See Full Document Text
GOVERNMENT OF INDIA
MINISTRY OF CIVIL AVIATION
RAJYA SABHA
UNSTARRED QUESTION NO : 968
th
(TO BE ANSWERED ON THE 9 February 2026)
STEPS TO PREVENT CYBER THREATS TARGETING AVIATION
INFRASTRUCTURE
968. SHRI JOSE K. MANI
Will the Minister of CIVIL AVIATION be pleased to state:-
(a) whether Government has assessed vulnerabilities in airport digital systems,
airline reservation networks, and aircraft communication systems, and if so, the
details thereof;
(b) whether any recent incidents of cyber intrusion or data breaches have been
reported in the civil aviation sector during the last three years, and if so, the details
and corrective actions taken thereof; and
(c) the measures that are currently in place to prevent and respond to cyber threats
targeting aviation infrastructure, including air traffic management systems and
passenger data platforms?
ANSWER
MINISTER OF STATE IN THE MINISTRY OF CIVIL AVIATION
(Shri Murlidhar Mohol)
(a) to (c): No cyber intrusion or data breach incidents have been reported in the last
three years in the Civil Aviation Sector. The airport/airline operators continuously
assess and identify security vulnerabilities, architectural weakness and control gaps
across their systems and any issues identified are fixed quickly.
Further, the following measures are currently in place to prevent and respond to
cyber threats in the aviation sector:
(i) Bureau of Civil Aviation Security, the aviation security regulator in the country
has issued Guidelines for the protection and handling of sensitive aviation security
data in the Aviation Sector.
(ii) National Critical Information Infrastructure Protection Centre (NCIIPC)
provides continuous threat alerts, based on which remedial actions are taken inaccordance with the NCIIPC and Indian Computer Emergency Response Team
(CERT-In) guidelines.
(iii) Cyber security audit from the CERT-IN empanelled agency is being conducted
for air traffic management systems at major airports.
(iv) Multi layered cybersecurity controls, including firewalls, web application
firewalls (WAF), and DDoS protection, are implemented by Airport Operators and
Airline Operators to protect their IT and operational systems. These measures
include access controls, network segmentation, continuous monitoring, incident
response procedures, data protection controls for passenger information, and
regular security assessments.
*****