Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Aviation Cybersecurity topic
No spam. Unsubscribe anytime.
United Airlines CISO on resilience: 'When something goes wrong, people notice'
Summary
Deneen DeFiore, United Airlines vice president and CISO, tells the FBI podcast resilience requires integrating safety and operations, focusing on identity and third-party risk, practicing recovery, and building nontraditional talent pipelines.
Get email alerts on the Aviation Cybersecurity topic
No spam. Unsubscribe anytime.
Deneen DeFiore, vice president and chief information security officer at United Airlines, described how the airline industry approaches cybersecurity differently because outages have immediate operational and safety consequences.
"When something goes wrong in an airline, people tend to notice," DeFiore said, adding that United centers its security program on resiliency and safety-risk assessments so controls do not impair the ability to operate safely. She said the company maps its most critical capabilities — flight dispatch, flight planning, crew records — and aligns people, processes and technology to preserve those capabilities during incidents.
DeFiore said United uses intelligence-driven prioritization to pair threat signals with business outcomes and risk tolerance instead of relying solely on regulation. "Threat management is risk management," she said, describing how mitigations aim for the largest defensive effect across criminal and nation-state attack paths.
On common attack surfaces, DeFiore and host Brett Leatherman emphasized edge devices and identity and access management. DeFiore noted many edge devices cannot run endpoint agents and that organizations must rethink how to instrument and monitor those environments. For help-desk social engineering, United deploys red teaming, automated identity verification for password resets and continuous evaluation of controls while accepting trade-offs in service speed.
Drawing on recent outages, DeFiore recounted recovery lessons: during a CrowdStrike outage, United manually rebooted more than 26,000 devices across 365 airports and grounded nearly 1,400 flights over three days; the company now prioritizes recovery rehearsals, alternate technical paths, and manual workarounds at scale. She said concentration risk in dependent third-party vendors is a major vulnerability and recommended rehearsing failover and manual procedures frequently.
To address the cybersecurity talent gap, DeFiore described a rotational program that brings early-career and nontraditional talent into cybersecurity roles from operational positions such as ramp work and customer service. She argued those hires bring operational context that improves security decision-making.
For CISOs and boards, DeFiore advised moving toward a continuous-controls, intelligence-centric model that embeds security capabilities into enterprise processes so organizations can operate at scale as attacker and defender speeds increase. "If CISOs and board members aren't thinking about moving into more of a continuous controls environment, they need to start doing that now," she said.
The interview closed with DeFiore and Leatherman underscoring the role of practiced recovery, trusted relationships with law enforcement and industry collaboration in improving resilience across aviation and other critical sectors.

