Podcast Archives - Software Engineering Daily · Podcast Archives - Software Engineering Daily

Aviation Cybersecurity with Serge Christiaans

·50 min·4 clips
Serge Christians warns that airplane engines could be remotely switched off mid-flight by hackers.
Serge Christiaans is a former Dutch Air Force pilot and commercial aviator who now works as a cybersecurity instructor and consultant. Host Gregor Vand, a security-focused technologist, explores with Serge how his dual expertise shapes his view of aviation cyber risks. This episode examines the unique vulnerabilities of modern aircraft and the cultural challenges in securing global aviation. Modern aircraft function as flying server rooms with hundreds of interconnected computers and systems. Serge explains that the aviation industry's cybersecurity maturity lags behind sectors like finance due to a deep-seated cultural resistance to change, which stems from a primary focus on physical safety. The attack surface includes navigation systems, flight management computers, GPS receivers, and maintenance systems, all potentially vulnerable to spoofing or exploitation. Serge highlights aircraft engines as a critical concern, as they stream telemetry data to manufacturers and could theoretically be targeted. Legacy communication protocols like ARINC 429, designed in the 1970s without security in mind, remain in use due to aviation's long operational lifecycles. Only about 20% of pilots globally receive specific training on identifying and responding to cyber incidents mid-flight. A cyber attack in the cockpit may present as contradictory instrument data or unexplained system failures, requiring pilots to isolate the suspected system. One surprising insight is that a successful cyber attack on an airplane may not aim to cause a crash but to create chaos and demonstrate capability as a form of hybrid warfare. Serge argues that many airline executives fail to grasp cyber risk as a fundamental business threat, comparable to the operational risk of a ransomware attack. The ACARS messaging system, an unencrypted onboard data link, presents a simple vector for causing disruption through false messaging. Serge draws a direct parallel between the aviation industry's "just culture" of open incident reporting and the "blame culture" that stifles reporting in many corporate cybersecurity environments. He notes that authoritarian states often lack transparent reporting, forcing their airlines to learn from open-source reports published by Western carriers. Basic cyber hygiene and eliminating single points of failure, not advanced technology, are presented as the most urgent needs for airports and airlines. The conversation is educational and direct, grounded in Serge's operational experience as a pilot and CISO. The tone is conversational but urgent, emphasizing practical realities over theoretical speculation. This episode is ideal for cybersecurity professionals interested in critical infrastructure or listeners fascinated by the intersection of technology, safety, and geopolitics. Those seeking highly technical deep dives into specific aircraft systems may find the discussion more high-level.

As heard by us

Aviation's digital systems make cyber disruption a transportation problem, not just a cockpit concern.

Aviation cybersecurity feels concrete in this episode because it starts with the aircraft itself as a digital attack surface. Systems for navigation, communication, and engine performance are no longer treated as neatly isolated pieces of machinery; they sit inside a broader…

Read the full review in PlayNext →

Why you'd press play

You want to understand why aviation cybersecurity now feels less like an IT sidebar and more like a pressure point for global transport.

Read the full recommendation in PlayNext →
Listen to the show on