Skip to content

Security1 publisher2 min readPublished

DOT lets compliant airlines skip hotels and meals after a cyberattack delay

The Transportation Department's final rule drops amenity obligations for ten causes of disruption. Cyberattacks qualify only while the carrier can show compliance with applicable cybersecurity regulations, language Crowell & Moring calls notably broad.

The Watch · Security desk

Illustration accompanying DOT lets compliant airlines skip hotels and meals after a cyberattack delay

What happened

  • The Transportation Department published a rule last week that establishes a new cause-of-delay tracking category and reduces air carrier responsibilities to customers across 10 kinds of events.
  • From next month, airlines have federal clearance to withhold meal vouchers and hotel rooms when a cyberattack cancels or delays a flight.
  • Cyberattacks are on the list of 10, with a condition attached: the air carrier must be in compliance with applicable cybersecurity regulations.
  • Because the 10 causes are deemed not controllable, carriers are no longer obligated under customer service plans to provide amenities or compensation, Crowell & Moring counsel Sophie Hayashi wrote in a client alert.
  • A Department of Transportation spokesperson said Congress explicitly directed the department to make these changes in the FAA Reauthorization Act of 2024.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Passengers absorb the hotel and meal cost of a cyber-driven cancellation whenever the carrier can show it was following the applicable rules.
  • exposure The compliance record a security team can produce about an outage becomes the document that decides whether the airline owes passengers anything.
  • decision Airline cyber compliance spending now has a measurable payback, because demonstrable compliance is what removes the amenity bill after an attack.
  • precedent DOT already ruled the 2024 CrowdStrike outage within airline control, so the argument after the next mass aviation IT failure will be over whether it was an attack or a vendor defect.

The rule's reference to applicable cybersecurity regulations is "notably broad," said Kate Growley, a partner at Crowell & Moring [9]. Growley said the breadth may have been deliberate, because "Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected" [10]. One body of rules already reaches carriers: in 2023 the Biden administration imposed cybersecurity regulations on airports, aircraft owners and aircraft operators, citing "persistent cybersecurity threats" in the sector [11].

Carriers who cannot demonstrate compliance will be subject to customer and other requirements, Hayashi said [8]. A carrier that claims the exemption after a cyber-driven cancellation is also claiming that its security program met the regulations that applied to the incident.

No one has tallied what the exemption saves airlines, and there is no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to hand out meal vouchers or hotel rooms [12].

One of three recent incidents reached airline systems directly [1]. Scattered Spider attacked airlines last summer [13]. Last year's attack on Collins Aerospace led to delays in Europe [14], and the 2024 IT outage tied to CrowdStrike grounded flights without being a cyberattack at all [15].

The obligations at issue sit in airline-authored customer service plans, which are not legally binding [6]. DOT has maintained it will hold airlines "accountable" for those pledges [7].

FlyersRights said the change came without giving the public a chance to comment, and that it would monitor the impact and track any reduction in amenities [17]. Paul Hudson, the group's president, told CyberScoop that "cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant" [18]. Hudson said the group had previously urged stress tests for airline computer systems "that are going down often" [19].

John Breyault, vice president of public policy at the National Consumers League, said the compliance condition might still protect consumers [23]. He credited one earlier rule: it "gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren't beholden to the whims of the airlines," Breyault said [20]. His worry is another entry on the list of ten, unscheduled maintenance, which he said airlines could stretch to avoid compensating passengers [22]. Breyault also said "it's clear to us that the DOT seems inclined to try and make the rules a little less onerous" [21].

What to watch

  • Whether DOT issues guidance identifying which cybersecurity regulations satisfy the exemption's compliance condition.
  • The first cancellation an airline attributes to a cyberattack after the effective date, and whether DOT tests the carrier's compliance showing.
  • Whether FlyersRights or another group challenges the rule over the missing comment period.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories