Why it Matters The federal government's two primary aviation agencies are struggling to coordinate on a critical vulnerability: protecting aircraft from cyberattacks. A new Government Accountability Office (GAO) report reveals that while the Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) collaborate on aviation cybersecurity, they have failed to clearly delineate who is responsible for what, leaving potential gaps in the nation's defenses against digital threats to commercial aviation. The stakes are significant. Modern aircraft depend on interconnected systems both onboard and on the ground to operate safely. That same interconnection makes them more vulnerable to cyberattacks. If adversaries compromise these systems, the consequences could range from disrupted operations to safety hazards affecting millions of passengers annually. The GAO report, released on July 16, identifies key shortfalls in how the two agencies are managing this shared responsibility. The findings underscore a fundamental problem in how the federal government approaches aviation security in an era when cyber threats are as real as physical ones. The Big Picture Aircraft systems today communicate with ground-based infrastructure, maintenance networks, and air traffic control systems. This interconnectedness is essential for modern aviation operations, but it creates multiple entry points for potential cyberattacks. The FAA, housed within the Department of Transportation, serves as the primary aviation safety regulator. The TSA, part of the Department of Homeland Security, functions as the aviation security agency. Both agencies have important roles in protecting air travel and travelers from threats. But their missions, structures, and authorities differ significantly. The FAA has clearly defined roles and responsibilities for aviation cybersecurity within its regulatory framework; TSA does not. This asymmetry creates confusion about accountability and potentially leaves blind spots in security coverage. While the two agencies do work together on aviation cybersecurity matters, and the GAO acknowledges this collaboration exists, the