The passenger-processing stack, by owner. The common-use layer is the only one where the party that holds the contract and the party that carries the loss are different organisations.
On a Friday night in September 2025, ransomware reached the systems behind a piece of software almost no passenger has heard of. By Saturday morning, staff at Heathrow, Brussels, Berlin Brandenburg and Dublin were checking people in with pen and paper. Brussels asked airlines to cancel around 140 departures.1
No airline was breached. No airport was breached. No aircraft system, air traffic control system or navigation aid was touched, and the airports said so clearly at the time. What failed was a layer in between — a common-use passenger processing platform operated by Collins Aerospace, a division of RTX.2
That layer exists at every significant airport in Australia. This article is about who owns it here, and what happens when nobody has to look at it.
Source: CISC factsheet
Source: CISC factsheet
Source: SOCI Act, Part 2B
What a common-use platform actually does
Without common-use software, every airline needs its own check-in desks, its own kiosks and its own gate hardware, each running its own applications. That is expensive and it wastes terminal space.
Common-use software solves it. An agent from any airline logs in at any desk, and the platform delivers that airline's application to that screen, drives the boarding pass printer, the bag tag printer, the scanner and the card reader, then hands the desk to the next airline an hour later. It is the layer that makes a shared terminal possible.
It also means the desk has no independent capability. When the platform stops, the hardware in front of the passenger is inert.
The split that makes it fragile
Look at the diagram again and follow the two right-hand columns.
At every layer except one, the organisation that owns the systems is the organisation that suffers when they fail. Airlines own their reservations and departure control. Airports own baggage handling and flight information. Each carries its own consequences and each can commission its own assurance.
The common-use layer breaks that pattern. The airport operator typically holds the contract with the vendor. The vendor operates the platform. But when it fails, the loss lands on every airline at that airport — delays, cancellations, rebooking, compensation, reputational damage — and on their passengers.
So the party best placed to demand better security is not the party who pays when it goes wrong.
Two gaps this creates
- The airline cannot look. It has no contractual relationship with the vendor for that airport's deployment. No audit right, no assurance artefacts, no visibility of patch state, no seat at an incident response table. Its own supplier assurance programme will never capture the dependency, because on paper it is not its supplier.
- The airport cannot see far enough. It holds the contract, but the environment that failed in Europe was the vendor's shared back end, serving many airports at once. That is a fourth party, and very few third-party risk registers reach it.
Neither gap is negligence. Both are structural, and every party in the chain is behaving rationally.
Australia's map
Australian airports are split between two vendors, and the arrangements are public.
SITA runs Sydney, which signed a five-year technology deal in 2021 covering the SITA Flex common-use platform,3 along with Melbourne on AirportConnect Open4 and Gold Coast.5
Amadeus runs Brisbane, which moved to Amadeus cloud passenger technology across more than 300 common-use desks and 260 kiosks in 2024,6 along with Perth,7 Adelaide8 and Western Sydney International on Amadeus Flow.9
No Australian airport has been publicly named as a Collins Aerospace MUSE customer, and none was reported affected in September 2025.10
It is tempting to read that as comfort. It is not. Diversity between airports does nothing for any single airport. Sydney's passengers get no benefit from Melbourne running a different platform. Each airport still depends on one vendor, and each of those vendors still operates a shared environment underneath many airports. Amadeus alone reports more than 100 airports connected to its cloud use service.11
The concentration has not been removed. It has been moved.
Where Australian rules land — and where they stop
This is the part worth knowing, because it is not what most people assume.
Aviation is a critical infrastructure sector under the Security of Critical Infrastructure Act. But according to the Cyber and Infrastructure Security Centre's own factsheet, only two obligations apply to critical aviation assets: cyber security incident reporting, and the data notification obligation. The Critical Infrastructure Risk Management Program does not apply to them, and neither does the register obligation.12
Incident reporting runs to tight deadlines — 12 hours for an incident with significant impact, 72 hours for relevant impact.12 Those are obligations to tell the government after something breaks.
