2016年-普华永道全球_Aviation_Perspectives_Volume_43_-_Cybersecurity_detection_8页_3mb
报告摘要
Aviation Perspectives: Cybersecurity and the Airline Industry - Detection
Core Content
This document is part of a four-part series on cybersecurity in the airline industry, focusing on detection as a critical component of a comprehensive cyber defense strategy. It highlights the increasing frequency and sophistication of cyber threats targeting the aviation sector, emphasizing the need for proactive and intelligent detection mechanisms.
Main Objectives
- Early Detection: Identifying threats as soon as they begin to minimize damage.
- Operational Readiness: Establishing clear processes to respond to cyber incidents.
- Interconnectedness Management: Addressing the risks posed by the extensive and complex network of stakeholders and systems in the airline industry.
Key Points
Importance of Early Detection
- Cyber threats are inevitable, and the focus is now on when rather than if.
- Advanced threat actors often remain undetected for 6-18 months, allowing them to map systems and exfiltrate data.
- Early detection is essential to limit damage and prevent further attacks.
Challenges in Detection
- Lack of holistic monitoring: Many organizations do not have the tools or processes to detect threats effectively.
- Data correlation issues: Current tools often only perform basic pattern matching and fail to integrate data across systems.
- Evolving threats: Attackers continuously adapt, making detection protocols difficult to keep up with.
- Insider threats: These are often harder to detect and more costly to resolve.
- Financial constraints: Detection efforts are typically harder to fund than preventative measures like encryption.
Solutions for Effective Detection
- Comprehensive network coverage: Airlines should ensure full visibility across all network, data, and endpoint activities.
- Establish baselines: Define normal data transmission patterns to identify anomalies quickly.
- Employee training: Educate staff to recognize and respond to suspicious behaviors.
- Asset prioritization: Focus detection on high-value assets such as passenger data and operational systems.
- Internal and external collaboration: Develop cross-functional response processes and share threat intelligence with industry peers and external stakeholders.
- Invest in advanced tools: Use state-of-the-art detection technologies, especially cloud-based solutions, to provide real-time updates and dynamic defense capabilities.
- Build scalable defenses: Ensure detection systems can adapt to new threats and technologies.
- Address capability gaps: Expand monitoring coverage and establish a dedicated operations center for continuous cyber monitoring.
Cyber Detection in the Airline Ecosystem
Airlines face unique challenges due to their interconnected and dispersed nature. They must manage:
- Customer and Commercial Systems: Including payment platforms, loyalty systems, and global distribution systems.
- In-Flight Systems: Such as in-flight shopping, entertainment, and connectivity.
- Cockpit Systems: Including navigation, weather, and electronic flight bags.
- Airport Systems: Asset tracking, refueling, and vendor management.
- Operations Systems: Crew management, baggage handling, and maintenance.
- Corporate Systems: Human capital, finance, email, and data analytics.
The interconnectedness of these systems increases the risk of multi-point penetration and data leakage, making detection even more complex.
Investment Trends
- Proactive investment: Airlines are increasingly investing in cyber detection programs, with 91% planning to do so over the next three years.
- Improved preparedness: The percentage of airlines feeling prepared for common cyber threats has risen from 17% in 2013 to 48% today.
Conclusion
Detection is a moving target in the airline industry, requiring intelligent tools, collaborative processes, and continuous improvement. With the growing complexity of the airline ecosystem and the increasing frequency of cyber threats, detection is not just a defensive measure but a strategic necessity.
Next Part
The next part of the series will focus on reacting effectively to cyber attacks, including incident response and minimizing damage to customers, operations, and reputation.
Contacts
For more information or to discuss further, contact:
PwC Airline Specialists:
-
Jonathan Kletzel
+1 (312) 2986869
jonathan.kletzel@pwc.com -
Alexander T. Stillman
+1 (202) 487 8086
alexander.t.stillman@pwc.com -
Rajeet Mohan
+1 (305) 375 6239
rajeet.mohan@pwc.com -
Bryan Terry
+1 (678) 419 1540
bryan.terry@pwc.com -
Richard Wysong
+1 (415) 498 5353
richard.wysong@pwc.com
PwC Cybersecurity Specialists:
-
Charles Beard
+1 (703) 918 3318
charles.e.beard@pwc.com -
Rik Boren
+1 (314) 2068899
rik.boren@pwc.com -
Mickey Roach
+1 (214) 756 1635
mickey.roach@pwc.com -
Mir Kashifuddin
+1 (214) 754 4537
mir.kashifuddin@pwc.com -
Darren Orf
+1 (312) 298 5072
darren.c.orf@pwc.com -
Vincent Scott
+1 (513) 768 6397
vincent.h.scott@pwc.com
For general inquiries, contact Diana Garsia at +1 (973) 236 7264 or diana.t.garsia@pwc.com.
Visit pwc.com/us/airlines or follow us on Twitter @PwC_Aviation.
试读结束,高清完整版pdf/doc/ppt,请点下载