Cyberwall Blog · September 10, 2026

A Wake Up Call for Critical Infrastructure Security

A breach of airport display screens and PA systems in Canada is a reminder that critical infrastructure attacks don't need to hit the control systems directly to cause real damage.

By Alex Plotkin, CEO

A recent incident at Canadian airports made the case better than any awareness campaign could: attackers didn’t touch flight control systems or anything resembling “critical” infrastructure in the traditional sense. They got into public display screens and PA systems in British Columbia and Ontario, used them to broadcast political messages, and caused real flight delays in the process. No planes were at risk, but the disruption, and the erosion of public confidence, was real.

That’s the pattern worth paying attention to: peripheral systems, the ones that feel low stakes because they’re not the “important” ones, are often the easiest way into a network that eventually connects to something that matters. A display screen or a PA controller usually isn’t managed with the same rigor as a core operational system. It’s on a shared network segment, it runs on older firmware that doesn’t get patched on a predictable schedule, and it’s administered by whoever had time that quarter rather than a dedicated owner. None of that makes it a target on its own. It makes it a soft entry point that can be walked through to reach something that is a target.

Modern infrastructure environments have more of these soft entry points than ever, tied together across IT and operational technology, plus a growing list of third party vendors with their own access into the environment. IT/OT convergence was supposed to make operations more efficient, and it has, but it also means a compromise that starts on the business side of the house no longer has to stay there. A vendor’s remote access credentials, a shared management platform, a network that was never properly segmented between “office systems” and “operational systems”: each of these collapses the distance between an unimportant-looking breach and a genuinely damaging one. Airports are a visible example because the disruption played out in public, on screens travelers could see and read for themselves. The same dynamic plays out quietly in plenty of organizations that never make the news for it.

None of that is a reason to panic. It’s a reason to treat the boring systems with the same discipline as the critical ones. It’s also a reminder that “critical infrastructure” is a misleading label if it’s read as a fixed list of systems rather than a description of consequence. Any system can become critical infrastructure for a few hours if it’s the one an attacker chooses to use, which is exactly what happened here: a display screen isn’t critical in any normal sense, until it’s the thing broadcasting a message to a terminal full of travelers and forcing an operational response. In practice that means a few concrete things. A zero trust posture instead of assuming anything inside the network is automatically safe: every device and account has to prove it belongs, every time, rather than earning permanent trust once it’s inside the perimeter. Retiring legacy systems that can’t be properly secured, rather than leaving them running because replacing them is inconvenient or expensive. Continuous monitoring rather than periodic checks, since an attacker sitting quietly in a peripheral system for weeks won’t show up in a quarterly review. And response plans that cover the full environment, not just the systems everyone already agrees are important, so that when something unexpected does get compromised, there’s already a playbook for it rather than an improvised scramble.

In incidents like this one, the operational disruption often isn’t the most expensive part. Flight delays get resolved in hours. The damage to public and client trust takes much longer to repair, and it’s harder to quantify on a balance sheet, which is exactly why it tends to get underweighted in risk planning until an incident forces the conversation. For an IT Director trying to make the case internally for covering the “boring” systems, that’s the argument worth making to the board: the cost of a breach rarely lines up with how important the compromised system looked beforehand.

That’s the same reasoning behind a tested incident response plan that covers the whole environment, not just the systems everyone already agrees are critical. A plan that only accounts for the assets already flagged as high value will leave a gap exactly where an attacker is most likely to start. Building coverage around the full environment, including the systems that feel too minor to worry about, is what turns an incident like this one from a headline into a non-event.

Related reading: Top 10 High Profile Cybercrimes in 2021

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.