Back to Insights Risk Management

How does United Airlines’ CISO build the defense architecture?

Cybersecurity in a world where every change must be calculated: Security around critical systems not designed for frequent updates.

The aviation industry relies on complex, legacy digital systems. These systems were built to remain stable and safe over decades, not to adopt frequent technological innovations. According to United Airlines’ security philosophy, the goal is not to “break and rebuild,” but to add intelligent security layers around core systems that cannot (and must not) be changed frequently. Instead of forcibly trying to convert legacy systems into modern cloud environments, the approach is to “wrap” them: limiting access based on user identity, implementing network segmentation, and maintaining tight monitoring. Here, success is measured by precision rather than implementation speed—every change must improve safety and reliability without undermining the stability of aircraft in the air.

Operational Resilience Over Absolute Prevention: When a cyber incident becomes an immediate national and public crisis.

Airlines are far more than technology entities—they manage critical logistics and infrastructure. Therefore, a cyber strategy cannot settle for breach prevention alone; it must give equal weight to the ability to recover quickly and maintain operations even during an incident. In this context, cyber risk is measured by its impact on the ability to safely and punctually move aircraft, crews, and passengers. The implication is clear: a CISO cannot operate in a technical vacuum. They must deeply understand the “engine” of the business—from flight scheduling and maintenance to weather constraints. Cybersecurity is the force that enables the business to operate safely, not just an isolated technical department.

A Network of Partners Requires Shared Responsibility: Managing risks when key dependencies lie outside the organization.

The aviation industry depends on a massive network of vendors: airports, aircraft manufacturers, and government bodies. A large portion of risks is not under the direct control of the company. Consequently, instead of relying solely on “vendor questionnaires,” management focuses on understanding interdependencies and analyzing scenarios: “What happens if my partner’s system crashes?”. The starting premise is that some disruptions will originate externally. The goal is not to prevent every malfunction in the world, but to detect them early, understand their impact on flights, and respond without compromising passenger safety. This requires teamwork across all departments: security, operations, legal, and management—especially when aircraft are in the air.

Recommendations for CISOs in Complex Organizations by IPV Security Experts:

  • Resilience as a Core Objective: Do not promise “zero breaches”; invest in the capability to continue operating even when something goes wrong.
  • Enveloping Protection: Wrap legacy systems in modern controls rather than attempting to replace them through expensive and risky processes.
  • Business Analysis: Evaluate risks based on their impact on customers and operations, not just the technical rating of a vulnerability.
  • Multidisciplinary Drills: Build response teams that include management and operations, and practice extreme scenarios together.
  • The Language of Safety: Communicate with management about “service continuity” and “reliability” rather than software tool names.

In conclusion, the aviation model reflects a new reality for everyone: in complex systems, cybersecurity is measured by the ability to maintain trust and continuity—even under attack. The mission is not to build an impenetrable wall, but to build an organization that knows how to keep flying even under pressure.

For more information: United Airlines CISO on building resilience when disruption is inevitable – Help Net Security.

To consult with an expert, contact the specialists at IPV Security! For professional consultation, reach out to us at info@ipvsecurity.com or by phone at 077-4447130. IPV Security has specialized for 21 years in information security, cybersecurity, risk assessments, and information security standards and regulations.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation