Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

The Aviation Industry and Cyber Risk – SecurityScorecard Report

Posted on July 31, 2024July 31, 2024 By Martin Hinton

The aviation industry is a marvel of complexity, coordinating intricate schedules, unpredictable weather patterns, and the seamless flow of information across digital networks. From customer interactions to internal communications, the industry’s reliance on these digital systems is paramount for maintaining ongoing and reliable operations. Ensuring the cybersecurity of these systems is thus critical. With news today that Delta estimates the CrowdStrike outage will cost the company $500 million, this digital dependence is ever clear. As is the danger of system failure.

With this reality established a report worth noting. SecurityScorecard researchers conducted an in-depth analysis of cyber risks within the aviation industry. The study, The Cyber Risk Landscape of the Global Aviation Industry, 2024, focused on airlines and their associated vendors, including manufacturers, ground-handling service providers, and aviation-specific IT providers. Historically, the aviation industry’s security measures have prioritized physical risks. However, the recent findings underscore the urgency of integrating cyber risk management into the industry’s safety protocols. Following is our summary; link to the full report is here.

New Regulations

In response to growing cybersecurity concerns, regulatory bodies have introduced new measures. In the U.S., the Transportation Security Administration (TSA) implemented cybersecurity requirements for airports and airlines in March 2023. Similarly, the European Union’s Implementing Regulation 2023/203, which will take effect in 2026, aims to enhance information security risk management in aviation.

Key Findings

Security Scores

The report reveals that the aviation industry, on average, receives a “B” grade for cybersecurity. Airlines generally have higher security ratings than other sectors within the industry, such as manufacturers and aviation-specific IT vendors. However, these vendors still pose significant third-party cyber risks to airlines.

Application Security

Application Security is identified as the top weakness in the aviation sector’s attack surfaces, with issues like HTTP usage in redirect chains and missing attributes in session cookies being prevalent. These vulnerabilities significantly impact overall security scores.

Third-Party Breaches

The analysis shows that third-party breaches are a critical concern. For instance, aviation-specific software and IT vendors have the lowest security scores, making them high-risk entities for airlines. The study highlights that software and IT products are responsible for up to 75% of third-party breaches across all industries.

Publicly Reported Breaches

7% of the organizations in the study sample had publicly reported breaches in the past year. Additionally, 17% had at least one compromised device, and 3% had both breaches and compromised devices. This indicates a substantial risk of cyber incidents within the industry.

Impact of Third-Party Breaches

Despite higher security scores, airlines experienced 4% more breaches and compromises than the industry norm. This discrepancy is attributed to the lower scores and higher risks posed by their vendors.

Performance Correlation

The report establishes a correlation between security performance and industry rankings. Airlines with the best performance ratings from industry analysts and consumer publications also have above-average security ratings. Interestingly, budget airlines perform nearly on par with full-service airlines regarding security scores.

Ransomware Threats

Ransomware remains the top cyber threat to the aviation industry. Incidents involving ransomware often result in the theft of passenger data, used either for financial fraud or intelligence purposes.

Methodology

SecurityScorecard’s research compiled a sample of 250 organizations, including top-rated commercial passenger airlines, aircraft manufacturers, aviation services providers, and aviation-specific software and IT vendors. Each organization’s security score was evaluated based on its attack surface signals, with a detailed analysis of the lowest-scoring security factors and specific issues impacting their scores.

Cybersecurity Recommendations

Prioritize Software & IT Vendors

Airlines should focus on managing third-party risks associated with software and IT vendors. These vendors pose significant risks due to their lower security scores and higher likelihood of enabling breaches.

Comprehensive Third-Party Risk Management

Third-party risk management should extend beyond vendors to include customers and other partners. This comprehensive approach is essential for mitigating risks from all potential sources of cyber threats.

Improve Application Security and DNS Health

Special attention should be given to enhancing application cybersecurity, particularly addressing vulnerabilities in session cookies and ensuring robust DNS health. Implementing secure attributes in session cookies and maintaining SPF records can significantly reduce the risk of cyber attacks.

