Oliver Braun and Ricardo Roth explain how Berlin Brandenburg Airport is integrating cyber, physical and operational security to defend against hybrid threats and strengthen resilience in an increasingly unstable geopolitical environment.

Airports have always been high-value targets, but the nature of the threat has fundamentally changed. Today’s risk landscape is defined by hybrid threats, where cyber-attacks, physical vulnerabilities and operational dependencies intersect and reinforce each other. Recent events have illustrated this development very clearly.
The global CrowdStrike incident in 2024 demonstrated how even a faulty software update can cause major disruptions to air traffic operations within a very short time, even without a conventional cyber-attack. At the same time, physical threats such as sabotage against critical infrastructure, unmanned drones operating in the vicinity of airports and attacks on energy supply networks are increasingly becoming part of the threat landscape. Particularly at Berlin Brandenburg Airport (BER), the proximity to the German capital Berlin and the strong dependence on digital systems and external service infrastructures demonstrate how even regionally limited disruptions can rapidly develop into operational and security-relevant consequences for airport operations. What was once treated as separate domains is now a single, interconnected system. At BER, this is not a theoretical consideration but an operational reality that has driven a decisive shift towards an integrated “One Security” approach.
From isolated incidents to interconnected disruption
Recent years have shown that disruptions in digital systems can rapidly translate into operational impact. The challenge is no longer the detection of isolated incidents, but the ability to understand relationships between seemingly unrelated signals. Cyber-attacks are often anonymous, distributed and difficult to attribute, while physical incidents appear local and immediate. Only by bringing both perspectives together in time and context does a coherent threat picture emerge. This realisation has led to a fundamental change in how security is organised and executed at BER, moving away from parallel structures towards a connected system of situational awareness and response.
Third-party dependencies as a critical vulnerability
A key driver of this transformation has been the experience with incidents affecting third-party systems, including global aviation service providers such as Collins Aerospace. These events highlighted a critical vulnerability that is often underestimated: dependencies. Even when core airport systems remain secure, disruptions in external platforms can have immediate consequences for passenger handling, check-in and boarding processes, information flows and overall operational stability. At BER, such incidents were deliberately not treated as isolated IT problems, but as operational stress tests for the entire system.
Security cannot function in isolation
A concrete example of this integrated approach was the cyber-attack against the aviation service provider Collins Aerospace in September 2025, which affected several European airports. On the evening of 19 September, BER identified initial disruptions in systems supporting check-in, boarding and baggage handling after Collins Aerospace reported a cyber-related disruption of its platforms. As a precautionary measure, the airport disconnected interfaces to the affected systems and immediately activated joint assessment and crisis management processes involving cyber-security, physical security and operational departments.
Although the attack was not directed against BER itself, it had immediate consequences for airport operations and the physical security situation within the terminal environment. The disruption of automated processes resulted in increased passenger volumes at service counters, extended waiting times and altered movement and access patterns throughout terminal infrastructure. Cyber-security and physical security, therefore assessed the incident jointly from the outset in order to address both digital risks and potential impacts on passenger flow management, access control and the maintenance of safe operational procedures. At the same time, manual fallback processes were activated, additional security measures were implemented, and the situation was continuously evaluated in a co-ordinated manner until the systems could gradually be restored following extensive security validation measures in early October.
Lessons learned: managing dependencies and resilience

