Quick Summary
The Securityish Brief
In an interview with Help Net Security, Deneen DeFiore, VP and CISO at United Airlines, outlines the airline’s cybersecurity strategy amidst the complexities of aviation. The industry operates on long technology lifecycles, making constant change impractical. Instead, United Airlines prioritizes modernization that enhances safety and reliability without compromising operational integrity.
DeFiore explains that the airline’s hybrid identity as an IT company, logistics operator, and safety-critical infrastructure provider shapes its cybersecurity approach. Unlike other industries where incidents may lead primarily to data loss, aviation incidents can quickly result in operational disruptions and safety risks.
To manage cyber risks that originate outside its direct control, United Airlines invests in understanding dependencies and critical third parties. This includes conducting scenario analyses and operational impact modeling to prepare for potential disruptions.
Incident response in aviation is complex, requiring multidisciplinary collaboration to ensure safety and public trust. Decisions are made with input from various departments, emphasizing the importance of clear communication and pre-planned protocols.
Building trust across disciplines is essential for effective cybersecurity. DeFiore highlights the need for cybersecurity teams to understand the operational constraints of safety and engineering teams, fostering collaboration through shared goals.
- United Airlines focuses on wrapping legacy systems with modern controls to enhance cybersecurity without compromising operational integrity.
- The airline assesses cyber risk through scenario analysis and operational impact modeling, recognizing that many risks originate externally.
- Incident response decisions at United Airlines involve collaboration across multiple disciplines, ensuring safety and public trust are prioritized.
- Trust is built by understanding the operational needs of safety and engineering teams, promoting shared accountability in cybersecurity efforts.
- Cybersecurity at United Airlines is seen as an enabler of safe operations rather than a hindrance, fostering collaboration across departments.
Key Takeaways
- Review your organization’s incident response protocols to ensure they prioritize safety and operational continuity.
- Enhance collaboration between cybersecurity and operational teams to build trust and shared accountability.
- Conduct regular scenario analyses to assess potential external risks to your operations.
- Implement strong controls around legacy systems to protect against cyber threats without compromising their functionality.
- Foster a culture of communication and clarity in crisis decision-making across all departments.
Key Terms & Concepts
- Operational Continuity: In this article, operational continuity refers to maintaining essential functions during disruptions, especially in the aviation industry.
- Cyber Risk: Cyber risk refers to the potential for loss or disruption due to cyber incidents, which can impact operations and safety in aviation.
- Multidisciplinary Collaboration: In this article, multidisciplinary collaboration describes the teamwork between cybersecurity and other departments to ensure informed decision-making during incidents.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.