Back to Feed
Saturday, Aug 1, 2026, 05:00 PM

Aviation Cyber Resilience: Lessons from United Airlines CISO Deneen DeFiore

Aviation Cyber Resilience: Lessons from United Airlines CISO Deneen DeFiore

In a recent in-depth interview with Cyber Magazine, Deneen DeFiore, Chief Information Security Officer (CISO) at United Airlines, shed light on the evolving cyber threat landscape in the aviation sector. Securing a major airline isn't just about protecting airplanes; it requires safeguarding a massive digital ecosystem that spans passenger booking systems, supply chains, cloud infrastructure, and thousands of interconnected third-party vendors.

DeFiore emphasized that cybersecurity in modern aviation is fundamentally about operational resilience—the ability to anticipate, withstand, and rapidly recover from disruptions. For Site Reliability Engineers (SREs) and DevOps teams, this approach mirrors the core principles of chaos engineering and proactive monitoring.

The SRE Takeaway: Managing the Ecosystem

Airlines, like modern SaaS platforms, are highly dependent on external APIs, cloud providers, and SaaS tools. When a third-party vendor experiences an outage or a security breach, the blast radius can instantly ground flights or disrupt passenger check-ins.

To build true systemic resilience, SREs must move beyond internal system monitoring and embrace comprehensive ecosystem visibility:

  1. Aggregating Vendor Health: Relying on manual updates during a vendor outage is a recipe for delayed incident response. Tools like CloudStatusHQ aggregate third-party vendor dependency health status in real-time, giving your SRE team instant alerts when critical external APIs or infrastructure dependencies fail.
  2. Securing Digital Touchpoints: Securing customer-facing infrastructure requires continuous verification. Certificate Guardian monitors SSL/TLS certificate renewals and CT logs proactively, preventing sudden outages that block users from reaching booking and check-in portals.
  3. Domain and DNS Integrity: Aviation operations rely on absolute trust in domain routing. Domain Audit HQ provides proactive domain name expiration, DNS change, and WHOIS monitoring, ensuring that malicious actors cannot hijack critical domain assets or disrupt DNS resolution.

By implementing automated monitoring across both internal systems and external dependencies, organizations can achieve the high-availability standards highlighted in United's modern cybersecurity strategy.

Source Link

news.google.com

Read the original news article