Check out their delicious hot sauce!
A recent report from the U.S. Government Accountability Office (GAO) has identified significant shortfalls in the cybersecurity efforts of the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA), despite their collaboration to protect the nation’s aviation systems. The report, publicly released on July 16, 2026, details how the increasing reliance on interconnected systems for both aircraft and air traffic control makes the National Airspace System (NAS) more susceptible to cyberattacks. While the FAA has established clear roles and responsibilities for cybersecurity, the TSA’s framework is outdated and lacks the necessary detail to ensure accountability and continuous improvement.
Alerts
We Need Your Support Now More Than Ever, Will You Contribute $5 Per Month?
For five years we’ve spent a lot of time giving away our news, for free. And with all things, “free” has a cost, and that cost has now come due. Without reader support, Radio Free Hub City cannot survive long-term.…
Article continues after these messages…
We didn't pick our name by accident. While other outlets are proud to be government 'Partners,' we are proud to be exactly what our namesake requires: Free from government influence, and free from government censorship. We don't lock our news behind a paywall, will you help us keep it that way? If you're tired of news sweetened with confirmation bias that never questions the 'official story', consider becoming a monthly supporter. Just $5/month helps fund our local reporting, live election night coverage, and more.
The GAO’s findings indicate that the TSA’s 2018 Cybersecurity Roadmap, intended to guide its efforts in prioritizing cybersecurity, is no longer aligned with the Department of Homeland Security’s current strategy. Crucially, this roadmap fails to identify the specific offices responsible for its implementation and does not clearly define the TSA’s roles and responsibilities in overseeing aviation security programs. This lack of clarity could leave critical systems vulnerable to exploitation. The report suggests that without an updated roadmap that clearly outlines these responsibilities, the TSA cannot effectively hold stakeholders accountable or drive necessary improvements in aviation cybersecurity.
The report also scrutinizes the FAA’s own cybersecurity initiatives. While seven FAA entities are tasked with implementing the agency’s Cybersecurity Strategy, the agency has not consistently reported all of its cybersecurity spending to the Office of Management and Budget (OMB). Specifically, spending related to its Information Security/Cybersecurity Program, which supports research and development activities, was not fully included in budget submissions for fiscal years 2024 through 2026. This omission means that policymakers and Congress may not have a complete picture of the FAA’s cybersecurity investments, potentially impacting future funding decisions.
Furthermore, although the FAA’s processes for certifying aircraft and authorizing system security align with federal and industry best practices, its Zero Trust Implementation Plan requires further development. The plan, which outlines the agency’s transition to a zero trust architecture during NAS modernization, notably lacks specific transition steps for its Research and Development operating environment. Additionally, it only partially aligns with key practices recommended by the National Institute of Standards and Technology (NIST) for migrating to a zero trust architecture. This gap could hinder the FAA’s ability to effectively manage cybersecurity risks during its modernization efforts. The FAA’s progress in implementing its Cybersecurity Strategy’s goal to protect its networks and systems also shows room for improvement. While the strategy outlines monitoring requirements, only one of the seven applicable FAA entities has demonstrated full adherence to these requirements. Recognizing this, the FAA updated its strategy in March 2026 to include plans for a centralized implementation plan and performance metrics to track progress. However, ensuring consistent monitoring and incorporating lessons learned from past experiences will be crucial for the agency to effectively mitigate risks and prioritize resources.
The GAO has made five recommendations to address these identified shortcomings. One recommendation calls for the TSA to update its Cybersecurity Roadmap to define roles and responsibilities for its entities involved in aviation cybersecurity and to align it with the DHS Cybersecurity Strategy. The remaining four recommendations are directed at the FAA. These include updating its cyber budget data request process to capture all cybersecurity spending, enhancing its Zero Trust Implementation Plan with detailed transition steps for all operating environments, ensuring full alignment with NIST best practices for zero trust, and directing its Cybersecurity Steering Committee to carry out planned monitoring and incorporate lessons learned as it implements its revised strategy. Both the Department of Homeland Security and the Department of Transportation have agreed with the GAO’s recommendations for their respective agencies.
Article by Mel Anara, based upon information from the U.S. Government Accountability Office.
Do you believe we got something wrong? Please read our publishing standards and corrections policy.
Video Spotlight
Did you know? Supporters get a reduced ad experience!
Sponsored Articles
Get daily and breaking news for Washington County, MD area from Radio Free Hub City. Sign up with your email today!
Paid supporters have a reduced ad experience!
Discover more from Radio Free Hub City
Subscribe to get the latest posts sent to your email.



