Aviation Cybersecurity and Third-Party Software Service Providers: Do Companies Like CrowdStrike Get a Free Pass to Create Cyber Vulnerabilities?
Development summary
Claire Konerza’s Journal of Air Law and Commerce comment addresses the growing cybersecurity risks in civil aviation and the part played by third-party software service providers in creating or mitigating those risks. Using the disruption caused by CrowdStrike’s defective software update in summer 2024 as its point of reference, the piece considers how far such providers may be held liable beyond contractual limits, and the potential harm to airlines and consumers, including financial loss and data compromise.
Research note
Issue
The scope of third-party cybersecurity software providers' liability for harm to airlines and consumers caused by failures or inadequate protection in software used in commercial civil aviation.
Concepts
Academic details
“Aviation Cybersecurity and Third-Party Software Service Providers: Do Companies Like CrowdStrike Get a Free Pass to Create Cyber Vulnerabilities?”
Journal of Air Law and Commerce · 2025
DOI 10.25172/jalc.90.4.4
Show suggested citation
Claire Konerza, “Aviation Cybersecurity and Third-Party Software Service Providers: Do Companies Like CrowdStrike Get a Free Pass to Create Cyber Vulnerabilities?”, Journal of Air Law and Commerce, 2025-12-22, 10.25172/jalc.90.4.4. https://doi.org/10.25172/jalc.90.4.4