French Hill

08/17/2026 | News release | Archived content

RELEASE: REP. HILL AWARDS GOLDEN FLEECE TO FAA AND TSA FOR GAPS IN CYBERSECURITY

Rep. French Hill (AR-02) today announced that the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA) are the latest recipients of his Golden Fleece Award for recently identified shortcomings in their oversight of aviation cybersecurity risks.According to GAO, nearly 44,000 flights carrying 3 million passengers fly the skies of the United States every day. As aviation systems become increasingly connected, protecting avionics and ground systems from cyber threats is essential to maintaining the safety and reliability of America's aerospace.

Rep. Hill said, "Air travel is an essential part of American life and critical to the economic health of our nation. It's imperative that passengers, as well as pilots and flight attendants, have confidence that we're doing everything in our power to make sure they take off and land safely. Guarding the cyber systems that keep our nation's aviation infrastructure protected is a major part of that effort. While the FAA and TSA have taken steps to address cybersecurity challenges, gaps remain that require continued attention. Federal agencies responsible for keeping our planes flying must ensure they have defined responsibilities and effective risk management practices in place."

In his letter to Federal Aviation Administration Chief Information Security Officer Gina Fisk, Rep. Hill writes:

Dear Director Fisk,

I write to inform you that the Federal Aviation Administration (FAA) and the Transportation Security Administration (TSA) are the latest recipients of my Golden Fleece Award for shortcomings in their cybersecurity strategies. Nearly 44,000 flights and 3 million passengers travel through the National Airspace System (NAS) each day, underscoring the need for robust cybersecurity as avionics and ground systems become increasingly interconnected.

Between 2020 and 2025, the aerospace sector reported nearly 2,000 cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency (CISA). These incidents highlighted vulnerabilities such as inadequate software patching, internet-accessible operational technology, outdated software, vulnerable remote services that could enable unauthorized access to avionics, and ground systems or manipulation of critical information.

The Departments of Transportation (DOT) and Homeland Security (DHS) share responsibility for overseeing cybersecurity risk across America's transportation sector. Their authorities are established through federal statutes, including Federal Information Security Modernization Act (FISMA), the FAA Extension, Safety, and Security Act of 2016, and the FAA Reauthorization Act of 2024. The National Institute of Standards and Technology's (NIST) Cybersecurity Framework (CSF) 2.0 further provides guidance for managing cybersecurity risk and transitioning to a Zero Trust architecture.

While the FAA's cybersecurity strategy clearly defines agency roles and responsibilities, comparable TSA planning documents do not. For example, the TSA Strategy for 2018-2026 does not explicitly establish cybersecurity-specific goals or objectives to support aviation security. Moreover, it is no longer fully aligned with DHS's broader cybersecurity strategy. Other planning documents, including Administrator's Intent 3.0 and the 2018 TSA Cybersecurity Roadmap, similarly lack clear objectives and fail to define TSA's roles and responsibilities for overseeing airport and aircraft cybersecurity programs.

These documents also do not clearly identify the offices responsible for implementing their stated goals and objectives. Although Administrator's Intent 3.0 directed TSA to update its cybersecurity roadmap between 2018 and 2026, the agency has yet to do so.

The absence of clearly defined cybersecurity roles has contributed to confusion among manufacturers, airlines, and other aviation stakeholders regarding TSA's cybersecurity responsibilities. Although FAA has defined its role, greater interagency clarity would strengthen coordination across the aviation sector.

The Office of Management and Budget (OMB) requires agencies to report cybersecurity expenditures through the Cyber Budget Data Request process to inform the President's budget. However, FAA did not report complete information on its Information Security/Cybersecurity Program because it was not required to report all cybersecurity spending. Consequently, the Administration and Congress could lack a complete understanding of the agency's cybersecurity investments, including research and development activities.

While the FAA's Cybersecurity Strategy aligns with several federal Zero Trust practices, it does not fully align with NIST's Zero Trust Architecture guidance. The strategy fully aligns with only three of seven identified practices, and partially addresses the remaining four. Full implementation is necessary to effectively manage cybersecurity risks.

I appreciate the FAA's efforts to implement federal and industry best practices to mitigate cybersecurity vulnerabilities affecting avionics and ground systems. The FAA must continue implementing its cybersecurity posture to ensure the safety, security, and resilience of the National Airspace System.

If additional statutory authority is necessary to address these concerns, I encourage you to notify me promptly. I also welcome any technical assistance the FAA can provide to assist Congress in addressing these issues. Thank you for your attention to this matter.

Sincerely,

French Hill
Member of Congress

French Hill published this content on August 17, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 25, 2026 at 19:12 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]