Why it Matters

The federal government's two primary aviation agencies are struggling to coordinate on a critical vulnerability: protecting aircraft from cyberattacks. A new Government Accountability Office (GAO) report reveals that while the Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) collaborate on aviation cybersecurity, they have failed to clearly delineate who is responsible for what, leaving potential gaps in the nation's defenses against digital threats to commercial aviation.

The stakes are significant. Modern aircraft depend on interconnected systems both onboard and on the ground to operate safely. That same interconnection makes them more vulnerable to cyberattacks. If adversaries compromise these systems, the consequences could range from disrupted operations to safety hazards affecting millions of passengers annually.

The GAO report, released on July 16, identifies key shortfalls in how the two agencies are managing this shared responsibility. The findings underscore a fundamental problem in how the federal government approaches aviation security in an era when cyber threats are as real as physical ones.

The Big Picture

Aircraft systems today communicate with ground-based infrastructure, maintenance networks, and air traffic control systems. This interconnectedness is essential for modern aviation operations, but it creates multiple entry points for potential cyberattacks.

The FAA, housed within the Department of Transportation, serves as the primary aviation safety regulator. The TSA, part of the Department of Homeland Security, functions as the aviation security agency. Both agencies have important roles in protecting air travel and travelers from threats. But their missions, structures, and authorities differ significantly.

The FAA has clearly defined roles and responsibilities for aviation cybersecurity within its regulatory framework; TSA does not. This asymmetry creates confusion about accountability and potentially leaves blind spots in security coverage.

While the two agencies do work together on aviation cybersecurity matters, and the GAO acknowledges this collaboration exists, the report identifies an apparent wealth of overlapping roles and responsibilities between them. When responsibilities overlap without clear delineation, several problems emerge: neither agency may take full ownership of a particular security challenge, assuming the other is handling it; resources may be duplicated in some areas while gaps persist in others; or industry partners seeking guidance may receive conflicting direction from the two agencies.

The GAO's investigation found that the TSA's lack of clearly defined roles and responsibilities is the primary shortfall driving these coordination problems. Without explicit authority and responsibility assignments, the TSA cannot effectively partner with the FAA or provide clear security standards to the aviation industry.

What the GAO Found

The GAO report makes recommendations specifically directed at the TSA to address this shortfall. The recommendations focus on establishing clear roles and responsibilities for TSA aviation security functions. By codifying what the TSA is responsible for—and equally important, what it is not responsible for—the agency could eliminate ambiguity and improve coordination with the FAA.

The report does not suggest the FAA needs similar restructuring. The aviation regulator's existing framework for defining its cybersecurity responsibilities appears sufficient. The problem lies on the security side of the equation, where the TSA operates with less institutional clarity about its specific mandate.

Political Stakes

Aviation cybersecurity has become an increasingly prominent concern in Washington. As commercial aviation grows more dependent on digital systems, the potential impact of a successful cyberattack expands accordingly. Airlines, aircraft manufacturers, and airport operators all depend on secure digital infrastructure to function.

The federal government has been gradually tightening cybersecurity standards across critical infrastructure sectors, and aviation has not been exempt from this pressure. The GAO report reflects a broader recognition that the current approach to aviation cyber threats is inadequate for the threat environment.

The report arrives at a moment when cybersecurity funding and attention are competing priorities across multiple federal agencies. TSA, like other government entities, must balance cybersecurity investments against other security concerns. Without clear role definitions, however, TSA cannot effectively advocate for or justify cybersecurity spending to Congress and the Office of Management and Budget.

The Bottom Line

The GAO's recommendations provide a roadmap, but implementation depends on whether the TSA acts on them. The agency must establish explicit roles and responsibilities for aviation cybersecurity that complement, rather than duplicate, the FAA's existing framework. This requires coordination with the FAA, input from industry stakeholders, and potentially new regulatory guidance.

The FAA and TSA will need to formalize their collaboration beyond informal working relationships. Written agreements, clear escalation procedures, and defined decision-making authority for shared challenges are necessary to prevent future gaps.

The aviation industry awaits clarity. Airlines, aircraft manufacturers, and airport operators need to understand which agency sets cybersecurity standards, which agency enforces compliance, and which agency responds to incidents. Ambiguity creates compliance challenges and potentially undermines security by allowing operators to play agencies against each other or assume someone else is handling a particular threat.

Whether the TSA will move quickly to implement the GAO's recommendations remains to be seen.

Access the Legis1 platform for comprehensive political news, data, and insights.

Spot something wrong? Report an issue with this article