Security News

Cybersecurity news aggregator

INFO News SC Media

Audit reveals gaps in FAA and TSA cybersecurity strategies

  • What: GAO audit reveals gaps in FAA and TSA cybersecurity strategies
  • Impact: Critical infrastructure may be at risk due to incomplete security measures
Read Full Article →

Critical Infrastructure Security Audit reveals gaps in FAA and TSA cybersecurity strategies July 20, 2026 Share By SC Staff (Photo by Justin Sullivan/Getty Images) Biometric Update reports that a recent Government Accountability Office (GAO) audit has identified significant shortcomings in the cybersecurity strategies of both the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA), raising concerns about the protection of critical aviation systems. The GAO audit found that the FAA has only fully implemented three out of seven objectives for protecting agency networks, with critical areas like cyber monitoring, response, and the transition to zero-trust security remaining incomplete. The TSA, meanwhile, relies on an outdated cybersecurity plan from 2018 that lacks clear assignment of responsibilities for securing airlines and airports, leading to confusion within the industry. Despite no reported successful cyberattacks on aircraft avionics, the broader aviation sector has faced numerous cyber threats, with reported incidents rising significantly between 2020 and 2022. Vulnerabilities include poor software patching and unsupported operating systems, which could disrupt communications and alter flight data. While the FAA's aircraft certification process and ground system security received favorable findings, its zero-trust implementation plan needs further development. The TSA's lack of clarity in its cybersecurity roadmap makes accountability and progress measurement difficult. GAO has recommended that both agencies update their strategies, assign clear responsibilities, and improve reporting and implementation monitoring to enhance the overall cybersecurity posture of the U.S. aviation system. Source: Biometric Update SC Staff Related Government security US federal workers mandated to use app with Russian-founded vendor’s code SC Staff July 20, 2026 The application, costing $1.4 million, was mandated for use by the FAA and other federal employees. Critical Infrastructure Security Abbott Laboratories investigates 2 separate cyber incidents SC Staff July 20, 2026 The first incident was highlighted when the ShinyHunters extortion gang claimed to have accessed Abbott's internal legacy Exact Sciences systems in its Cancer Diagnostics business. Supply chain New npm malware cluster targets Vite ecosystem SC Staff July 20, 2026 The ViteVenom campaign, attributed to the threat actor SuccessKey, builds upon the tactics seen in the earlier ChainVeil attack. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Virtual Conference Securing the Backbone: Strategies to Counter Cyber Threats to Critical Infrastructure in the Public Sector On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article