The 9/11 lesson cybersecurity has yet to learn
Twenty-five years later, as cyber threats increasingly target systems that support critical infrastructure, cybersecurity faces a similar challenge: how do we build systems resilient enough to withstand the failure of any single layer?
The 9/11 terrorist attacks changed how our nation thinks about security. Nowhere was this change more visible than in aviation, with the creation of the Transportation Security Administration and the development of multiple layers of security designed to protect air travelers.
That lesson extends beyond aviation. Twenty-five years later, as cyber threats increasingly target systems that support critical infrastructure, cybersecurity faces a similar challenge: how do we build systems resilient enough to withstand the failure of any single layer?
The challenge is especially apparent as the Cybersecurity and Infrastructure Security Agency prepares to finalize its sweeping Cyber Incident Reporting for Critical Infrastructure Act rules in September. Washington continues to miss the broader lesson of systemic resilience.
Federal policy focuses heavily on mandatory breach reporting, yet reporting a crisis does not prevent one. Paradoxically, although TSA aggressively expands its own cybersecurity mandates across transit networks , the agency’s greatest lesson in systemic design continues to be overlooked. Digital defense frameworks remain dangerously tethered to centralized, single points of failure. True digital resilience requires less focus on compliance checklists and more on independent, multi-layered structures modeled on aviation security .
As the world learned during the CrowdStrike outage in July 2024, destruction does not always require bad actors. What began as a routine software update to around 8.5 million computers instantly crippled airlines, banks and hospitals worldwide, causing billions of dollars in damage . It wasn’t a cyberattack; it was digital “friendly fire.” Two months later, when a CrowdStrike executive testified before a congressional subcommittee, the central question wasn’t just what went wrong, but how our critical infrastructure became so fragile .
The answer lies in how digital systems are designed.
Our ever-expanding digital world was built upon a global technological monoculture — millions of organizations rely on the same vendors for system access. To fix our digital vulnerability, we need to look at one of the most visible, highly criticized, yet ultimately successful security systems in our nation: aviation security .
To the average traveler, the TSA can feel like “ security theater.” But beneath the inconvenience lies a strategy that balances risk-based resource allocation with a multi-layered defense . Just as the agency partitions off low-risk passengers to focus more attention on unknown threats, digital defense must use automation to filter out routine automated attacks, freeing human analysts to target sophisticated vectors.
However, filtering alone is not enough; it must be paired with the “Swiss cheese” model of defense: multiple independent layers of security tactics . Today, the TSA uses AI tools like Credential Authentication Technology using facial recognition (CAT-2) for identity verification across its checkpoints, alongside invisible tactics like federal air marshals on airplanes .
Every single one of these layers has flaws. “ Red Teams ” acting as undercover testers routinely slip banned items past checkpoints. But here is the secret: the system is designed to absorb local failures. Independent layers means that a breach at the checkpoint does not compromise the air marshal or the hardened cockpit door on the plane. Together, these flawed sheets of “Swiss cheese” overlap to form a system that is more resilient than any single layer.
With cybersecurity , digital defense strategies claim to use layers . But those layers may be tethered to a single point of failure. When CrowdStrike’s automated update failed, it didn’t just fail locally. Since the software operates at the kernel level , the structural foundation of the operating system, the faulty update can bring down the entire system. When that single point snapped, the entire “house of cards” came down.
The environments themselves dictate these differences. Physical terrorists are constrained by geography, physics and resources. In contrast, cybercriminals may launch thousands of automated attacks daily . Because digital threats are relentless, exposed vulnerabilities will eventually be discovered and exploited.
The critical lesson that cybersecurity must borrow from aviation security is the necessity of architectural compartmentalization. True independent redundancy is not just installing two security tools that tie back to the same cloud or vendor; that is just like building two separate emergency exits that lead into the same locked hallway. True resilience requires distinct, disconnected layers of defense. If a faulty software update crashes Layer A, Layer B must be isolated so it can keep the system online.
Ironically, the TSA already recognizes this. The agency has issued emergency cybersecurity mandates to force transit operators to secure their own interconnected software networks . This means that physical security increasingly depends on cyber resilience.
This level of resilience can be expensive . Developing, deploying and maintaining independent layers of cybersecurity will increase costs, some of which may be passed down to consumers. But we must ask ourselves: what is the alternative?
In the security domain, physical or cyber, there is no such thing as a “free lunch.” We can either pay an incremental premium today to build robust, multi-layered systems, or we can pay the catastrophic lump-sum invoice tomorrow while digging ourselves out of a crisis.
If we want a digital future that is on the same safety level as commercial flight , software buyers must demand architectural isolation, and regulators must reward systems designed to survive local failure rather than just compliance paperwork.
Sheldon H. Jacobson, Ph.D., is a professor in computer science at the University of Illinois Urbana-Champaign. As a data scientist, he applies his expertise in data-driven, risk-based decision-making to evaluate and inform public policy. He has researched aviation security for over 30 years, formulating the technical underpinnings of risk-based security that contributed to the design of TSA PreCheck.
Topics in this story
Gathered from external sources. Rights to this text belong to whoever originally published it.