Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Getting The Airlines Back On Their Feet After A Disaster
Articles

Getting The Airlines Back On Their Feet After A Disaster

ISBuzz TeamBy ISBuzz TeamSeptember 28, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
IT managers and disaster recovery planners
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Just a few weeks ago, Brussels airspace was closed for several hours following a technical problem. Labelled “a disaster” for Brussels Airport, the incident saw flights cancelled, delayed or diverted and passengers stranded. Unfortunately, this isn’t an isolated event and in fact they’re on the rise.

TSB and Visa have both recently suffered technical downtime which left customers unable to access their accounts or make payments. Last year, British Airways had not one but two system failures that saw 75,000 passengers grounded in the first instance, with head of parent company IAG admitting it was “damaging to our reputation”. The trouble didn’t end there with another two system failures this year causing “chaos” at Heathrow. After vowing “never again” following the first incident, what is it that keeps going wrong and what should these companies be doing to avoid it happening again?

A common theme between these companies is that they all have big, complex IT systems. Because of that and their reliance on these systems, they should have processes in place, which mean that when they have an issue within their IT systems, the impact on operations is minimised and, perhaps more importantly, when the systems are brought back up following any outage, they are focussed on solving the operational carnage and reputational damage that their outage caused, rather just simply just picking up where they left off. Processes such as – resilient IT, crisis management, disaster recovery (DR) and business continuity. The likelihood is that companies do have these processes in place so why aren’t they working?

A quick analysis of recent airline IT-related disasters shows that an outage of a mere 30 minutes on an essential IT system is more than enough to cause a newsworthy operational knock-on effect. This time criticality has, quite rightly, prompted the airline industry to improve the resilience of its IT by investing in high availability (HA) systems to minimise the chance of operational disruption. Its complex IT systems are frequently designed to provide eye-watering application uptimes on a daily basis by being “fault tolerant”, which is achieved by duplication and redundancy in the technology systems and/or, in extremis, “fail-over” to another solution.

However, whilst an HA system works to ensure the business as usual availability of information and technology services by making the IT system more resilient to faults and component failures, it does not provide the means to recover information technology services (e.g. infrastructure, telecoms, systems applications, data and Service Desk etc.) in extreme cases of downtime/disruption.

In short, an HA solution without an associated IT DR solution is just asking for trouble.

But beware – although disaster recoveries can now happen very quickly, in businesses such as airlines where severe operational impacts are almost instantaneous, a DR solution designed solely as a backstop for a business as usual HA solution will provide very little value to a disrupted business attempting to sort out operational chaos.

I don’t know if Brussels Airport or British Airways, or indeed TSB and Visa, made these mistakes. But I do know that HA without a DR solution, that has been defined by the business continuity and crisis management needs of the business, will result in acute failure once the IT resilience afforded by the HA is overwhelmed. This is then followed by a prolonged and disproportionate operational impact as the first systems to be recovered will be those that are needed for normal operation and to sort out operational backlogs.

What can businesses do?

It is tempting to think that ensuring the resilience or continuity of all the individual parts of a business will guarantee the resilience or continuity of the whole. However, as the airline examples demonstrate, this is not necessarily the case.

Whilst it makes perfect sense that each element of the business (e.g. IT, Operations, Finance, Marketing etc.) are resilient in their own right against low impact, high probability risks by using high availability techniques, they need to adopt the tried and tested business continuity and organisational resilience approach for high impact risks.

This is particularly important when thinking about IT. Disaster Recovery capabilities need to focus on the recovery of the business rather than recovery of the IT system. Only then will it be able to minimise the impact to the citizen or the customer.

These types and scale of incidents just shouldn’t be happening today. The technology and expertise are out there to ensure that if an IT issue strikes, it doesn’t completely cripple the company both from a logistical point of view on the day but also with regards to reputation. It’s been a while since British Airways has been known as “the world’s favourite airline” and the latest spate of technical failures won’t be helping that reduction in confidence. As our reliance on technology continues to grow, businesses from all industries need to ensure that they fully understand the difference between high availability and disaster recovery and that disaster recovery is of no use unless it recovers the things that a business needs in the immediate aftermath of a disaster.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}