GAO Finds FAA, TSA Gaps in Aviation Cybersecurity Oversight
A July 16 GAO audit found open FAA and TSA oversight gaps involving cybersecurity roles, monitoring and budget tracking—not a reported attack on aircraft controls.
A Government Accountability Office audit released July 16 found unresolved cybersecurity oversight gaps at the Federal Aviation Administration and Transportation Security Administration, including unclear responsibilities, incomplete spending reports and uneven implementation of FAA’s cybersecurity strategy.
GAO identified five open recommendations for the two agencies. FAA and TSA agreed with the recommendations. The audit focuses on governance, accountability and monitoring across aviation systems—not evidence that ordinary commercial flights are currently unsafe or that a successful cyberattack on aircraft controls has occurred.
TSA’s roadmap is outdated
GAO found that TSA’s aviation cybersecurity roadmap dates to 2018 and is no longer aligned with the Department of Homeland Security’s current cybersecurity strategy. The roadmap also does not clearly identify the offices responsible for carrying out its goals or define TSA’s oversight roles involving airports and aircraft operators.
That lack of clarity matters because aviation cybersecurity is divided across interconnected systems and agencies. TSA oversees security programs involving airports and aircraft operators, while FAA manages major parts of the national airspace system and related technology. Clearly assigning responsibility helps agencies hold stakeholders accountable, coordinate protections and measure progress over time.
FAA had not fully carried out its strategy
GAO reviewed seven objectives supporting an FAA cybersecurity strategy goal focused on protecting and defending networks and systems. The agency fully implemented three of the seven objectives and partially implemented the other four during the review period.
The three-of-seven result applies only to the objectives GAO reviewed. It does not mean FAA has only three cybersecurity measures agencywide. Instead, GAO found that the reviewed strategy objectives were not all fully implemented and that FAA had weaknesses in monitoring progress across the agency.
FAA updated its strategy in March 2026 and described plans for a centralized implementation plan and performance metrics. GAO’s recommendations remain open until the agency’s actions can be confirmed.
Budget reporting is part of the oversight issue
FAA did not include all aviation cybersecurity activities and costs in budget information submitted to the Office of Management and Budget for fiscal years 2024 through 2026. GAO specifically identified missing spending data for an information-security and cybersecurity program supporting research and development.
Incomplete reporting can make it harder for Congress, budget officials and agency leaders to determine how much is being invested, where resources are going and whether future funding requests address the highest-priority risks.
FAA’s fiscal 2026 budget materials show that cybersecurity remains a planned investment area. They include $35 million for operations cybersecurity and $27 million for information-security facilities and equipment, along with planned modernization using zero-trust architecture and related principles. Those figures are requested or planned investments, not proof that projects have been completed or that the amounts represent final spending.
What happens next
The five open recommendations call for TSA to update and communicate its cybersecurity roadmap. FAA is expected to improve cyber-budget data collection, expand and align its zero-trust implementation plan with federal best practices, and strengthen monitoring by its Cybersecurity Steering Committee.
For travelers, the immediate issue is not a reported cyberattack on aircraft controls. The accountability question is whether federal agencies can clearly assign responsibility, track investments and verify that protections are being implemented across aviation systems connecting aircraft, airports and air-traffic-control operations. Updates to TSA’s roadmap, FAA monitoring results and the eventual closure of GAO’s recommendations will show whether the agencies are turning the audit’s findings into documented improvements.
Sources
- GAO aviation cybersecurity audit
- FAA Fiscal Year 2026 Budget Estimates
- DOT Inspector General continuous-monitoring audit
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.