Intelligence

The Layer Nobody Owns.European airports lost check-in for days to a vendor most passengers have never heard of. Australia has the same layer — and it sits outside the country's main critical infrastructure risk rules.

Evidence-based analysis of threats, regulatory developments and security failures affecting Australian organisations. Passive OSINT only.

IntelligenceCategory
7 minRead time
Sep 2026Published
SOCI · CIRMPFrameworks referenced

Passive only — no systems, networks or accounts are accessed at any point.

BLACKFLAG ADVISORY — INTELLIGENCE Who owns the airport check-in stack Every layer has an owner. The layer that failed in Europe has two, and neither of them is the airline. LAYER WHO OWNS IT WHO CARRIES THE LOSS 01 Passenger touchpoints Shared hardware on the terminal floor Check-in desk Self-service kiosk Self bag drop Gate podium Airport operator Owns the hardware Airline Queues, delays, claims 02 Common-use platform SITA, Amadeus or Collins Aerospace. One platform every airline logs in to. Airline session brokering Airline app at the desk Printer and peripheral control Device identity and config Vendor operates, airport contracts Every airline at that airport 03 Vendor shared back end One environment serving many airports at once Platform servers Directory and authentication Private inter-site network Legacy and remote access Vendor alone No customer visibility Every airport on the platform 04 Airline systems Off-airport, reached through the common-use layer Departure control Reservations Weight and balance Loyalty Airline Own contracts Airline Unreachable, not breached 05 Airport operational systems Run by the airport operator Baggage handling Operational database Flight information Border and biometrics Airport operator Own contracts Airport operator Manual fallback 06 Airside and safety-critical Separate networks. No connection to the common-use layer. Air traffic control Aircraft systems Navigation aids Airservices, operators Unaffected Heavily regulated ACCOUNTABILITY GAP The airline carries the consequence but holds no contract with the vendor for this airport. No audit right, no assurance, no seat at incident response. ACCOUNTABILITY GAP The airport holds the contract but cannot see the vendor's shared back end. It is a fourth party to everyone who depends on it. SAFETY-CRITICAL SEPARATION The party who can demand better security is not the party who pays when it fails. BLACKFLAGADVISORY.COM.AU Generic common-use architecture. Ownership varies by contract.

The passenger-processing stack, by owner. The common-use layer is the only one where the party that holds the contract and the party that carries the loss are different organisations.

On a Friday night in September 2025, ransomware reached the systems behind a piece of software almost no passenger has heard of. By Saturday morning, staff at Heathrow, Brussels, Berlin Brandenburg and Dublin were checking people in with pen and paper. Brussels asked airlines to cancel around 140 departures.1

No airline was breached. No airport was breached. No aircraft system, air traffic control system or navigation aid was touched, and the airports said so clearly at the time. What failed was a layer in between — a common-use passenger processing platform operated by Collins Aerospace, a division of RTX.2

That layer exists at every significant airport in Australia. This article is about who owns it here, and what happens when nobody has to look at it.

2
SOCI obligations that apply to critical aviation assets
Source: CISC factsheet
0
Risk management program obligations over the vendor layer
Source: CISC factsheet
12 hrs
To report a significant-impact cyber incident
Source: SOCI Act, Part 2B

What a common-use platform actually does

Without common-use software, every airline needs its own check-in desks, its own kiosks and its own gate hardware, each running its own applications. That is expensive and it wastes terminal space.

Common-use software solves it. An agent from any airline logs in at any desk, and the platform delivers that airline's application to that screen, drives the boarding pass printer, the bag tag printer, the scanner and the card reader, then hands the desk to the next airline an hour later. It is the layer that makes a shared terminal possible.

It also means the desk has no independent capability. When the platform stops, the hardware in front of the passenger is inert.

The shape of the failureThe European outage did not spread outward from one airport. It came down from one vendor, into many airports, at the same moment.

The split that makes it fragile

Look at the diagram again and follow the two right-hand columns.

At every layer except one, the organisation that owns the systems is the organisation that suffers when they fail. Airlines own their reservations and departure control. Airports own baggage handling and flight information. Each carries its own consequences and each can commission its own assurance.

The common-use layer breaks that pattern. The airport operator typically holds the contract with the vendor. The vendor operates the platform. But when it fails, the loss lands on every airline at that airport — delays, cancellations, rebooking, compensation, reputational damage — and on their passengers.

So the party best placed to demand better security is not the party who pays when it goes wrong.

Two gaps this creates

  • The airline cannot look. It has no contractual relationship with the vendor for that airport's deployment. No audit right, no assurance artefacts, no visibility of patch state, no seat at an incident response table. Its own supplier assurance programme will never capture the dependency, because on paper it is not its supplier.
  • The airport cannot see far enough. It holds the contract, but the environment that failed in Europe was the vendor's shared back end, serving many airports at once. That is a fourth party, and very few third-party risk registers reach it.

Neither gap is negligence. Both are structural, and every party in the chain is behaving rationally.

Australia's map

Australian airports are split between two vendors, and the arrangements are public.

SITA runs Sydney, which signed a five-year technology deal in 2021 covering the SITA Flex common-use platform,3 along with Melbourne on AirportConnect Open4 and Gold Coast.5

Amadeus runs Brisbane, which moved to Amadeus cloud passenger technology across more than 300 common-use desks and 260 kiosks in 2024,6 along with Perth,7 Adelaide8 and Western Sydney International on Amadeus Flow.9

No Australian airport has been publicly named as a Collins Aerospace MUSE customer, and none was reported affected in September 2025.10

It is tempting to read that as comfort. It is not. Diversity between airports does nothing for any single airport. Sydney's passengers get no benefit from Melbourne running a different platform. Each airport still depends on one vendor, and each of those vendors still operates a shared environment underneath many airports. Amadeus alone reports more than 100 airports connected to its cloud use service.11

The concentration has not been removed. It has been moved.

