemetry data can enhance capability development, improve system resilience against threats like electronic warfare (as seen with Starlink's jamming mitigation), and drive predictive maintenance.
- Physical Access as a Primary Vector: The talk re-emphasizes a fundamental cybersecurity truth: if you have physical access to a system, you can compromise it. In the context of global commercial aviation, where numerous individuals have physical access to aircraft and their avionics across various airports and maintenance facilities, this presents a significant and often underestimated vulnerability.
- Shift from Reactive to Proactive Safety: The speakers advocate for moving away from a historical pattern where major safety improvements are typically catalyzed by fatalities. The new FAA mandate and the push for data-driven insights represent an opportunity to proactively address cyber risks before they lead to catastrophic outcomes.
Technical Deep Dive
▶ Watch: Alarming State: No Cyber Defenses in Commercial Aircraft (3:00)
The core technical argument of the talk revolves around the concept of digital transformation through the pervasive collection and analysis of telemetry data from operational systems. Stewart Wagner, drawing from his experience as the Air Force's Chief Digital Transformation Officer, defined this as "learning from data off of operational systems." In the defense context, this means gathering "bits off jets," munitions, ships, and submarines to understand their health, performance, and vulnerabilities.
Stewart highlighted how leading technology companies have mastered this approach:
- Microsoft: Leverages log data from device crashes to analyze system health and prioritize fixes for reliability. This iterative process of releasing beta builds, collecting crash data, and then refining the product is a testament to data-driven improvement.
- Tesla: Utilizes automatically collected data to power its AI automation capabilities, constantly learning and adapting vehicle performance.
- SpaceX (Starlink): Demonstrated remarkable electronic warfare resilience. While many focused on the rapid software patches deployed to mitigate jamming, the critical underlying factor was the automatic collection of data that informed what was being jammed, how it was being affected, and consequently, how to develop effective countermeasures. This data was essential for understanding the nature of the interference and engineering the right fix.
- Google: Beyond its search algorithms, Google's "unplanned, crowd-sourced learning" with fluid data is exemplified by Google Flu Trends. By analyzing search terms, Google was able to predict flu outbreaks, sometimes even outperforming the CDC, showcasing the power of aggregated, automatically collected data for predictive analytics.
Stewart outlined four primary ways to learn from data collected off operational systems:
- Adapt the system itself: Make direct modifications or improvements to the hardware or software based on data insights.
- Adapt tactics, techniques, and procedures (TTPs): Change how the system is used or operated to maximize effectiveness or mitigate risks.
- Adapt strategy: Inform higher-level strategic decisions based on aggregated data trends.
- Adapt exercise and training: Use data to refine training programs and simulations, making them more realistic and effective.
In the Air Force, the hypothetical data pipeline for learning and adaptation involves several critical steps:
- Mission Capture: An operational system, such as a fighter jet, collects data during a mission, potentially about neutral, adversarial, or friendly systems.
- Data Sharing: These "bits" must be securely extracted from the operational system and shared with humans or machines capable of analysis. This is a non-trivial challenge, especially in environments with degraded communications or where direct internet connections are not feasible.
- Classification: A unique and complex step in the Department of Defense (DOD) is classifying the collected data (e.g., unclassified, secret, top secret). The act of combining different data sets can often lead to up-classification, requiring analysis to occur in higher-security environments.
- Doers/Machines Learn: The classified data is then provided to analysts or automated systems ("doers or machines") in a permissive environment where they can build, test, and refine solutions. This could involve developing new analytics, software patches, or operational procedures.
A significant challenge in the DOD, as noted, is dealing with data classification and often degraded communication links, making simple data transfer difficult. However, insights from the Space Force, where telemetry collection from autonomous space systems is inherent due to the absence of human operators and the need for remote management, provide a potential model for robust instrumentation and data piping.
The discussion also touched upon predictive maintenance, where data, even if harvested and leveraged retrospectively, can provide signals about system functions operating outside of specifications. This allows for proactive maintenance on the ground before flights, preventing in-air failures, saving lives, and reducing costs.
The issue of GPS spoofing and jamming was highlighted as a current and tangible cyber threat. Thousands of flights are impacted monthly. When MMR GPS receivers receive bad time signals from spoofing, it can cause internal systems to fail and crash. The ability to discern whether such an event is an intentional attack or a maintenance anomaly is critical for pilots to make informed decisions (e.g., proceed, divert). This underscores the need for intelligent, context-aware alerts, rather than simply raw data, to avoid overwhelming the crew.
Demo / Proof of Concept
▶ Watch: Fundamental Vulnerability: Physical Access to Aircraft Avionics (4:00)
While the talk did not feature a live demonstration in the traditional sense, Stewart Wagner’s work at the Air Force served as a significant proof of concept for the ideas presented. As the Chief Digital Transformation Officer, he led a series of hackathons against fighter jets.
The purpose of these hackathons was not merely to find vulnerabilities, but to "encourage and demonstrate the potential of this data" – specifically, the vast amount of telemetry data generated by operational weapon systems. Stewart emphasized that while hackathons often get conflated with pure cyber exploitation, his focus was broader, encompassing capability development. By putting these complex systems in front of skilled teams, the Air Force aimed to:
- Illustrate the value of data: Show how collecting and analyzing data from fighter jets could lead to insights for improving system reliability, performance, and resilience.
- Drive innovation: Provide a permissive environment for "doers or machines" to learn from operational data and develop new solutions, whether they be software patches, updated tactics, or enhanced training modules.
