Protecting Critical National Infrastructure in a Connected World
15 Sep 2026
What Recent Airport Incidents Reveal about Cyber Resilience
In late August 2026, the operator of a major UK airport group confirmed an unauthorised threat actor had gained access to systems holding data on more than 8 million customers across the airports it manages. Email addresses, phone numbers, vehicle registrations and postcodes had been pulled from car park booking systems, lounge sign-ups and the free Wi-Fi passengers log into. The incident did not affect payment card information, banking details or passport data held on the impacted system. Airline operations were unaffected, and passengers were not exposed to any direct safety risk. The UK National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) were both informed, and affected customers received emails warning them to be aware of phishing and malicious activity.
The incident raises wider questions about the resilience of aviation systems, and of other organisations that depend on complex technology. Airports are increasingly central to cybersecurity discussions because they combine critical infrastructure with highly interconnected digital ecosystems.
There Is a Precedent for This
In September 2025, a cyber-attack hit a major supplier of airline check-in and boarding software used by several of Europe’s busiest airports. The airports themselves were not directly compromised; the attackers only needed to breach one shared supplier. Within days, three major airports were handwriting boarding passes and baggage tags, while one temporarily cancelled many outbound flights. The EU’s cybersecurity agency later confirmed the breach as a third-party ransomware incident.
Viewed together, these incidents point to a wider trend. One involved a direct breach of an airport operator’s customer-facing systems; the other stemmed from a supply chain compromise affecting a shared supplier. But the challenge is not confined to aviation. Across every sector, the attack surface now extends beyond core operational systems to include customer-facing services, parking platforms, Wi-Fi networks, loyalty programmes, cloud environments and a growing network of third-party applications and suppliers. In aviation, these systems are integral to the wider airport ecosystem, but similar dependencies exist in other critical sectors such as food, healthcare, finance, and energy. Each interconnected service creates another potential route for threat actors, often without requiring them to target critical operational systems directly.
The Gap Between Assessments and Adversary Behaviour
Most organisations can produce a tidy set of policies, security architecture diagrams, training completion rates and last year’s penetration test report covering a handful of applications or tightly scoped systems. What fewer can honestly say is: “we know what happens when a skilled, motivated adversary targets us using the same tools, patience and creativity as a real threat actor.”
That is the difference between vulnerability assessment and red teaming, and it is one that incidents like these continue to publicly expose.
A vulnerability assessment shows where weaknesses exist; red teaming, or threat-led penetration testing, shows what could happen if a determined attacker exploited them. It tests whether a threat actor could gain access, move through an environment, evade controls, reach critical systems or data, and achieve their objectives using tactics, techniques and procedures (TTPs) associated with real-world adversaries.
Crucially, the exercise is not solely about identifying vulnerabilities, it is also about evaluating the effectiveness of an organisation's detection and response capabilities. For example, security teams may successfully detect certain stages of an attack but fail to identify others, highlighting opportunities to refine monitoring, alerting, processes and technologies. Understanding what was detected, what was missed, and why helps organisations better align their people, processes and controls to strengthen their overall security posture.
This goes far beyond compliance. It gives organisations the chance to find and fix security gaps on their own terms, in a controlled and realistic way, before a real threat actor can exploit them.
Other high-stakes sectors, especially financial services, have already formalised this kind of testing: threat intelligence-led, live-environment exercises against critical systems, with intelligence teams profiling realistic adversaries before the red team exercise begins. Aviation and other critical national infrastructure (CNI) operators don't need to invent this from scratch. They need to apply the same discipline: intelligence-led scoping that emulates the attack profiles, objectives and methods of threat actors relevant to their sector, while exercising the full kill chain from initial access through to how people and processes respond.
Moving Cybersecurity into the Boardroom
Organisations that manage cyber risk most effectively tend to share several common characteristics:
- Cybersecurity is no longer treated as a purely technical concern. It is considered at board level alongside financial, operational and regulatory risk, with senior leaders expected to understand the organisation's exposure and the potential business impact of a cyber incident. This reflects a broader regulatory direction of travel, including guidance from the UK's National Cyber Security Centre and the UK Government, which has repeatedly emphasised that cyber risk is a board-level responsibility and that effective cyber resilience requires active leadership and oversight from the top of the organisation.
- Supply chain security is scrutinised meaningfully, supported by contractual security requirements, ongoing assurance, and the ability to quickly determine whether the organisation is affected when a key supplier suffers a security breach.
- Technical environments are designed for resilience, with appropriate segregation between customer-facing services, business systems, and critical operational or financial assets. This helps ensure that, if a compromise occurs, its impact can be contained and prevented from escalating into a wider organisational incident.
- Incident communication and disclosure processes are actively prepared and tested, supported by regular incident response exercises, so organisations can meet tightening regulatory reporting obligations and respond to growing stakeholder expectations for transparency.
- Mature organisations also recognise that a data breach is rarely the end of an incident. Instead, it often marks the beginning of a period of heightened risk, during which phishing, social engineering and impersonation attacks are more likely to occur. As a result, they monitor for secondary threats and adapt their defensive posture accordingly.
- Importantly, organisations do not assume their controls, processes and technologies are effective. They test them. Through activities such as red teaming and threat-led penetration testing, they validate not only whether an attacker could gain access, but also whether security teams can detect, respond to and contain malicious activity effectively. This provides valuable insight into what was detected, what was missed, and where monitoring, alerting and response processes can be improved. The outcome is not simply a list of vulnerabilities, but a clearer understanding of how people, processes and technology work together under realistic attack conditions, helping organisations continuously strengthen their overall security posture.
Intertek helps businesses and government bodies validate the security of emerging technologies through threat-led penetration testing and consultancy services. Whether assessing AI implementations, conducting red team exercises that simulate real-world attack scenarios, or securing IoT and OT environments, our experts help identify weaknesses before they can be exploited. The result is a stronger security posture that enables innovation without introducing unnecessary risk.