Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

Adam Dudley
October 8, 2026
Industry Perspectives
Plan flying through tech icons illustration

The first Aviation ISAC summit, a little over a decade ago, was about forty people in a room in Miami, hosted by the Health ISAC. This year’s conference in Vancouver hosted more than five hundred: airlines, airports, OEMs, suppliers, and government, all in one place for three days. Many in the audience were new to the conference. One of the opening speakers asked first-timers to raise their hands, and a lot of hands went up around the room. 

I was there to moderate a panel on building airline vulnerability management programs. Several major airlines run those programs on Nucleus, which means we spend a good part of our year listening to this industry, and I still came home with more notes than I expected.  

What follows here is what stood out in those noes and mattered most to me, including a keynote on resilience that has more to do with vulnerability and exposure management than it first appears. 

Just a quick note: To honor the A-ISAC’s commitment to openness and information sharing, I’ve intentionally left many individual and company names anonymous in this recap. 

Every Accepted Risk Was Priced for a Slower AttackerΒ 

The line that stuck with me came from the opening panel, from a security leader at a major airline. Every company has a pile of risks it accepted years ago. Those acceptances were based on assumptions about likelihood. In a world where frontier AI makes exploitation cheap and fast, those assumptions are no longer valid, and most of the register has never been reopened. 

He borrowed a line from a former White House adviser to make the point: don’t get caught up in probability. Everything they dealt with was improbable, right up until it happened. That is where we are with AI-enabled attacks. The things we filed under unlikely are going to happen all the time. 

The same speaker made a second point that I think is the real opportunity. For the first time in a decade, boards and executives are paying attention. The hygiene work that has been kicked down the road, the decommissioning, the trade-off conversations nobody wanted to have, can actually get done right now. The window is short. The gap between open models and frontier models is now measured in months, not years. If you have been waiting for air cover to fix the boring stuff, this is it. 

Detection Speed Is Worthless Without Decision RightsΒ 

There isn’t much point in detecting something within seconds if it takes an hour or two to find the person with the authority to act on it. Shutting down or quarantining an engineering system that is critical to operations, taking down a ticketing platform: those decisions need a named owner, and clear safety and operational boundaries, before the incident. Not in the heat of it. 

I have sat through a lot of conversations about ‘mean time to detect.’ This was the first time in a while I heard someone put β€˜mean time to authority’ on the table, and I think it is the number that matters at AI speed. 

The Foundations Are Fragile Because Nobody Controls the Whole JourneyΒ 

An airline can run excellent controls and still be taken down by a shared network, an airport system, or a specialist supplier. The passenger never sees those boundaries. They just see flight delays, cancellations, and broken plans. 

One operator described about fifty years of technology end-to-end across their customer journey. Some of the oldest systems are also the most resilient, which is often why they are still there. The fragility came later, as the industry digitized by stacking digital services on top of digital services, and every layer added a dependency. 

The resilience test that followed is the one I keep repeating. Confidence comes from what you have tested, not what you have put in place. Plenty of teams have exercised their own runbooks. Far fewer have exercised them with the airport, the network provider, and the supplier they would actually be calling at two in the morning. If the definition of cyber resilience is withstanding incidents while essential services keep running, and restoring them quickly when they don’t, then the test must include the organizations you depend on. 

The advice that came with it was simple. Build the relationships before you need them. 

An ATT&CK-style Framework Built for AircraftΒ 

One of the more technical sessions covered ASCENT, an aviation-specific threat framework being built by a working group of operators, OEMs, and suppliers. The problem it solves is familiar to anyone who has tried to threat model a system that doesn’t look like an enterprise network. MITRE ATT&CK applies in places and not in others. Teams spent their time tearing it down and rebuilding it for data loaders, ground systems, and onboard domains instead of doing the actual risk assessment. 

Rather than reinvent anything, the group mapped across existing frameworks: ATT&CK for ground IT, SPARTA for the satellite and space pieces, the automotive matrices for things like compromised radio and cellular signals, and the aircraft domain model from ARINC 664 Part 5 and ARINC 811 (the Aircraft Control Domain, the Airline Information Services Domain, the Passenger Information and Entertainment Services Domain, and passenger-owned devices), plus a ground systems domain.  

The finding after phase one, spanning a year and a half,  was that the tactics barely change. As one presenter put it, sideways is sideways. The work is in the techniques, and in deciding which domains each one applies to and what the impact looks like when the target is flight controls rather than a seatback screen. 

The piece I liked most is the wiki of threat scenarios attached to the matrix. Instead of a theoretical list of what could happen, the goal is observables: things that have shown up in the news, in research, or in incident data, mapped to the techniques, so an end user can start from a realistic scenario and work down to mitigations and detections. Next year is about operationalizing it and moving to a continuous sustainment model. If your program includes anything that touches an aircraft or the systems that load data onto one, it is worth getting involved. 

AI for OT Risk Assessment, Done Low and SlowΒ 

A panel of practitioners from two airlines, an OEM, and a baggage-handling integrator walked through using generative AI to replace manual, reactive risk assessments on operational technology. The OT reality framed everything: 20-30 year equipment life spans, 24×7 availability requirements, Windows XP and Windows 7 on human-machine interfaces (HMIs), default and shared passwords, open USB ports, and vendors with standing remote access because they own the machine. 

The method was more mature than I expected. Telemetry from four domains (user, network, file integrity, and ports, protocols, and services) feeds a weighted risk score. Instead of one monolithic prompt, the team wrote a prompt per weakness class and grounded each one with retrieval from their own remediation playbooks and assessment instructions. A subject matter expert reviews the ratings, corrects the ones the model gets wrong (an internet-exposed remote admin service rated critical, agreed; broad vendor reach into multiple HMIs rated high, should be critical), and the next pass learns from the correction. 

