By P. A. Jayakantha
Former Director General of Civil Aviation and Chief Executive Officer
ICAO Accredited International Auditor – USAP-CMA
The FZ1073 aviation security incident raises questions over cockpit access, insider threats, crew screening and ICAO security oversight.
Cockpit Security, Insider Threats and the Perspective of ICAO Annex 17 and USAP-CMA Audits
Reports concerning flydubai flight FZ1073, operating from Dubai to Tel Aviv on September 30, 2026, have brought renewed attention to a critical question for global aviation security: what happens when a person who is authorised to have direct access to the cockpit becomes a security threat?
The Boeing 737 MAX 8 was reportedly transmitting transponder code 7700, indicating a general emergency, and subsequently 7500, the code associated with unlawful interference or hijacking. Flight-tracking data showed the aircraft changing course before being diverted to Tabuk Airport in Saudi Arabia, where it landed safely.
The 7500 signal reportedly prompted Israeli security authorities to respond on the basis that the aircraft could potentially have been subject to a hijacking situation. Subsequent reports indicated that the incident may have involved a serious confrontation between two individuals on board, with one allegedly assaulting another.
The final official investigation into the incident has not yet been published.
The important security question, therefore, extends beyond the conventional scenario of an external individual attempting to hijack an aircraft. FZ1073 highlights the potential consequences when a person already authorised to access a critical area becomes the source of the threat.
A New Question for Aviation Security
Traditionally, much of the attention surrounding aircraft security has focused on one question:
“How can an unauthorized person gain access to an aircraft?”
FZ1073 raises another:
“What happens when a person who is authorized to have direct access to the cockpit becomes a security threat?”
This brings the concept of the insider threat into sharper focus: the risk that a person with legitimate access to a critical area within the aviation system could misuse that access and create a threat to the aircraft.
Aviation personnel may possess privileges and access unavailable to ordinary passengers. Depending on their role, they may have knowledge of aircraft control systems, cockpit access, an understanding of security procedures and, in certain circumstances, the ability to influence or control aircraft operations.
Conventional airport screening and perimeter-security measures alone may therefore be insufficient to address every such threat.
How Should This Be Examined Under ICAO Annex 17?
The International Civil Aviation Organization, through Annex 17 – Aviation Security, establishes Standards and Recommended Practices for protecting international civil aviation against acts of unlawful interference.
These include measures addressing unauthorised access to the flight crew compartment, weapons and other dangerous articles, personnel security, protective security measures and responses to acts of unlawful interference.
The question arising from FZ1073 is therefore straightforward but important: if the cockpit door is effectively protected against unauthorised external access, are existing measures sufficient to control a threat originating from someone who already has legitimate cockpit access?
ICAO has already strengthened its international aviation-security framework in response to insider threats. Amendment 17 to Annex 17 included revised provisions covering background checks, vulnerability assessments, training, access control and staff screening.
FZ1073 provides an opportunity to examine how effectively those principles address risks associated with authorised cockpit access.
How Did a Weapon Enter the Aircraft?
If the investigation ultimately confirms reports that a weapon was used, another important set of aviation-security questions arises.
Investigators should establish:
- What was the weapon?
- Who brought it onto the aircraft?
- How did it pass through the screening process?
- Was it an item a crew member could legitimately carry or access?
- Were screening procedures at the departure airport correctly implemented?
- Was the weapon obtained from somewhere inside the aircraft?
- What specific crew-screening arrangements were in place?
Answers to those questions should not automatically lead to the conclusion that there was simply a “screening failure.”
Establishing how an object reached the aircraft, who had access to it and whether established security procedures were correctly implemented requires evidence from the investigation.
Personnel Security
Another area highlighted by FZ1073 is personnel security.
For individuals performing security-sensitive aviation functions, appropriate background checks and recurrent security checks are important. Their purpose should not be to make assumptions about individuals, but to manage security risks on the basis of relevant security information and professional conduct.
Areas requiring review include:
- Initial background verification.
- Recurrent security checks.
- Security-related incidents.
- Access authorisation.
- Reporting mechanisms.
The adequacy of authorisation procedures for security-sensitive duties should also be examined.
Consideration could further be given to whether continuous background checks, already used in some technologically advanced States, could complement or replace traditional recurrent checks where appropriate and subject to applicable laws, privacy protections and proportionality.
The Insider Threat
Greater attention must now be given to the insider threat within aviation security.
A security threat does not necessarily follow only the conventional pathway:
External person → aircraft
It may also arise through:
Person with authorised access → misuse of that access → threat to the aircraft
National Civil Aviation Security Programmes and the security programmes of aviation stakeholders should therefore assess and manage risks associated with authorised persons and insider threats.
The objective is not to treat authorised aviation personnel as inherent security risks. Rather, it is to recognise that access privileges form part of the overall risk environment and require proportionate safeguards.