Where Australian rules land — and where they stop

This is the part worth knowing, because it is not what most people assume.

Aviation is a critical infrastructure sector under the Security of Critical Infrastructure Act. But according to the Cyber and Infrastructure Security Centre's own factsheet, only two obligations apply to critical aviation assets: cyber security incident reporting, and the data notification obligation. The Critical Infrastructure Risk Management Program does not apply to them, and neither does the register obligation.12

Incident reporting runs to tight deadlines — 12 hours for an incident with significant impact, 72 hours for relevant impact.12 Those are obligations to tell the government after something breaks.

Operators in energy, water, data storage and several other sectors carry a risk management program that must address hazards including supply chain.13 Critical aviation assets do not.

The practical positionThere is no standing legal requirement for an Australian airport to run a risk management program over its common-use vendor, or to evidence assurance over the layer that took European airports offline. Reform is underway — the Transport Security Amendment (Security of Australia's Transport Sector) Bill 2024 moves aviation and maritime towards mandatory all-hazards security obligations including cyber — but the published impact analysis does not specifically address third-party or vendor risk management.14

We are not suggesting Australian airports are poorly run, or that any specific operator is exposed. We have no evidence of that and have made no assessment of any named airport. The point is narrower and, we think, harder to argue with: the obligation framework does not currently reach the layer that failed overseas, so whatever assurance exists over it is voluntary.

What can be done without a contract

The obvious objection to all of this is access. An airline cannot audit an airport's platform. An airport cannot audit its vendor's shared back end. Assurance you have no right to demand is not assurance you can obtain.

Except that a meaningful part of it can be observed from outside, with no access and no permission at all. Publicly reachable management interfaces and remote access appliances. Legacy services that should have been retired. Certificate and hostname patterns that reveal shared infrastructure behind nominally separate suppliers. Credentials belonging to a vendor's staff circulating in breach and infostealer data. Software and version disclosure from public endpoints.

None of that requires touching a system. It is the view an attacker builds before deciding whether to bother, and it is available to the party carrying the loss just as readily as to the party holding the contract.

That is the whole argument for passive assessment in a dependency you do not own: you cannot audit it, but you can still look at it.

Five questions for an aviation board

  • Which common-use platform do we depend on at each port we operate from, and who holds that contract?
  • If that platform failed tomorrow, how long could we process passengers, and have we tested it rather than assumed it?
  • What assurance do we hold over a vendor we do not contract with, and what have we actually asked for?
  • Do we know what sits underneath that vendor — the shared environment serving other airports?
  • If a common-use outage hit us, who reports it, within 12 hours, and to whom?
Related Assessment
Third-Party Risk Assessment

What a supplier or platform exposes to the internet, observed without their cooperation and without an audit right. Passive only — no systems accessed.

View Assessment Start with a Threat Scan →

Sources & references

  • EU airport disruptions caused by ransomware attack on Collins Aerospace MUSE — Biometric Update, 22 September 2025 www.biometricupdate.com
  • RTX confirms hack of passenger boarding software involved ransomware — Cybersecurity Dive, 26 September 2025 www.cybersecuritydive.com
  • SITA and Sydney Airport sign five-year technology deal — SITA, 25 March 2021 www.sita.aero
  • SITA self-service technology supports Melbourne Airport's growth strategy — International Airport Review, 11 June 2013 www.internationalairportreview.com
  • Gold Coast Airport extends partnership with SITA — SITA, 19 November 2019 www.sita.aero
  • Brisbane chooses Amadeus technology for exceptional airport experience — Amadeus, 12 September 2024 amadeus.com
  • Perth Airport chooses Amadeus — Amadeus, 1 December 2019; and Perth Airport self-service expansion — Future Travel Experience, 17 September 2025 amadeus.com
  • Adelaide Airport to transform passenger experience with Amadeus self-service and cloud technology — Future Travel Experience, 20 August 2026 www.futuretravelexperience.com
  • Sydney's new airport partners with Amadeus for strategic technology rollout — Amadeus, 27 April 2023 amadeus.com
  • European hack a wake-up call for Australian airports, expert says — Australian Aviation, 22 September 2025 australianaviation.com.au
  • ACUS reaches milestone as Amadeus accelerates airport technology evolution — Amadeus, 20 November 2023 amadeus.com
  • SOCI Act obligations for critical aviation assets — Cyber and Infrastructure Security Centre www.cisc.gov.au
  • Security of Critical Infrastructure Act 2018 obligations factsheet — Cyber and Infrastructure Security Centre www.cisc.gov.au
  • Aviation and Maritime Transport Security Reforms impact analysis — Office of Impact Analysis, 17 December 2024 oia.pmc.gov.au

This article is general information, not legal advice. It makes no assessment of, and asserts no finding about, any named airport, airline or vendor. Platform arrangements are drawn from public vendor and trade announcements and may have changed. Confirm obligations against the SOCI Act and CISC guidance.

You Depend On It.
You Did Not Sign For It.

Every organisation has a dependency it cannot audit — a platform someone else contracted, running underneath its operations. We assess those dependencies from the outside, so the party carrying the risk can finally see it. Board-ready output, no access required.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.

Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber SOCI / Critical Infrastructure Obligation Tool →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report