Several lessons emerged from this. Dependencies must be actively managed rather than assumed to be stable. Cyber incidents must immediately trigger operational awareness beyond the IT domain. Fallback processes are as critical as preventive measures, because resilience is defined by the ability to maintain operations under degraded conditions. Most importantly, interfaces between stakeholders, systems and responsibilities consistently proved to be the most vulnerable points. These insights directly informed the evolution towards an integrated security model that treats cyber, physical and operational aspects as one coherent system.
At the core of this model is the deliberate integration of situational awareness. Instead of operating separately, the Cyber Security Operations Centre and the Airport Security Operations Centre are connected to enable continuous exchange and joint assessment. This enables the correlation of cyber anomalies with physical observations and operational irregularities. A technical disruption in an access control system, for example, is no longer viewed purely as a cyber issue but immediately assessed for potential physical security implications and operational consequences. This significantly improves both the speed and the quality of decision-making, particularly in ambiguous or rapidly evolving situations.
This integration is not limited to monitoring and response but extends into risk management and system design. Risk assessments are conducted jointly across disciplines, ensuring that vulnerabilities are understood in their full context. Measures are aligned to reduce risk holistically, not within isolated domains.
Protecting critical infrastructure through layered security
A concrete example is the protection of critical infrastructure such as data centres. Cyber-security defines the protection requirements for information assets, while physical security translates these requirements into zoned architectures, layered access concepts and hardened environments. Only the combination of both perspectives results in effective protection.
Another key pillar of BER’s approach is the understanding that security cannot function in isolation. Airports are part of a highly interconnected operational environment, and today’s threat actors operate in the same way. For this reason, BER is actively integrated into both national and international security networks, including Airports Council International (ACI) and German Airport Association (ADV). Within these networks, security stakeholders exchange indicators of compromise, share intelligence and provide early warnings regarding emerging threats. This collaborative framework enables airports to identify and address developments before they manifest locally, making collective knowledge an essential component of modern security management.
Especially within the German capital region, trusted and long-standing co-operation with authorities and security partners remains a critical success factor. BER works closely with the supervisory authority, the Aviation Security Authority Berlin-Brandenburg (LuBB), alongside federal and state police agencies, intelligence services and other key stakeholders, including the security divisions of airlines operating at BER. These established partnerships support rapid information sharing, co-ordinated responses and a common operational understanding of an increasingly dynamic threat landscape.
Although the attack was not directed against BER itself, it had immediate consequences for airport operations and the physical security situation within the terminal environment.
The growing focus of attackers on operational technology further reinforces the need for integration. Systems that directly influence airport operations, such as access control, surveillance or communication infrastructure, are increasingly targeted because of their potential to disrupt operations. These systems are typically highly availability-critical, have long lifecycles and were not originally designed for today’s cyber threat environment. At BER, this challenge is addressed through a joint design approach in which cyber-security requirements and physical protection measures are developed together. The result is a layered architecture where digital and physical safeguards reinforce each other rather than operate independently.
Regulatory requirements also play a role in driving integration. Obligations related to critical infrastructure protection and reporting, including those towards authorities such as the German Federal Office for Information Security (BSI), require co-ordinated processes that span multiple domains. At BER, incident reporting, risk evaluation and compliance measures are therefore aligned across cyber and physical security functions. This reduces duplication, avoids conflicting priorities and ensures a consistent overall security posture.
The human factor as an active layer of defence
Despite all technological advancements, one factor remains central: the human element. Employees represent the final layer of defence, but also a potential vulnerability. At BER, this is addressed through a holistic approach that combines cyber awareness measures, such as phishing simulations, with physical security principles that rely on vigilance and structured reporting. Employees are not viewed as weak points, but as active sensors within the security system, capable of detecting anomalies that no technical system would identify on its own.
The strategic objective behind all these measures is clear. Security is not understood as the protection of individual assets, but as the ability to ensure stable airport operations under all conditions. This requires integrated situational awareness, co-ordinated response mechanisms and a consistent, risk-based allocation of resources. Security becomes an enabler of operational continuity and resilience, rather than a purely defensive function.
Berlin Brandenburg Airport has translated real incidents, evolving threats and regulatory demands into a coherent and operational model. The “One Security” approach, based on an all-hazards philosophy, connects cyber, physical and operational security into a single system. This integration allows dependencies to be managed proactively, threats to be identified earlier, and responses to be executed more effectively. In a hybrid threat environment, resilience is not the result of isolated excellence within individual domains, but of their seamless interaction. An airport is not a collection of systems. It is one system, and it must be protected as one.
This article first appeared in the Airport security in a geopolitically complex world eReport. Read the full report here.








No comments yet