The USAP-CMA Perspective
The ICAO Universal Security Audit Programme – Continuous Monitoring Approach, or USAP-CMA, is a principal mechanism used to monitor States’ aviation-security oversight systems and their implementation of Annex 17 Standards.
USAP-CMA examines eight Critical Elements of a State’s aviation-security oversight system. Together, they cover the wider oversight framework, including quality control and the correction of security deficiencies.
In light of FZ1073, particular attention could be given to each of these areas:
CE-1 – Aviation Security Legislation
Does national legislation provide the Appropriate Authority with adequate powers relating to crew security, personnel security, weapons control and unlawful interference?
CE-2 – Aviation Security Programmes and Regulations
Do the National Civil Aviation Security Programme, or NCASP, and relevant regulations adequately address cockpit security, crew security and insider threats?
CE-3 – Appropriate Authority
Are responsibilities among government entities relating to aviation security clearly defined?
Are crisis-coordination arrangements among the airline, Air Traffic Control, airport security, police and military authorities adequate?
CE-4 – Personnel Qualifications and Training
Are the required qualifications and training adequate for flight crew, AVSEC personnel and aviation-security oversight personnel?
CE-5 – Technical Guidance
Is adequate technical guidance available for assessing and managing insider threats and threats involving authorised persons?
CE-6 – Certification and Approval
Do airport and airline security programmes and training programmes adequately address such risks?
CE-7 – Quality Control
Does the Appropriate Authority use audits, inspections and testing to verify that security measures are actually being implemented?
CE-8 – Resolution of Security Concerns
Are identified security deficiencies analysed, corrective action taken and implementation of that corrective action subsequently verified?
Eight Measures to Prevent Similar Incidents
Several measures could be considered to strengthen aviation security against these threats.
1. Introduce Flight-Deck Insider Threat Risk Assessments
Aviation organisations should separately identify internal security risks associated with flight crew and other authorised personnel who have access to critical areas.
2. Strengthen Personnel Security Measures
Subject to applicable legal and privacy requirements, initial and recurrent security checks, access-authorisation procedures and security-related reporting mechanisms should be reviewed.
3. Strengthen Crew Security Training
In addition to conventional hijacking scenarios, training and exercises should address situations involving a “violent incident involving an authorized flight-crew member.”
4. Review Cabin Crew Training
Procedures to be followed by cabin crew during a security incident involving the cockpit should be reviewed and reinforced.
5. Conduct ATC-AVSEC-Airline Joint Exercises
When emergency indications such as 7700 or 7500 are received, coordination among Air Traffic Control, the airline, airport security, police, military authorities and the Appropriate Authority should be tested regularly through table-top and full-scale exercises.
6. Review the NCASP and Operator Security Programmes
National and operator security programmes should be reviewed to ensure that insider threats and threats involving authorised persons are adequately addressed.
7. Strengthen Quality-Control Programmes
The question should not merely be:
“Does the procedure exist?”
It should also be:
“Is the procedure actually being implemented effectively?”
That should be verified through audit, inspection and testing.
8. Develop a Corrective Action Plan Following an Incident
Once the final investigation report becomes available, an appropriate Corrective Action Plan should be developed for any identified deficiencies, with the regulator verifying its effective implementation.
The purpose of ICAO USAP-CMA is not merely to identify deficiencies. It is also to prioritise corrective measures, verify their implementation and continuously improve aviation-security performance.
The Key Aviation-Security Lesson
The principal lesson emerging from FZ1073 is that strengthening the cockpit door alone cannot constitute a complete aviation-security solution.
A cockpit door is primarily intended to protect against unauthorised external access. If a person who already has legitimate cockpit access becomes a security threat, the response requires a wider integrated system:
Personnel Security + Insider Threat Management + Training + Cockpit Security + Risk Assessment + Emergency Response + Quality Control
These elements must operate together as an interconnected security system.
Final Observation
As the final investigation report concerning FZ1073 has not yet been released, it would be inappropriate to regard any currently reported explanation as the definitive account of the incident.
flydubai has confirmed that FZ1073 was diverted to Tabuk and landed safely. The airline has also said the causes and motives remain subject to official investigation and has urged against premature speculation.
Once the investigation is completed, however, the incident can provide a valuable learning opportunity for global aviation security.
The objective should not be to place blame on an individual or an airline. The essential question should instead be:
“What additional layers of security should exist within the system to prevent such an incident from occurring again?”
That approach is consistent with the philosophy of ICAO USAP-CMA: identify deficiencies, assess risks, implement corrective actions and verify that those measures are genuinely effective.
Aviation security cannot be achieved merely by protecting a door or a single screening point. It is a multilayered system involving people, procedures, technology, oversight and international cooperation.
The most important lesson FZ1073 may offer the global aviation-security community is:
“Authorized access does not necessarily mean zero security risk.”
Recognising that risk and managing it through reasonable and proportionate measures will be an increasingly important challenge for aviation security.
