UNDERSTANDING DIGITAL RESILIENCE
Foresight and Navigation through Cyber Heavy Weather
You cannot stop the storms.
You can decide how to prepare, survive and thrive.
Expert perspectives on Strategic Cyber Foresight
Coordinator in the Executive Office of the U.S. President
former Senior Cyber Advisor in the U.S. government
for Cyber Policy in the U.S. National Security Council
Integration Center of the United States
Council on Foreign Relations (CFR) and author of The Hacked World Order:
How Nations Fight, Trade, Maneuver, and Manipulate in the Digital Age
a Senior Adviser in the Economic Security and Technology Department at CSIS
Public Affairs (SIPA) Cyber Program and founding member of the Office of
National Cyber Director at the White House
Reaching the Chasm: How to Drive Your Early-Stage Start-Up to Scale
CCTI at the Foundation for Defense of Democracies (FDD)
Real Scenario Walkthrough
On the evening of Friday, September 19, 2025, a cyber attack disrupted Collins Aerospace, a U.S.-based aviation technology vendor and subsidiary of RTX (formerly Raytheon Technologies). The attack hit Collins systems supporting MUSE (Multi-User System Environment), software that airlines use for electronic check-in, baggage drops, and boarding.
The disruption affected major European airports. On September 22, the EU’s cybersecurity agency, ENISA, confirmed that a ransomware incident caused the outage, though it did not name a perpetrator. Security researchers have since linked the intrusion to HardBit ransomware, and reports describe a phishing lure disguised as an RTX firmware update as the likely entry point, with more than 1,000 computers affected. The weekend travel disruption contributed to at least 217 flight cancelations and an estimated loss of millions of euros for affected airports and airlines.
Step 1: Insight
It’s early 2024, and you are the CEO of a company that owns an affected European airport. You are thinking about how to remain digitally resilient and consider the risk drivers that could bring a digital storm to your enterprise. How did your current technology dependencies create single points of failure? What unique cyber risk drivers apply specifically to your industry?
Understand your risk drivers
Technology
Check-in, bag drop, and gate assignments had been consolidated onto shared MUSE software used by many airlines and airports across Europe, creating a high concentration risk.
Cyber
According to external reports, Collins had outdated internet-facing systems, end-of-life VPN devices, and weak/valid credential exposure, along with potential prior data theft from a BianLian ransomware attack in 2023.
Geopolitical
Aviation and cyber regulation are fragmented — the EU’s NIS2 and the UK’s rules diverge from the lighter U.S. approach, leaving one vendor to answer to competing compliance regimes. Meanwhile, Russia has carried out repeated cyber campaigns against Western logistics providers and technology companies, including airports and air traffic management systems.
Step 2: Preparation
Develop “severe but plausible” scenarios that combine multiple risk drivers with your industry and company profile. How do the strands of technological, geopolitical, supply chain, and regulatory challenges combine to impact your airport’s operations?
Scenario planning for digital storms
You understand that when a shared vendor like MUSE goes dark, there will be delays, cancelations, and chaos. At some airports, passengers may stand in long lines while staff switch to pen and paper — manually verifying passenger information, writing baggage tags by hand, and checking bags. Gate changes would need to be coordinated through two-way radios rather than digitally.
Scenario planning turns those improvised workarounds into prepared ones. Working through this storm in advance identifies preparation steps that you can take now:
Explore alternative vendors and redundancies that would allow for critical processes even when MUSE goes dark.
Backup procedures prepared, practiced, and in place, such as leveraging radio and call signs for gate changes.
A business continuity plan with specific vendor outages and a recovery playbook for the failure of a key supplier.
Step 3: Execution
It’s September 2025, and the digital storm has arrived: check-in and baggage systems are down at your airport, flights are delayed or canceled, and lines of frustrated passengers swarm airline desks.
Airports couldn’t work on the repair because the software ran on Collins’ networks. However, Collins’ parent company, RTX, later told the SEC that MUSE runs on customer-specific networks kept separate from RTX’s own enterprise systems. Either way, the airports waited. Reporting also described Collins machines being reinfected after cleanup, which stretched the recovery out.
Apply the action steps to weather the digital storms
Execution puts your strategic preparation in place and response plans in action. It requires a navigator to own the practice of strategic foresight inside the organization. This navigator should be appointed before the crisis occurs.
Operations knew check-in ran through one platform. Procurement held the contract. Cybersecurity teams knew ransomware was hitting aviation suppliers. The navigator thought through these factors, put the pieces together, and pushed for an updated business continuity plan that included executing the workarounds established.
Step 4: Evolution
It’s now mid-2026. The digital storm has passed: RTX filed with the SEC on September 26, 2025, confirmed ransomware, and said it expected no material impact on the business. What did you and your organization learn from the digital storm, and how are the lessons being implemented?
Debrief the storm and identify actionable learning for future storms
Organizations should use a post-incident review to test whether their response plan actually held up under pressure, or whether confusion and improvisation carried the response instead. Potential lessons learned include:
Our check-in depends on one vendor with no substitute. This means we should establish an agreed number of desks able to run offline and test them.
Standalone check-in laptops, iPads, basic mobile tools, and manual operations with pen and paper helped us get by. Should we integrate those processes into staff training exercises?
We had no way to get status from the vendor while we were down, meaning we should add outage reporting terms at the next contract renewal.
Heathrow experienced ”minimal” disruptions and no cancelations related to the incident, whereas Brussels asked airlines to cancel nearly 140 flights. We should assess the differences in operations between the airports to strengthen resiliency.
Scenario Conclusion
Understanding Digital Resilience: Foresight and Navigation through Cyber Heavy Weather provides readers with the framework to respond to incidents like the Collins Aerospace while providing real-world and polycrisis scenarios to strengthen your toolset for effective strategic foresight.
Reach out to icr@nextpeak.net to learn more.
BEYOND THE BOOK
Sign up for updates
Fill out the form to get connected and receive updates straight to your inbox. Unsubscribe at any time.