Protect Intellectual Property and Passenger Data

Organizations must prioritize protecting high-value assets such as aerospace intellectual property and passenger data. Enhanced security measures around these assets can help detect and prevent attempts to compromise them.

Avoid Paying Ransoms

While paying ransoms may seem like a quick fix, it comes with significant risks, including the possibility of not recovering data and encouraging further attacks. Legal advice should be sought before considering ransom payments.

Conclusion

The aviation industry’s cybersecurity landscape is complex and fraught with challenges. By prioritizing third-party risk management, improving application security, and protecting critical assets, the industry can enhance its resilience against cyber threats and ensure safer aviation operations in an increasingly digital world.

Source: The Cyber Risk Landscape of the Global Aviation Industry, 2024.

Other News: Supply-Chain Risk Continues to Bedevil Large Companies and their Cyber Insurers (Opens in a new browser tab)

Other News: Delta CEO Says CrowdStrike Tech Outage Cost It $500 Million.

Cyber Insurance, Cybersecurity, Cybersecurity Report Tags:Aviation, Aviation Cyber Risk, cyber insurance, Cyber Risk, Cyber Risk Analysis, Cybersecurity, SecurityScorecard

Post navigation

Previous Post: Boost Insurance Secures Major Investment from BHMS
Next Post: Coalition Introduces Active Cyber Insurance in Germany

Related Posts

  • USQRisk Launches Pera, a Managing General Agent Insuring Cyber-Related Risk Cyber Insurance
  • SecurityScorecard Achieves StateRAMP Ready Status and Reaffirms FedRAMP Compliance Cybersecurity
  • Biggest Myths Around Cyber Insurance? Cyber Insurance
  • Cowbell Joins ABI to Strengthen UK Cyber Insurance Sector Cyber Insurance
  • Urgent Wake-Up Call: 6 Shocking Stats About Family Office Cybersecurity in 2024 Cyber Insurance
  • A Hurricane of Cyber Insurance – Report Cyber Insurance

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In this clip from our latest podcast, Martin Hinton and William Altman dive into the long-term consequences of data breaches — especially those affecting K–12 students. Highlighting the PowerSchool breach, which exposed 60 million student records, they explore how leaked personal data like mental health history may resurface decades later, leaving individuals vulnerable to fraud, identity abuse, and digital exploitation.

Altman warns that while credit monitoring may address financial risk, it fails to protect against deeper psychological and reputational harm. This conversation is a must-hear for educators, parents, and policymakers thinking beyond immediate breach responses.

🔗 Learn more at www.cybcube.com/
#Cybersecurity #StudentPrivacy #DataBreach #PowerSchool #CyberRisk #IdentityTheft #DigitalSafety #CyberInsurance
Education Cybersecurity Exposed: Long-Term Impact of K–12 Cybersecurity Breaches
The threat of cybersecurity breaches in 2025 and the long-term damage of a cyberattack. In this episode of the Cyber Insurance News Podcast, Executive Editor Martin Hinton interviews William Altman, Head of Cyber Threat Intelligence at CyberCube. They explore the evolving world of cybersecurity and cyber insurance. The episode dives into why small businesses are highly vulnerable, how AI is both a weapon and a shield in cyber defense and the critical gaps in threat intelligence. They also discuss basic measures even the smallest business can take to protect themselves from a cybersecurity breach. 

A spotlight is cast on the education sector, where underfunded cybersecurity programs have made schools a prime target for threat actors. These cybersecurity breaches can have a lasting impact. One alarming breach compromised 60 million K-12 student records, revealing sensitive data like mental health histories, data that can't be “reset” like a credit card. This breach raises urgent concerns about the long-term impacts of cybercrime on students' privacy, identity, and future safety, far beyond the limits of traditional credit monitoring.

They also explore the security posture of the financial sector, the power of identity and privileged access management, and the real-world impact of software vulnerabilities.

