
by Bert Archer
Last updated: 9:15 AM ET, Fri February 28, 2025
Day 2 at the World Data Symposium, organized by IATA and hosted by Aer Lingus, was all about danger.
It started out with a talk called Implementing Zero-trust to Reduce Attack Surface. Filled with phrases borrowed from more worrying realms, like “blast surface” and “attack radius,” the people in charge of cybersecurity for IATA and Lufthansa swapped stories from the trenches of the fight against cyber attacks. “Zero trust” is the new byword in the industry, which boiled down to layman's terms means no online interaction can be safely executed unless no facet of it has been trusted at any point.
They spent a good deal of their time talking about the sorts of interactions that happen behind the scenes in the aviation industry, between developers and contractors, airport workers and airlines. But according to Lufthansa’s head security architect, Martin Schkopke, “The passenger journey is one of the most challenging parts of it.”
“It’s a big question for sales and marketing,” Schkopke told TravelPulse Quebec, “because basically they still see two-factor authentication as an obstacle to ease of use.”
They’re not wrong.
So it looks like booking tickets will get more complicated before it gets easier. Which may be good news for travel advisors.
They mentioned the SolarWinds attack, which most of us outside the IT world will have forgotten about by now, or never known about in the first place, as a major milestone on the way to the culture of fear that now permeates their world. It's no longer just the network, or the internet that’s fraught, said Conner Hagan, IATA’s senior cloud security architect, “but all of the software running on it.”
Talk then turned to more easily understandable danger: the kind that damages and crashes planes.
According to data collected by IATA and analyzed by Cathay Pacific for this talk, accidents occur for 10 basic reasons, with “runway excursions“ - planes running off the end of the runway – coming in at number 1, accounting for 22%, followed by landing gear not deploying or collapsing 16%, hard landings 10%, loss of control in flight 8%, and so-called “off-runway touchdowns” 4%, among others.
The good news here was that where the cybersecurity talks all seemed to be about limiting damage from inevitable attacks, the data collected around physical incidents involving planes was very much about preventing anything serious from happening at all.
And there’s a lot of data. Literally billions of second-by-second digital data points are registered, in addition to thousands of human reports of incidents that range from significant to minor to insignificant, all of which is analysed and used to minimize risk.
As the moderator, Montrealaise Chantal Berthiaume, IATA’s director of OSS business systems and performance, pointed out, this kind of data collection is all about the kinds of incidents nobody hears about, in aid of preventing the kinds that people do.
Not all heroes wear capes: some just walk softly and carry very big spreadsheets.
Topics From This Article to Explore