Federal audit finds major gaps in US a
GAO finds FAA behind on zero trust and TSA lacking clear cybersecurity responsibilities for airports and airlines
Jul 19, 2026, 3:53 pm EDT
|
Anthony Kimery
CategoriesAccess Control | Biometrics News | Government Services
The U.S. Federal A has not fully carried out its strategy for protecting air traffic systems and other critical aon (TSA) continues to rely on an outdated cybersecurity plan that does not clearly assign responsibility for securing airlines and airports, according to a new federal audit
Anaudit by the Government Accountability Office (GAO), Congress’ investigative arm, found the FAA had fully implemented only three of seven objectives supporting its goal of protecting and defending agency networks
Work remained incomplete in several areas central to the security of theNational Airspace System, including cyber monitoring and response, control over privileged users, compliance with current federal standards, and the transition to zero-trust security
The findings come as aircraft systems are increasingly connected to air traffic control facilities, weather services, navigation systems, satellites, and other external networks
Those connections make modern athrough which an attacker could attempt to gain access or interfere with operations
GAO said there have been no reported successful cyberattacks on aircraft avionics. The broader ate-sponsored actors, financially motivated groups, and hacktivists
Cybersecurity incidents reported to the Cybersecurity and Infrastructure Security Agency across the aeclining to 151 in 2024
The total increased again to 352 in 2025. Those figures cover the wider aaircraft flight systems
The vulnerabilities identified in reported incidents included poor software patching, Internet accessible operational technology, unsupported operating systems, insecure remote services, weak network segmentation, and default credentials
Successful exploitation could disrupt communications with air traffic controllers, alter data used by cockpit systems, interfere with aircraft location information, or allow unauthorized access to a
FAA and TSA are the two principal federal agencies responsible for a FAA regulates aircraft safety, oversees the cybersecurity of avionics through its certification process, and operates the ground systems supporting the National Airspace System
TSA oversees security programs maintained by airports and aircraft operators
GAO found FAA’s cybersecurity strategy clearly assigned duties to seven agency organizations. TSA’s planning documents did not provide the same clarity
TSA’s principal Cybersecurity Roadmap dates to 2018 and is no longer aligned with the Department of Homeland Security’s (DHS) current cybersecurity strategy, GAO said
TSA also has not identified which of its offices are responsible for carrying out its goals, nor does it clearly define the agency’s cybersecurity responsibilities for overseeing airport and airline security programs
The absence of clearly assigned responsibilities makes it more difficult for TSA to hold its own offices and regulated entities accountable, measure progress, or improve its a
Several also said they had difficulty understanding TSA’s role. Representatives of one airline told GAO they believed TSA lacked the re properly
Confusion increased after TSA issued a Joint Emergency Amendment in March 2023 requiring covered airports and aircraft operators to include measures in their security programs to protect critical information technology, operational technology, and business support systems against disruption
Some industry representatives had assumed that such cybersecurity requirements fell under FAA’s authority. FAA and TSA later worked together on guidance clarifying that re’s requirement
Congress also granted FAA exclusive authority over the cybersecurity of civil aircraft in theFAA Reauthorization Act of 2024
Despite the uncertainty surrounding their separate responsibilities, GAO found that FAA and TSA worked effectively together through the Ants of Transportation, DHS, and Department of Defense
The initiative met all eight of GAO’s leading practices for interagency collaboration, including defining common outcomes, assigning leadership, sharing re
FAA also received favorable findings in several areas. GAO concluded that the agency’s current and proposed aircraft certification process addressed all of the federal and industry practices auditors identified for protecting avionics against cybersecurity risks
FAA’s security authorization process for the ground systems it operates in the National Airspace System also met those practices
The audit found more significant weaknesses in FAA’s plan for moving its networks to a zero-trust architecture
FAA’s implementation plan fully addressed only three of seven migration practices recommended by the National Institute of Standards and Technology (NIST)
It did not contain detailed transition plans for the agency’s research and development environment and only partially addressed the identification of users, assets, data flows, and business processes across the agency’s other operating environments
The omission is significant because research and development will support the continuing modernization of the National Airspace System
GAO said FAA cannot be certain it is comprehensively managing the associated cybersecurity risks without applying zero-trust principles across all its operating environments
Auditors also found FAA had not fully reported its cybersecurity spending to the Office of Management and Budget
FAA’s annual budget requests identified several cybersecurity programs, including funding for network protection, secure remote access, authentication systems, and research into tools intended to detect and mitigate attacks on the a
The agency’s Information Security and Cybersecurity Program received requested funding of $6.4 million for fiscal year 2024, $5.9 million for 2025 and $4.6 million for 2026
FAA did not include that research program in the cybersecurity spending data it submitted for the government-wide budget process
Its internal reporting procedure collected information only for investments already listed in a prepopulated spreadsheet and did not direct program offices to add other cybersecurity spending
FAA officials said the program had been included in the agency’s most recent submission for the fiscal year 2027 budget, but GAO said the agency had not provided evidence supporting that claim as of April
The incomplete reporting could prevent Congress and executive branch officials from understanding how much FAA is spending on cybersecurity and complicate decisions about future funding, particularly as the agency tests AI, machine learning, and other technologies for a
GAO attributed FAA’s incomplete implementation of its cybersecurity strategy in part to the absence of a comprehensive monitoring process
Although the strategy required participating offices to align their business plans with its objectives, only one of the seven applicable FAA entities provided evidence that it had done so
FAA reported that it faced difficulties allocating re cybersecurity employees, protecting aging infrastructure, and reducing risks to operational technology without disrupting its mission
While the agency adopted a revised Cybersecurity Strategy in March and now plans to develop a centralized implementation plan and performance measures for tracking progress, GAO said FAA must ensure that its Cybersecurity Steering Committee conducts monitoring and incorporates lessons from the failure to track the earlier strategy
GAO issued five recommendations. It called on TSA to update itsCybersecurity Roadmap, assign responsibility for carrying out its goals, align the document with the DHS strategy, and communicate the revised plan to nonfederal a
The watchdog recommended that FAA capture all cybersecurity spending in its budget reporting, develop transition steps for every operating environment, bring its zero-trust plan into full alignment with NIST guidance, and ensure that implementation of its revised cybersecurity strategy is monitored
Article Topics
cybersecurity | GAO (Government Accountability Office) | TSA | U.S. Government | zero trust

