Securing the Modern Airport: Professor Kai London on OT Cybersecurity for Aviation
By the Ezeiza Times Technology Desk
A modern airport is one of the most complex operational-technology environments on earth — baggage systems, jet bridges, fuel management, runway lighting, building controls, security screening and air-traffic support, all increasingly networked. “An airport is a city that runs on control systems,” says Professor Kai London, a senior CISO who advises transport and critical-infrastructure operators. “And when those systems are attacked, the consequence is not a slow website. It is grounded aircraft, stranded passengers and, potentially, safety at risk.”
“Aviation fused physical safety and cyber security years ago. In an airport, an OT compromise is an operational and safety event — which is exactly why it belongs on the board's agenda.”
Why airports are hard to secure
London points to the sheer diversity of systems and stakeholders. “An airport blends airline systems, ground handlers, retailers, government agencies and the airport's own operations — each with its own technology and its own access,” he says. “That interconnection is what makes it work, and what makes it hard to defend.” Much of the underlying control technology, he adds, was built for reliability rather than security.
The pattern of failure
As across critical infrastructure, London stresses that the decisive weaknesses are usually mundane: an over-privileged identity, a flat network that lets a compromise spread, a supplier with weak security, a remote-access pathway nobody reviewed. “These are governable problems,” he says, “which is the encouraging part.”
A practical playbook
London's recommendations translate directly to aviation: inventory every connected system; segment ruthlessly so a breach in one area cannot reach flight-critical or safety systems; bring identity under control for every human and machine; scrutinise the access held by the many third parties operating on site; and rehearse the incident so the airport can keep running while it responds. “Run the loss of a key system as an exercise,” he says, “before a real attacker runs it for you.”
Resilience is continuity
For an asset where downtime cascades across an entire network of flights, London frames resilience as the goal. “The objective is not a system that is never attacked,” he says. “It is an airport that keeps operating safely when one is.” Regulators, he notes, increasingly expect operators to demonstrate exactly that resilience.
For a hub that connects a nation to the world, London's message is clear: the airport now runs on code as much as on concrete, and securing that code is inseparable from keeping the aircraft moving and the passengers safe.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
