In recent days, frequent travellers witnessed something that once seemed unthinkable: check-in and baggage drop systems brought to a standstill at some of Europe’s largest airports, including Heathrow, Brussels and Berlin. The cause was neither a storm nor a strike, but a cyberattack against Collins Aerospace, a critical technology provider to airlines and airports worldwide.
Highly digitalized processes suddenly returned to pen and paper. Passengers faced endless queues, while flights were delayed, cancelled or diverted, resulting in millions of euros in direct and indirect losses. It was a wake-up call: global aviation, one of the world’s most interconnected and technology-dependent sectors, proved vulnerable to a single point of failure within its supply chain.
What this attack teaches us
Supply chains are only as strong as their weakest link. Airports and airlines depend on external technology solutions for critical operations. Reservation systems, baggage check-in, air traffic control and maintenance all rely on specialized providers. When one provider suffers an attack, the entire ecosystem is affected. Industry leaders must recognize that cybersecurity management no longer ends at the boundaries of their own organizations. The security posture of the entire supply chain must be audited, assessed and continuously monitored.
Operational resilience is not optional. Contingency plans were only partially effective. Resorting to manual processes demonstrated adaptability, but also exposed a lack of robust digital redundancy. In an increasingly digital sector, operational continuity must be planned according to its strategic importance. The question is simple: in the event of disruption, do we have independent, redundant systems capable of maintaining operations?
Passenger trust is a fragile asset. In air travel, trust is closely associated with punctuality and predictability. An incident of this nature undermines the sector’s image of safety and reliability. The issue goes beyond immediate financial losses. It also affects reputation—the most difficult asset to rebuild.
Where NIS2 comes in
The NIS2 Directive, which entered into force in 2023 and must be implemented by EU Member States, is more than a legal document. It is a survival guide for critical sectors such as air transport.
In light of this incident, the analysis should focus on four essential areas:
- Supply chain management (Article 21 of NIS2): Critical ICT providers must be audited, certified and monitored. Trust alone is not enough; organizations must verify.
- Business continuity plans: Manual processes cannot be the primary plan in 2025. Digital redundancy and parallel systems are essential.
- Incident reporting (24 hours / 72 hours / one month): Rapid and structured communication with national and European authorities must receive the same priority as physical security.
- Management accountability (Article 20): Cybersecurity is no longer solely a technical matter. Boards of directors must be involved, informed and prepared.
Leaders who approach these requirements as an opportunity will gain a competitive advantage. In a sector where minutes translate into millions, operational resilience will become the new hallmark of trust.
The executive perspective: from obligation to competitive advantage
Implementing NIS2 should not be viewed solely as a regulatory burden. For airports, airlines and technology providers, resilience is a market differentiator.
In a sector where delays of only a few minutes can cost millions, demonstrating the ability to withstand cyberattacks and maintain continuous operations may become a decisive factor in attracting passengers and partners. More than avoiding fines – which can reach up to 2% of global turnover – implementing NIS2 means investing in passenger trust, operational efficiency and a strong international reputation.
