Blog · K.17 · Industry

Penetration testing for aviation

An airline holds your passport, your card and your travel history; an airport runs baggage, check-in and building systems that a nation depends on. Aviation pairs mass passenger and payment data and high-value loyalty points with safety-critical operational technology and critical-infrastructure status - a uniquely high-consequence target. In the GCC, home to world-leading carriers and hub airports, the exposure is significant. Here's why aviation gets hit, what a test must cover, and how OT changes the approach.

AviationAirlinesAirportsLoyalty FraudCritical Infrastructure
Aviation: Passenger & Payment Data · Loyalty / Miles Fraud · Booking & Check-in · Airport OT & Baggage · Critical Infrastructure · PCI DSS + PDPL Aviation: Passenger & Payment Data · Loyalty / Miles Fraud · Booking & Check-in · Airport OT & Baggage · Critical Infrastructure · PCI DSS + PDPL
// TL;DR

Aviation is a high-consequence target: it combines mass passenger & payment data, high-value loyalty programmes (miles = money, so fraud and account takeover), safety-critical OT, and critical-infrastructure status. Airline tests cover booking/reservation, payments, loyalty, check-in & mobile apps, and partner/GDS APIs; airport tests add passenger-processing, baggage and operational/building systems. Across both: web/API, network segmentation (corporate vs passenger-facing vs operational), and booking/fare/loyalty business logic. Safety-critical OT is tested conservatively (passive-first), with the key question - can an attacker reach the operational systems from IT? Drivers: PCI DSS, the PDPLs/GDPR, national cyber and civil-aviation frameworks, and critical-infrastructure resilience. Details below; the OT discipline mirrors manufacturing.

// 01 Why aviation is a high-consequence target

Aviation is targeted from several directions at once. It holds large volumes of passenger personal and payment data - identity documents, travel patterns, cards - and runs high-value loyalty programmes whose miles have real, monetisable value, drawing constant fraud and account-takeover attacks. Operationally, it depends on interconnected systems for booking, check-in, baggage, flight operations and airport infrastructure, where disruption has outsized consequences - a grounded fleet, a stalled airport. And as critical national infrastructure, it attracts not just criminals but more capable actors. That combination - sensitive data, monetisable loyalty accounts, operational dependence, and critical-infrastructure status - makes aviation both attractive and high-consequence. In the GCC, with globally-significant carriers and mega-hub airports, it's a flagship, nationally-important sector, which is why it needs rigorous testing, not a checkbox.

// 02 What to test

01

Booking & payments

Reservation systems and payment flows - the passenger-data and money core, plus partner/GDS APIs.

02

Loyalty & miles

Frequent-flyer platforms - miles are money, so account takeover and points fraud are headline risks.

03

Check-in & mobile

Check-in, the mobile app, and passenger-facing web.

04

Airport & OT

For airports: passenger processing, baggage handling, and operational/building systems.

Across all of it: the web and API layers, the network and its segmentation between corporate, passenger-facing and operational zones, and the business logic of bookings, fares and loyalty points.

// 03 Operational technology - tested conservatively

Aviation includes safety-critical and operational systems - airport OT, baggage and building systems, and the specialised systems around flight operations - that cannot be treated like a web app. Testing these is weighted toward passive and read-only techniques - architecture review, configuration analysis, and above all IT-to-OT boundary testing - with any active testing agreed in advance and, where possible, run against a test environment or planned maintenance window. The corporate and passenger-facing IT is tested normally. The central question mirrors manufacturing and logistics: can an attacker who compromises corporate or passenger-facing systems reach the operational ones? Validating that segmentation - without disrupting a live airport or airline operation - is the core of the OT portion, handled with the same care we bring to any critical-infrastructure OT.

// 04 Regulatory drivers & how it runs

Aviation's testing drivers are layered. Data protection - the regional PDPLs or GDPR - governs the extensive passenger data; PCI DSS covers payment-card handling. As critical national infrastructure, airlines and airports commonly fall under national cybersecurity frameworks and civil-aviation-authority security requirements, with growing international attention (ICAO and regional regulators). In the GCC, national cyber security authorities and civil-aviation regulators set sector expectations. Even absent a single explicit mandate, the combination of passenger-data obligations, payment security, operational resilience and critical-infrastructure status drives regular testing. Engagements weight the data, loyalty and payment risks, treat OT conservatively, and map findings to the applicable regimes - manual-led, findings retested to closure, per our methodology.

// 05 Frequently asked questions

Why is aviation a target?

It combines large volumes of passenger personal and payment data, high-value loyalty programmes, safety-critical OT, and critical-infrastructure status. Airlines and airports hold detailed passenger records and process payments at scale; frequent-flyer points have real value and draw fraud and account takeover; operations depend on interconnected systems where disruption has outsized consequences. That mix makes aviation attractive and high-consequence for criminals and capable actors alike.

What should an aviation pentest cover?

For an airline: booking and reservation systems, payment flows, the loyalty/frequent-flyer platform, check-in and mobile apps, and partner/GDS APIs. For an airport: passenger-processing, baggage handling, and operational/building systems. Across both: web and API layers, network segmentation between corporate, passenger-facing and operational zones, and the business logic of bookings, fares and loyalty. Safety-critical OT is approached conservatively.

Is aviation OT tested differently?

Yes. Safety-critical and operational systems can't be treated like a web app. Testing is weighted to passive and read-only techniques - architecture review, configuration analysis, boundary testing - with active testing agreed in advance and ideally against a test environment or maintenance window. Corporate and passenger-facing IT is tested normally. The central question is whether an attacker can reach operational systems from IT, so segmentation is a major focus.

Which regulations apply?

Data-protection law for passenger data (PDPLs or GDPR), PCI DSS for cards, and - as critical infrastructure - national cybersecurity frameworks and civil-aviation-authority requirements, with growing international attention from ICAO and regional regulators. In the GCC, national cyber and civil-aviation regulators set expectations. Even absent a single mandate, passenger-data obligations, payment security, operational resilience and critical-infrastructure status drive testing.

// 06 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Tests airlines and airports across the GCC — booking, payments, loyalty, check-in and the IT/OT boundary — with passenger-data and miles-fraud focus and a conservative, passive-first approach to operational systems.

Airline or airport?

We test aviation across booking, payments, loyalty and check-in — and the IT/OT boundary that protects operational systems — with passenger-data and miles-fraud focus, mapped to your regulator.

Scope an aviation test → OT / ICS testing →