FAA faces electromagnetic spectrum security gaps, watchdog finds
by Mary McCue Bell · The Washington TimesThe Federal Aviation Administration’s protocols for screening certain cybersecurity risks are likely insufficient to properly respond to and prevent potential threats, according to a new report.
The agency does not have risk and mitigation assessments, security documentation and real-time monitoring capabilities to counter electromagnetic spectrum-related threats, including GPS spoofing and radio jamming, according to a report from the Government Accountability Office.
As a result, attacks could “disrupt aviation communications, degrade situational awareness, and increase the risk of operational disruptions,” said the report, released Monday.
Responsible for civil aviation safety oversight, the FAA provides air traffic service to more than 44,000 flights and 3 million airline passengers daily, relying on interconnected systems that use radio frequency signals across the electromagnetic spectrum for communication, navigation and surveillance.
If disrupted or attacked, flights could be hit with operational disruptions, air traffic control effectiveness could be eroded and passengers may be faced with significant flight delays.
More than 1,000 flights were canceled nationwide Monday and more than 6,000 were delayed due to a severed fiber optic line for a key air traffic control facility in Philadelphia. Transportation Secretary Sean Duffy said Monday night that the problem was fixed and that all airports in the Northeast were resuming normal operations.
While FAA has identified emerging spectrum-related cybersecurity threats, it has not fully implemented “key elements” of a risk-based cybersecurity program, the GAO report stated.
For seven of the eight spectrum-dependent National Airspace System networks GAO reviewed, FAA did not produce separate, detailed risk assessment reports because the agency “maintains a general spectrum risk assessment that addresses risks across systems,” according to the report.
Advertisement Advertisement
Moreover, FAA’s general spectrum risk assessment does not evaluate system-specific risks, meaning its reports do not include how specific threats and vulnerabilities affect individual systems.
Until the agency’s assessment looks at individual systems, the agency “may lack complete and reliable information to make risk-based cybersecurity decisions for critical NAS systems,” the report says.
“As a result, security weaknesses may go unidentified, inadequately assessed, or insufficiently mitigated, increasing the risk of disruption to aviation operations,” it reads.
CPDLC — the digital messaging system pilots and air traffic controllers use instead of radio — was built without encryption or authentication, meaning a bad actor with the right equipment could intercept messages or send fake instructions that look like they came from air traffic control, the report says.
Additionally, the FAA’s current cybersecurity collaboration with other federal agencies and aviation industry stakeholders lacks established procedures for information sharing, reporting and coordination with non-federal partners.
Advertisement Advertisement
Fully implementing leading collaboration practices could help the FAA avoid fragmented, inefficient responses to incidents, according to the report.
Incidents of satellite navigation system signal loss, including interference, space weather or onboard issues, have increased from 28.1 to 60.1 per 1,000 aircraft since 2021, according to a 2025 International Air Transport Association report cited by the GAO.
To combat risks, FAA and its partners are working together to detect and advise on jamming and spoofing, including working with industry to make detection and mitigation procedures available to pilots, the GAO report says.
The Department of Transportation, which oversees the FAA, said the agency is strengthening its risk assessment process and will seek to enhance outreach efforts across the aviation ecosystem.
Advertisement Advertisement
Contact the author
Mary McCue Bell
Follow author updates Follow Click to follow. Manage followed authors