Two lines from that session belong on a wall somewhere:  

  • “AI doesn’t make bad data better.” It makes it a whole lot worse, and turns it into a bigger problem than the one you were trying to solve. One analyst described asking the model for a device count, getting eight, and knowing from experience the real number was over 4,000.
  • β€œThe teams getting real value from it started with asset visibility, governance, and operational context,” and are deliberately going low and slow until that foundation holds.Β 

The operational context point is the one I would underline for anyone running vulnerability management in a mixed IT and OT environment. A critical finding on an HMI running Windows XP in the underbelly of an airport might sit behind sixteen physical controls that no attacker will ever get through. Or it might be one of the controllers you can find exposed on the internet with a free search engine, which one panelist noted he could shut down from his colleague’s laptop in minutes. The score doesn’t know the difference. The person who walks the floor does. Risk belongs to the asset owner, and the assessment must be weighted by location, by system, and by what the business loses when that system stops. 

The Keynote on Resilience That Was Really About MarginΒ 

Adam Markel, a resilience researcher and author of Change Proof, gave the keynote. I’ll admit I walked in expecting something I could skip. I was wrong, and the reason is a single idea he kept returning to.Β 

He asked the room to define the term margin. Everyone said profit. He asked us to think of it instead as the space between our load and our limit, then pointed out that most of us are not running at 80% with room to spare. We run at 98% or 99%. His research, much of it with people in industries like ours, says that lack of space shows up directly as more mistakes, more issues, and more breakdowns per hundred employees. 

That is a remediation capacity problem described in human terms. Every vulnerability and exposure management program I’ve seen struggle was struggling for the same reason: the people fixing things were already at their limit before the next scan ran. The airline programs running through Nucleus are some of the largest and most complex we see; the ones that work have been deliberate about this. Fewer findings reaching people, better prioritized, with the context already attached, is how margin gets built back into a team that has none. 

His second idea cut against the model most security teams run on. Resilience is not endurance. The Rocky version, where you get knocked down and keep getting up, loses the fight. The research he cited on Olympic athletes and leaders in complex roles found one thing in common, and it was not grit. It was rituals for recovery: mental, physical, emotional, and all of it scheduled. His example was an Iditarod musher who stops her dogs every four hours, before they are tired, because preventing exhaustion is easier than recovering from it. Stress is not the problem. Stress is required to grow. The problem is the absence of recovery from it.Β 

He also put a number on something every incident commander knows. When emotion goes up, intelligence goes down by as much as 13 IQ points. A pause before the decision is not a soft skill. It is a control. His practical version was a few minutes of nothing; a breath held at the top, a walk before the reply gets sent. The Navy SEALs use the same breathing technique for the same reason. 

The line I wrote down verbatim came from a retired engineer he quoted: “When it comes to change, it is never a technical problem. It is a people problem.” Technology doesn’t resist change. People do, because we learned early that being wrong has consequences. The thing we already know feels safer even when we know it is not optimal. Anyone who has tried to move a vulnerability program from severity-first to risk-based prioritization has lived that sentence.Β 

I am not going to tell a security operations team to put their legs up the wall in an airport. Markel does, and he is probably right. What I took from the keynote is narrower. Margin is a design decision. A team with no space between load and limit will accept risks it shouldn’t, miss the 4,000 devices the model said were eight, and make its worst decisions at the exact moment it needs its best ones. 

The Panel: My Original Reason for AttendingΒ 

I moderated “Building Airline Vulnerability Management Programs: Turning Strategy into Scalable Exposure Reduction” with Nicole Calvert, Director of Vulnerability and Cyber Asset Management at United Airlines, Dan Davis, Director of Digital Risk and Resiliency at United Airlines, and Jacob Teague, Senior Vulnerability Management Analyst at Southwest Airlines. Three people who run these programs for real, with real fleets and real schedules behind them. 

Nucleus moderated panel at Aviation ISAC Summit

Moderating is a strange seat. You spend the hour listening for the next question instead of writing down the answers, so I came off stage with a clear sense of the conversation and almost no notes. What I can say is what the title promised and what I went in to ask about: not the strategy, which most programs have, but the part where it has to scale across a fleet, a schedule, and a team with a limit. The threads that ran through every other session I attended were the lens I moderated through. The specifics are theirs to tell, and I hope they do. 

The question in the panel title, how a strategy on a slide becomes measurable exposure reduction at scale, is one I hear every week. Nucleus sits at the center of the vulnerability and exposure management programs at major airlines, which is where every scanner, asset inventory, and threat feed lands before a finding becomes someone’s work. From that seat, the pattern is consistent. The programs that scale have settled who can act, what data they trust, and how much capacity they have. The ones that stall are usually missing one of the three. 

What I’m Taking Home from Aviation ISACΒ 

Risk acceptance has a shelf life, and AI just shortened it. The register your organization signed off on in 2022 or 2023 was priced for an attacker that no longer exists. Reopening it is not a tooling project. It needs decision rights that are settled before the incident, asset data that is good enough for a model to reason over, and enough margin on the team that the people doing the work can still think. 

The aviation community has a head start on this because it has spent more than a decade learning to work across competitors. Build the relationships before you need them and go reopen the register.

Adam Dudley
Adam is VP of Strategy and Alliances at Nucleus Security, working closely with the company's partners and integrations. Adam is also proudly the company's longest-tenured non-founding employee.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.