Regulations for Air Transport May Prove Ineffective: Study

Date:

Share post:

A study by Queen Mary University of London’s Cloud Legal Project has stated that the cybersecurity strategies for air transport set by the NIS Directive of European Union might be ineffective against cyber risks and do not go far enough. The 2018 NIS Regulations which implemented the NIS Directive in the U.K. ensures the safety of operators of essential services against disruptions caused by cyber risks.

The researchers found that, to comply with the regulations, operators must identify, assess, and then address the cyber risks they face which often entails a level of subjective judgement and trade-offs. They stressed that the requirements of the Directive are too vague and open to interpretation. The flipside to this is that several airports and airlines may only put in place the security measures they deem commercially beneficial to them. They also pointed out that service providers may even abuse the directives by engaging in a malpractice called paper compliance, which basically means creating a massive trove of security documentation to show regulators without making actual changes to the cybersecurity infrastructure.

Another downside was that, with the NIS directives being so vague, it is difficult for regulatory bodies to effectively check and scrutinize whether the security requirements are being met. Dave Michels, Researcher at Queen Mary’s Centre for Commercial Law Studies and co-author of the paper, said, “Regulators will need to carefully monitor airports and airlines and challenge their approaches as necessary. This will require them to hire cybersecurity experts to do this effectively.”

Ian Walden, Professor of Information and Communications Law and co-author of the study, added, “Brexit may further complicate matters due to the UK’s departure from the European Agency for Cybersecurity, which plays an important role by providing guidelines for compliance and sharing best practices.”

The researchers focused on airports like Heathrow and airlines like British Airways, which were at the epicenter of major cyberattacks in the past.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...