When Check-Ins Crash: The Airport Cyberattack Every Executive Must Learn From
By Ann Marie van den Hurk, MSc., APR – Founder, Mind The Gap Advisory
The September 19 Lesson
On September 19, 2025, tens of thousands of travelers across Europe faced chaos—not from weather, but from a major cyberattack on airport check-in and boarding systems.
London Heathrow, Brussels Airport, and Berlin Brandenburg were among the hardest hit. Digital systems operated by Collins Aerospace, a key aviation service provider, went down—forcing staff to switch to manual check-ins and baggage processing.
The impact rippled quickly:
Brussels Airport confirmed nine cancellations, multiple diversions, and hours-long queues (Euronews, 2025).
Heathrow issued warnings of widespread delays, advising travelers to check flight status before leaving home (Al Jazeera, 2025).
Berlin Brandenburg experienced hours of manual check-ins and significant passenger disruption.
For travelers, it was frustration. For the aviation industry, it was a wake-up call.
The New Reality: A Single Point of Failure Can Ground Entire Regions
The incident underscored how deeply aviation—and nearly every sector—is tied to third-party vendors and interconnected digital infrastructure.
When one node fails, the domino effect is immediate and global.
The risks for leaders go far beyond IT downtime:
Operational Paralysis: Critical services grind to a halt.
Reputational Fallout: Trust erodes when customers face chaos without clear communication.
Financial Impact: Cancellations, diversions, and disrupted supply chains quickly rack up costs.
Regulatory Pressure: Aviation regulators are scrutinizing cyber resilience with the same rigor as safety.
Board-Level Exposure: Stakeholders demand oversight of third-party risks.
According to Thales, the aviation sector has seen a 600% increase in cyberattacks between 2024 and 2025 (France24, 2025). Experts, including Dr. Elena Martinez of the University of Amsterdam, describe this event as a “stark reminder” of the fragility of digital-first operations (Gigadgets, 2025).
What CEOs, Boards, and C-Suites Must Do
This was not just an “IT systems issue.” It was an enterprise resilience failure.
- Every leadership team should be asking today:
- How dependent are we on single vendors or systems?
- Do we have tested backup processes—manual or otherwise?
- Is cyber risk treated with the same urgency as safety and financial risk?
- Are third-party vendors included in crisis simulations?
- Do our response workflows protect both operations and reputation?
In my work guiding global organizations through cyber and reputational crises, I’ve seen firsthand how one compromised vendor can ripple across an entire operation. The organizations that recover fastest aren’t the ones with the best tech—they’re the ones with leaders who drill, communicate, and adapt under pressure.
The Lesson from Europe’s Airports
The Collins Aerospace incident proves that resilience isn’t about avoiding disruption altogether—it’s about containing the damage and maintaining trust under pressure.
Executives who treat cyber resilience as a technical checkbox will find themselves flat-footed when the lights go out. Those who embed it as a leadership and governance priority will navigate turbulence with authority.
Final Thought
If Europe’s busiest airports can be brought to a standstill by one cyberattack, so can your organization. The question isn’t whether your systems are vulnerable, but whether your leadership is prepared.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
Quick FAQ
Was passenger data stolen in this attack?
As of now, there is no evidence that customer data was compromised. The disruption was operational, not informational.
How rare are these attacks?
While full system takedowns are uncommon, attempts are increasing sharply—up 600% in the aviation sector year-over-year.
What should executives take away?
Cyber risk isn’t just IT’s responsibility—it’s a boardroom and reputational risk. Preparedness needs to be practiced, not just planned.