🔐 KEY TOPICS:

Cybersecurity strategies for small businesses

The widening cyber insurance protection gap

How AI is used in phishing and threat reconnaissance

Managing software vulnerabilities and patch cycles

Cybersecurity in education and financial sectors

Global threat intelligence trends

📌 Takeaways:

MFA significantly reduces attack success rates.

Small businesses and schools are increasingly at risk.

Sensitive student data breaches have lifelong consequences.

AI is making phishing more personalized and efficient.

MSPs can be critical vulnerabilities in your cyber chain.

💡 Essential Cybersecurity Resources for SMBs:

🔗 NIST Cybersecurity Framework

🔗 CIS Critical Security Controls

👉 Subscribe for more expert interviews and visit @cybercube4461 for more insights. 

#cybersecuritybreaches2025 #cybersecuritybreaches #cyberinsurance #AIinCybersecurity #studentdatabreach #smallbusinesssecurity #educationcybersecurity #dataprotection #CyberCube #MFA #cyberrisk

Chapters
00:00 Introduction to Cyber Threat Intelligence
02:58 Understanding the Cyber Insurance Landscape
05:55  The Vulnerability of Small Businesses
08:54 Practical Cybersecurity Measures for Small Businesses
12:04 The Role of Education in Cybersecurity
18:07  The Long-Term Impact of Data Breaches
27:01 Cybersecurity in the Financial Sector
29:01 The Risks of Common Technologies in Finance
31:15 AI: The Double-Edged Sword in Cybersecurity
35:40 The Evolving Threat Landscape with AI
39:11 Global Cybersecurity: Regulations Matter
42:15 Cybersecurity Essentials for Small Businesses
Cybersecurity Breaches 2025: Small Business, AI & Education Breaches.
In the wake of the Harrods hack and cyberattacks impacting other retailers, the alarming state of UK cybersecurity will be revealed in 2024. From cyberattacks hitting major UK retailers like Co-op and Harrods to small businesses struggling without protection, the message is clear—cybercrime is a national threat.

New research by Pen Underwriting reveals that while 90% of UK and Irish businesses feel secure, only 47% have dedicated cyber insurance. Even more shocking—only 18% of businesses earning under £1 million are covered. The cost isn’t just financial—real people suffer, like the couple who lost their wedding cake due to a ransomware attack.

Watch now to understand:

Why UK businesses are dangerously unprepared

How cyberattacks are more common than fires or theft

The key role of employee training, data backups, and multi-factor authentication (MFA)

Why cyber insurance is no longer optional

Visit www.cyberinsurancenews.org for the latest cyber insurance and cybersecurity updates.

#UKCybersecurity #CyberInsurance #SmallBusinessSecurity #CyberCrime
Harrods hack UK Cybersecurity Crisis: Shocking Stats, Real Victims & Business Risks. #cybersecurity
Load More... Subscribe

Categories

  • 8-K
  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime cyber crime CyberCube cyber insurace cyberinsurance cyber insurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyber liability insurance cyberliabilityinsurance Cyber Resilience Cyber Risk Cyber Risk Management cyber security Cybersecurity cybersecurity insurance Cyber threats Data Breach Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance reinsurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • New York State Mulls Groundbreaking Cybersecurity Regulations for Hospitals Cyber Insurance Laws & Regulations
    • No Lazy Days of Summer for K-12 Schools Trying to Get Their Cyber Insurance Renewed  Cyber Insurance for Government
    • Marsh Expands Cyber Insurance with Cyber Echo Encore, Adding $45 Million Coverage Cyber Insurance
    • K-12 Cyber Insurance Rates Up 300%?  Cyber Insurance for Government
    • Lawyers — Better Consider Cyber In Addition to Malpractice Insurance to Protect Against Losses from “Spoofing”  Cyber Insurance Industry Groups
    • Ramping Cyber Insurance Premiums Help Hiscox Hit Profitability in H1 2021  Cyber Insurance
    • Finally a Book Just for Us. Cowbell Cyber Releases “Cyber Insurance For Dummies” & It’s Free Cyber Insurance
    • Cyber Insurance Sunday – Upload Cyber Insurance Sunday - Upload

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme