Cyber security experts have warned the ongoing cyber-attack on several of Europe’s biggest airports highlights not only the threats faced by businesses but the fears that many are simply “sleeping at the wheel” when it comes to cyber security.
Tens of thousands of passengers across Europe have seen flights delayed and cancelled over the weekend and yesterday after the system provided by US software maker Collins Aerospace was attacked on Friday night resulting in disruption at s airports including Brussels, Berlin, London Heathrow and Dublin.
The systems affected control were the check-in and boarding which has left staff to look to manual operations which has caused delays and cancellations with the systems yet be fully restored yesterday morning.
Jeremy Samide, CEO, of 3D cyber threat visualisation platform provider Blackwired explained:
“To the uninitiated, the attack on the European airports this past weekend did not happen overnight. Hackers have been planning this assault for weeks, if not months.”
“Based on what we know today, those protecting critical infrastructure are, quite frankly, sleeping at the wheel.
“No matter how much technology the industry throws at the cybersecurity conundrum, we fail to understand and see the systemic problems that continue to face every organisation. Simply put, the industry is focused on the wrong approach. It is looking in the wrong direction, and this attack could have been avoided.
“The industry at large is built upon a bedrock of hardware and software that is designed to wait for an attack to hit – protecting a perimeter that doesn’t exist anymore.
“The threat actors today are taking advantage of this by doubling down on polymorphic malware and AI driven threats. When we see attacks like this, experience has proven that they know more about the target’s network and systems than those currently employed to defend it.
“Technology now exists whereby any organisation can visualise every external threat surrounding its environment. The ability to pinpoint and visualise adversarial development and movement has become critical in changing the legacy mindset of ‘detect and respond’ to a ‘predict, prevent and defeat’ mentality.”
He added: “This attack on the European airlines is a direct result of a critical supply chain attack downstream, where no one is held accountable. Having complete insight into the cybersecurity threat landscape of your supply chain is critical.
“Having the ability to acquire such intelligence exists on the market today through zero touch, non-invasive technology which means, no software or agents have to be installed – it is a case of “plug and play”.
“In summary, organisations need to embrace a ‘defend forward’ approach to cybersecurity or they will become the next victim. It’s time for the cybersecurity industry to stop sensationalising threat actors with cartoons, patting each other on the back for a job not well done and instead take the gloves off and fight fire with fire.”
David Mound, head of Research and Community, at Shinobi Security explained there was more that should and could have been done to protect their systems from attack.
“The disruption at Heathrow, Brussels and Berlin isn’t surprising – it’s a textbook supply chain attack,” he said. “The airports weren’t directly compromised, a weak link in their technology ecosystem was exploited, which is a stark reminder that security is only as strong as the most vulnerable vendor in your supply chain.
“More frequent penetration testing would almost certainly have helped. A once-a-year test is no longer fit for purpose when adversaries are probing 24/7. High-value targets like Collins Aerospace should face continuous red teaming and simulated supply chain attacks to expose and shut down entry points before they’re exploited.
“This is a systemic failure in third-party risk management, and it it’s no longer enough to accept a vendor’s security statement at face value. Airports must demand independent testing, adopt Zero Trust principles, and ensure vendors only get the minimum access required. Contingency plans also need to be sharper – manual check-in used to be a feasible work around, but the scale of disruption here showed a lack of preparedness.
“The aviation industry runs on an intricate web of legacy systems and providers, making it an inevitable target – but inevitability shouldn’t mean acceptance. Cybersecurity is not just an IT issue; it’s a critical business risk with global ripple effects. One breach has disrupted tens of thousands of passengers – if that doesn’t put cybersecurity on the boardroom agenda, nothing will.”
Supply Chains Built on Trust (and Blind Spots)
Firmware is no longer the quiet corner of the security stack. It’s the new battleground — a place where national security, corporate espionage, and cybercrime all intersect.
As long as firmware remains out of sight and out of mind, attackers will continue to exploit it with precision and patience. The question isn’t whether the supply chain can be trusted — it’s how quickly we can rebuild that trust, one line of embedded code at a time.
Firmware threats are notoriously hard to detect. Traditional endpoint protection operates at the OS level, leaving firmware activity unchecked. Security teams often lack visibility into BIOS or UEFI layers, and forensic tools aren’t always designed to analyze hardware-embedded code.
To make matters worse, firmware vulnerabilities don’t just affect PCs or servers — they extend to routers, cameras, industrial controllers, and the exploding universe of IoT devices. In other words: the attack surface is everywhere, and it’s mostly blind.
Mitigating firmware risk requires both cultural and technical shifts.
- Hardware attestation and integrity validation must become standard practice — not optional features.
- SBOMs (Software Bills of Materials) should expand to include firmware components, offering transparency down to the silicon.
- Vendor accountability needs to move beyond marketing claims; buyers should demand verifiable security documentation from every link in their supply chain.
- And perhaps most importantly, firmware updates must be automated, auditable, and enforced — because manual patching simply doesn’t scale.
It’s 2025, and somehow, we’re still talking about firmware. The invisible layer of code that quietly powers every device—from routers and servers to coffee machines—remains one of cybersecurity’s most persistent weak spots. Firmware sits in an awkward middle ground: too low-level for IT to patch regularly, too critical for manufacturers to ignore. But the truth is, most do. Vendors often bake firmware into devices and then walk away—leaving millions of endpoints running outdated, unpatched code.