- Build electronic warfare resilience: As exemplified by the Starlink case, understanding how systems are being jammed through data collection is paramount to developing effective mitigations. The hackathons likely explored similar data-driven approaches to understand and counter threats to aircraft systems.
These defense experiments, by actively engaging with and challenging operational systems, demonstrated a proactive, data-informed approach to system improvement that the speakers argue is critically missing in civil aviation. The hackathons, therefore, represented a practical, large-scale "demo" of how to leverage data and external expertise to enhance the security and capabilities of complex, high-stakes systems.
Defensive Implications
▶ Watch: Stewart's Air Force Hackathons Against Fighter Jets Begin (6:15)
The insights from this talk carry profound implications for defenders across the aviation sector, demanding a multi-faceted approach to bolster cybersecurity:
- Mandate and Implement Continuous Monitoring: The new FAA requirement for cybersecurity and continuous monitoring of avionics in new aircraft type certification is a critical victory. Defenders, including regulators, OEMs, and airlines, must ensure this mandate is not merely a checkbox exercise but leads to robust, effective, and auditable security controls throughout the aircraft lifecycle. Efforts should also explore how these principles can be retrofitted or applied to existing fleets where feasible.
- Enhance Telemetry and Instrumentation: Civil aviation must drastically improve its capabilities for automatic data collection and instrumentation on fly-by-wire assets. This telemetry is vital for understanding system health, identifying anomalies, and detecting potential cyber intrusions. Learning from big tech, this data should be collected not just for maintenance but specifically for security analytics, predictive maintenance, and operational resilience.
- Break Down Data Silos: The current fragmentation of data between operators, OEMs, and regulatory bodies severely hampers collective security efforts. Mechanisms must be established for secure, aggregated, and desensitized data sharing to enable a holistic view of risks and trends across the industry. This requires trust, standardized data formats, and clear governance.
- Develop Crew-Centric Cyber Alerts: The absence of real-time cyber alerts for pilots is a glaring vulnerability. Systems must be designed to provide clear, actionable indications of malicious activity (e.g., compromised data bus, bad firmware, intentional GPS spoofing) without overwhelming the crew. This requires careful consideration of crew load and the cognitive burden of information, ensuring alerts are concise, relevant, and aid decision-making (e.g., divert, proceed, land).
- Address Physical Access Vulnerabilities: Given that physical access can lead to compromise, stringent security controls around aircraft and avionics access are paramount. This includes enhanced vetting for personnel, robust physical security measures at airports and maintenance facilities globally, and continuous monitoring of access logs.
- Modernize the Software Supply Chain: The aviation industry needs to adopt modern software development and delivery practices, including cryptographic signing for all software updates and robust supply chain security measures to prevent the introduction of malicious code.
- Invest in Expertise, Funding, and Collaboration: The congressional directive for a GAO report on staffing, funding, and structures is an opportunity to address critical resource gaps. Defenders must advocate for increased investment in cybersecurity talent, dedicated funding for research and implementation, and the establishment of collaborative committees that include diverse voices from all stakeholders.
- Embrace Transparency over Obscurity: Acknowledging the debate from the Q&A, relying on "security by obscurity" is a failed strategy. Proactive vulnerability research, ethical hacking, and controlled disclosure mechanisms are essential to find and fix bugs before adversaries exploit them. This fosters a more informed and capable defensive posture.
- Shift to Proactive Risk Management: The overarching implication is a call to abandon the reactive, fatality-driven approach to safety. By leveraging data, modern security practices, and robust policy, the aviation industry can proactively identify, assess, and mitigate cyber risks, ensuring the safety and security of air travel before catastrophic events occur. This includes understanding and preparing for threats like GPS spoofing and jamming, which are already impacting thousands of flights monthly.
Key Takeaways
- Commercial aircraft currently lack fundamental cybersecurity defenses such as antivirus, intrusion detection/prevention systems, and real-time crew alerts for malicious activity.
- The recently passed FAA Reauthorization Act mandates cybersecurity and continuous monitoring for new aircraft type certifications, marking a significant step towards proactive security policy.
- The aviation industry must adopt a data-driven approach, similar to big tech, by significantly enhancing telemetry collection and instrumentation on fly-by-wire assets to improve safety, reliability, and cyber resilience.
- Lessons from Air Force hackathons against fighter jets demonstrate the power of operational data for capability development and building electronic warfare resilience, providing a model for civil aviation.
- Physical access to aircraft avionics remains a critical and often underestimated vulnerability that requires stringent controls and monitoring.
- Breaking down data silos between operators, OEMs, and regulators is crucial for fostering a holistic understanding of aviation cyber risks and enabling effective defensive strategies.
About the Speaker(s)
Michael Weigand is a reformed Army officer and recovering entrepreneur with extensive experience across military, industry, and policy domains. He served as one of the first cyber officers in the Army before founding a company dedicated to developing hardware and software solutions for aircraft protection. A private pilot himself, Weigand has been deeply involved in shaping aviation policy on Capitol Hill, advocating for necessary legal and regulatory changes to advance aircraft cybersecurity.
Stewart Wagner brings a strong background in data engineering from his time as a software developer at Microsoft, where he focused on telemetry systems for operating systems and cloud services. He later transitioned to the Department of Defense, serving as the Air Force's Chief Digital Transformation Officer. In this role, Wagner championed the concept of learning and adapting from operational data, particularly telemetry from weapon systems, and notably led a series of hackathons against fighter jets to demonstrate the potential of data-driven capability development.