Operators in energy, water, data storage and several other sectors carry a risk management program that must address hazards including supply chain.13 Critical aviation assets do not.
We are not suggesting Australian airports are poorly run, or that any specific operator is exposed. We have no evidence of that and have made no assessment of any named airport. The point is narrower and, we think, harder to argue with: the obligation framework does not currently reach the layer that failed overseas, so whatever assurance exists over it is voluntary.
What can be done without a contract
The obvious objection to all of this is access. An airline cannot audit an airport's platform. An airport cannot audit its vendor's shared back end. Assurance you have no right to demand is not assurance you can obtain.
Except that a meaningful part of it can be observed from outside, with no access and no permission at all. Publicly reachable management interfaces and remote access appliances. Legacy services that should have been retired. Certificate and hostname patterns that reveal shared infrastructure behind nominally separate suppliers. Credentials belonging to a vendor's staff circulating in breach and infostealer data. Software and version disclosure from public endpoints.
None of that requires touching a system. It is the view an attacker builds before deciding whether to bother, and it is available to the party carrying the loss just as readily as to the party holding the contract.
That is the whole argument for passive assessment in a dependency you do not own: you cannot audit it, but you can still look at it.
Five questions for an aviation board
- Which common-use platform do we depend on at each port we operate from, and who holds that contract?
- If that platform failed tomorrow, how long could we process passengers, and have we tested it rather than assumed it?
- What assurance do we hold over a vendor we do not contract with, and what have we actually asked for?
- Do we know what sits underneath that vendor — the shared environment serving other airports?
- If a common-use outage hit us, who reports it, within 12 hours, and to whom?
What a supplier or platform exposes to the internet, observed without their cooperation and without an audit right. Passive only — no systems accessed.
View Assessment Start with a Threat Scan →Sources & references
- EU airport disruptions caused by ransomware attack on Collins Aerospace MUSE — Biometric Update, 22 September 2025 www.biometricupdate.com
- RTX confirms hack of passenger boarding software involved ransomware — Cybersecurity Dive, 26 September 2025 www.cybersecuritydive.com
- SITA and Sydney Airport sign five-year technology deal — SITA, 25 March 2021 www.sita.aero
- SITA self-service technology supports Melbourne Airport's growth strategy — International Airport Review, 11 June 2013 www.internationalairportreview.com
- Gold Coast Airport extends partnership with SITA — SITA, 19 November 2019 www.sita.aero
- Brisbane chooses Amadeus technology for exceptional airport experience — Amadeus, 12 September 2024 amadeus.com
- Perth Airport chooses Amadeus — Amadeus, 1 December 2019; and Perth Airport self-service expansion — Future Travel Experience, 17 September 2025 amadeus.com
- Adelaide Airport to transform passenger experience with Amadeus self-service and cloud technology — Future Travel Experience, 20 August 2026 www.futuretravelexperience.com
- Sydney's new airport partners with Amadeus for strategic technology rollout — Amadeus, 27 April 2023 amadeus.com
- European hack a wake-up call for Australian airports, expert says — Australian Aviation, 22 September 2025 australianaviation.com.au
- ACUS reaches milestone as Amadeus accelerates airport technology evolution — Amadeus, 20 November 2023 amadeus.com
- SOCI Act obligations for critical aviation assets — Cyber and Infrastructure Security Centre www.cisc.gov.au
- Security of Critical Infrastructure Act 2018 obligations factsheet — Cyber and Infrastructure Security Centre www.cisc.gov.au
- Aviation and Maritime Transport Security Reforms impact analysis — Office of Impact Analysis, 17 December 2024 oia.pmc.gov.au
This article is general information, not legal advice. It makes no assessment of, and asserts no finding about, any named airport, airline or vendor. Platform arrangements are drawn from public vendor and trade announcements and may have changed. Confirm obligations against the SOCI Act and CISC guidance.