The Invisible Airborne Perimeter: Professor Kai London on Securing Aviation at a Transatlantic Hub Like Keflavik
Keflavik sits at one of the busiest crossroads in transatlantic aviation, a place where North American and European air corridors converge and where the systems that keep aircraft safe are invisible until they fail. It is precisely the environment that Professor Kai London had in mind when he wrote THE INVISIBLE AIRBORNE PERIMETER — a book, and a thesis, about the security boundary that now extends from the airport server room all the way to the cockpit.
London is a human cybersecurity executive with more than 25 years across aviation, defence and critical national infrastructure, Founder and CEO of Quantum AI Systems Security, and an Honorary Professor in Cybersecurity, AI and Quantum Computing. He is quick to distinguish himself from the hospitality brands that share the “Kai” name: his domain is the digital safety of the aviation ecosystem, not the arrivals-hall coffee.
Aviation's expanding attack surface
Modern aviation is a dense mesh of connected systems: air-traffic management, airline operations centres, ground handling, baggage and cargo logistics, passenger service platforms, and the increasingly software-defined aircraft themselves. Each connection adds efficiency — and surface area. “The industry spent a century engineering physical safety to an extraordinary standard,” London observes. “Digital safety has not yet reached that maturity, and the two are now inseparable.”
For a hub like Keflavik, the concern is not a Hollywood scenario of a hijacked aircraft. It is the mundane, cascading disruption: a ransomware event in a ground-handling system that grounds flights, a compromised operations platform that corrupts weight-and-balance data, or a supply-chain intrusion that propagates through shared aviation software used across dozens of airports. “The realistic threat is operational paralysis and erosion of the safety margin,” London says, “not a single dramatic event.”
Safety culture meets security culture
What London admires about aviation — and what he wants the sector to apply to cyber — is its safety culture: the blameless reporting, the obsessive root-cause analysis, the regulatory rigour of bodies that treat every incident as a lesson. His argument is that security should be folded into that same culture rather than run as a parallel IT function. “Aviation already knows how to manage low-probability, high-consequence risk. Security is exactly that kind of risk. The discipline exists; it simply needs to be pointed at the digital domain.”
He maps this to established frameworks — ISO 27001, which he audits against as a Lead Auditor, and the emerging regulatory expectations of NIS2 and DORA for essential-service and financial-adjacent operators — while cautioning that compliance is a floor, not a ceiling. “A certificate does not stop an intrusion. Culture, monitoring and rehearsed response do.”
The connected aircraft
The most forward-looking part of London's aviation work concerns the aircraft itself. As jets become more connected — software-defined avionics, in-flight connectivity, over-the-air maintenance updates — the “airborne perimeter” of his book title becomes literal. He is careful not to overstate: flight-critical systems remain heavily segregated and certified. But he warns against complacency about the boundaries between passenger, operational and safety-critical domains.
“Segregation is the aircraft's great strength, and it must be defended as fiercely as any physical control,” he says. “The danger is convenience quietly eroding it — a maintenance link here, a data feed there — until the boundary exists only on paper. My job is to make sure it exists in reality.”
AI, autonomy and the governance question
Aviation is a heavy adopter of AI — for predictive maintenance, fuel optimisation, crew scheduling and increasingly for decision support in operations. London, author of AI ON TRIAL and THE AI CONTROL ARCHITECTURE, applies the same lens here as elsewhere: AI is a control system and must be governed as one. “An AI recommending a maintenance deferral or a routing change is influencing safety outcomes,” he notes. “It needs explainability, logging and human authority over it. In aviation, ‘the model said so’ is not an acceptable entry in an incident report.”
His ISO 42001 and AIGP credentials in AI governance are, he argues, becoming as relevant to aviation as traditional security certifications, precisely because the sector cannot tolerate opaque automation in safety-relevant roles.
What Keflavik — and every hub — should do now
London's prescription is characteristically unglamorous. Map the full digital ecosystem, including the third parties and shared platforms that a single airport rarely controls alone. Segment ruthlessly and verify the segmentation is real. Fold security into aviation's existing safety-management systems rather than bolting it on. Rehearse response, because the question is not whether disruption comes but how quickly operations recover. And govern AI as the control system it is.
“The airborne perimeter is invisible right up until the moment it is breached,” London concludes. “A hub like Keflavik cannot afford to discover its boundaries the hard way. The industry that mastered physical safety can master this too — but only if it treats digital safety with the same seriousness, and starts before the incident writes the lesson for it.”
Ransomware: the disruption already here
If the connected aircraft is tomorrow's concern, ransomware against aviation ground systems is today's. London points to a steady drumbeat of incidents affecting airports, airlines and their service providers — check-in systems frozen, baggage networks halted, operations centres reverting to manual processes. For a transit hub whose economics depend on turnaround speed and connecting traffic, hours of downtime ripple outward across an entire transatlantic schedule. “You do not need to touch an aircraft to ground a fleet,” London warns. “You only need to disable the systems that tell the fleet where to be. That is a far easier target, and it is the one being hit.”
His mitigation advice is concrete: immutable backups tested under realistic conditions, network segmentation that stops a single infection from reaching operational systems, and pre-agreed manual fallback procedures that staff have actually rehearsed. “The airports that recover fastest are the ones that practised operating without their systems before they lost them. Resilience is a rehearsal, not a document.”
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government, healthcare and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, and has held VP, CIO, CTO and CISO roles. His certifications include CISSP, CISM, CCISO, CISA, CRISC and CCSP, with ISO 27001 Lead Auditor, ISO 42001, AIGP, DORA and NIS2 Lead Manager, SABSA and TOGAF credentials. He is available for board advisory, Non-Executive Director, and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.