The 9/11 attacks reshaped American security thinking, most visibly in aviation. The creation of the Transportation Security Administration and its multi-layered security apparatus—from passenger screening to reinforced cockpit doors—was a direct response to a single catastrophic failure. Twenty-five years later, as cyber threats increasingly target critical infrastructure, cybersecurity has yet to absorb the same lesson: resilience must be built into the system itself, not just reported after the fact.

The gap is especially glaring as the Cybersecurity and Infrastructure Security Agency (CISA) prepares to finalize its Cyber Incident Reporting for Critical Infrastructure Act rules in September. Washington's policy focus remains heavily weighted toward mandatory breach reporting. But reporting a crisis does not prevent one. The TSA, ironically, has expanded its own cybersecurity mandates across transit networks, yet the agency's core design principle—independent, redundant layers—is being ignored in digital defense frameworks. These frameworks remain dangerously tethered to centralized, single points of failure.

Read also
Policy
Wage Theft: The $50 Billion Crime Corporate America Gets Away With
Wage theft strips U.S. workers of up to $50 billion a year—more than all street crime combined. Weak enforcement and corporate impunity keep it thriving.

The July 2024 CrowdStrike outage was a stark illustration. A routine software update to 8.5 million computers crippled airlines, banks, and hospitals worldwide, causing billions in damage. It wasn't a cyberattack; it was digital "friendly fire." When a CrowdStrike executive testified before a congressional subcommittee two months later, the central question wasn't just what went wrong, but how our critical infrastructure became so fragile.

The answer lies in design. Our digital world was built on a global technological monoculture—millions of organizations rely on the same vendors for system access. To fix this, we need to look at one of the most visible, criticized, yet ultimately successful security systems: aviation security.

To the average traveler, TSA checkpoints can feel like "security theater." But beneath the inconvenience lies a strategy that balances risk-based resource allocation with multi-layered defense. Just as the agency partitions off low-risk passengers to focus on unknown threats, digital defense must use automation to filter routine attacks, freeing human analysts to target sophisticated vectors.

Filtering alone isn't enough; it must be paired with the "Swiss cheese" model—multiple independent layers of security. Today, TSA uses AI tools like Credential Authentication Technology (CAT-2) for identity verification, alongside invisible tactics like federal air marshals. Every layer has flaws—Red Teams routinely slip banned items past checkpoints—but the system is designed to absorb local failures. A breach at the checkpoint doesn't compromise the air marshal or the hardened cockpit door. Together, these flawed sheets overlap to form a system more resilient than any single layer.

Cybersecurity claims to use layers, but those layers are often tethered to a single point of failure. When CrowdStrike's automated update failed, it didn't fail locally. Because the software operates at the kernel level—the structural foundation of the operating system—the faulty update brought down entire systems. When that single point snapped, the whole house of cards came down.

The environments dictate these differences. Physical terrorists are constrained by geography, physics, and resources. Cybercriminals can launch thousands of automated attacks daily. Because digital threats are relentless, exposed vulnerabilities will eventually be exploited.

The critical lesson cybersecurity must borrow from aviation is architectural compartmentalization. True independent redundancy isn't just installing two security tools that tie back to the same cloud or vendor—that's like building two emergency exits that lead into the same locked hallway. True resilience requires distinct, disconnected layers. If a faulty update crashes Layer A, Layer B must be isolated to keep the system online.

Ironically, the TSA already recognizes this. The agency has issued emergency cybersecurity mandates to force transit operators to secure their interconnected software networks. Physical security increasingly depends on cyber resilience. But this level of resilience is expensive. Developing, deploying, and maintaining independent layers of cybersecurity will increase costs, some of which may be passed to consumers. As the political debate over infrastructure spending intensifies, we must ask: what is the alternative?

In the security domain, physical or cyber, there is no such thing as a free lunch. We can pay an incremental premium today to build robust, multi-layered systems, or we can pay the catastrophic lump-sum invoice tomorrow while digging ourselves out of the rubble. The choice is clear—if we have the will to learn from 9/11.