Skip to content
Bridewell: State of Aviation Supply Chain and Cyber Risks

Bridewell: State of Aviation Supply Chain and Cyber Risks

Cybermagazine • September 27, 2026

Cybersecurity is non-negotiable for operational resilience in an era where security gaps and exposure area easily weaponised by bad actors.

This is particularly true for critical infrastructure industries like aviation , as supply chains face mounting pressure from cybercriminals who exploit digital connections between airlines, airports, manufacturers and suppliers.

Bridewell , a cyber security partner, has released a report examining how these attacks compromise the industry.

The study surveyed 250 cyber security professionals working in aviation. It found that interconnected systems have created more entry points for hackers targeting the sector.

Attack frequency climbs higher

According to Bridewell, almost half of respondents state that the volume of attacks against their organisations has increased in the last 12 months. This could show a correlation with the rapid digitalisation of supply chains across the aviation sector.

The most common entry point for attacks was through compromised credentials, as reported by 30% of respondents. Third-party and supply chain access was an entry point for these attacks in 13.2% of cases.

As smaller third parties often have weaker security systems, hackers target these organisations first.

Once inside a supplier or vendor system, attackers gain an indirect pathway into larger organisational defences. This access could mean entry to entire databases, client lists and partner ecosystems.

"A key concern from cybersecurity professionals is attacks on airport operational infrastructure and supply chain partners," explains Kelechi Onyedebelu , Director Security Solutions Presales at Bridewell US.

"60% of respondents shared that they are concerned attacks that target their vendors and partners. In an industry so dependent on a deep network of suppliers, it's important to ensure that each organisation is doing its due diligence to keep good cyber hygiene."

Digital systems create vulnerabilities

"The aviation industry has changed dramatically over the past two decades, and it’s now fundamentally dependent on interconnected digital systems," Kelechi notes.

Real-time data sharing is now standard across the sector. While this is a welcome progress, it also creates a wider attack surface for criminals to exploit.

"What we’re seeing is that the aviation industry is under sustained pressure and experiencing significant financial losses as a result," he says.

"At the same time, organisations are also having to balance immediate threats with longer-term concerns around skills shortages, changing regulations and emerging technologies."

Kelechi explains that as airlines, airports, manufacturers and suppliers now all operate on interconnected technologies, cyber resilience can o longer be achieved by individual organisations working in isolation.

Manchester breach affects millions

In August 2026, the Manchester Airports Group revealed that it had been victim to a major data breach . Personal information of more than 8.5 million individuals was compromised.

The group operates Manchester, London Stansted and East Midlands airports. Data was harvested from customers who had signed up for terminal Wi-Fi, airport parking, lounge access or Fast Track security passes.

This attack demonstrated how severe the impact of breaching hyper-connected ecosystems in the network can be. Aviation groups have increasingly experienced attacks which result in major data breaches and financial losses caused by delays, reputational damage and disruption.

According to Bridewell, 100% of respondents were financially impacted by an attack. Some 45.2% described their most significant attack as having a critical or high impact on their organisation.

"It's also important to note that compromised credentials were cited as the most common entry point (30%) into these organisations," Kelechi notes.

"With such an interconnected supply chain , each set of credentials held by a vendor or contractor is a potential risk.

"This highlights that identity and access management across third parties is one of the most important areas to focus on in supply chain cyber resilience."

Investment in defence rises

According to the report, 70.8% of respondents have adopted AI or machine learning as a tool for cyber defence.

Every organisation we surveyed reported a financial impact from a breach in the past year, averaging over US$1.4m Kelechi Onyedebelu, Director Security Solutions Presales at Bridewell US

Every organisation we surveyed reported a financial impact from a breach in the past year, averaging over US$1.4m

Promisingly, some 77.6% have seen increased budgets for cyber security within their organisation.

The last 12 months have demonstrated how vulnerable organisations are to attacks. Increased supply chain complexity brings increased risk.

"Shared threat intelligence and coordinated standards are valuable tools for securing a complex supply chain and organisations that embrace this will be far better protected," says Kelechi.

"Every organisation we surveyed reported a financial impact from a breach in the past year, averaging over US$1.4m.

"For supply chain leaders everywhere, it’s a reminder that cyber resilience cannot be overlooked," Kelechi concludes.

US$1,433,059 - the mean losses from an attack or breach

100% of respondents said they experienced financial losses due to a breach in the last year

In the past 12 months, 46% of respondents have seen an increase in attacks against their organisation

30% of the attack entry points was caused by compromised credentials

Malware, credential theft and DDOS attacks were experienced by 8% of respondents

On average, an organisation experienced 3.85 phishing attacks in the last year

More than ¾ respondents have seen organisational increases to cybersecurity budgets in the current fiscal year

Manchester Airports Group

Manchester Airports Group

Kelechi Onyedebelu Director of Cybersecurity Solutions and Presales - USA

Director of Cybersecurity Solutions and Presales - USA

Manchester Airports Group

Manchester Airports Group

Mastercard Tackles SME Security Gap with Built In Protection Cyber Security

Tackling Fraud in Finance with Anna Wallace, CEO of CFIT Cyber Security

Top 10: Cloud Security Companies Cloud Security

Akamai: Why AI-Driven Threats are Intensifying for Finance Technology & AI

Extracted Entities