When Boeing’s Product Security Engineering (PSE) team received an encrypted email in 2021 under the headline “potential vulnerability,” they swung into action.
The message came through a tip line managed by Boeing’s Vulnerability Disclosure Program (VDP), which encourages responsible reporting of possible vulnerabilities in Boeing products, systems, assets, software and services.
After reviewing the report from Pen Test Partners, a cybersecurity research group based in the United Kingdom, Boeing decided it was a good opportunity to make a security enhancement. Boeing then added Pen Test Partners to its Security Hall of Fame, which recognizes the first person or group to disclose a qualifying vulnerability.
“It’s important that we continue to sustain the resilience of our products throughout their lifecycle through initiatives such as the Vulnerability Disclosure Program.” - Laurel Matthew, risk management leader within Boeing Product Security Engineering
Laurel Matthew, risk management leader within Boeing’s PSE group, said companies are in a rapidly evolving threat environment. Multiple layers of protection, including software, hardware, and network architecture features are designed and installed to ensure the security of all Boeing critical flight systems.
“It’s important that we continue to sustain the resilience of our products throughout their lifecycle through initiatives such as the Vulnerability Disclosure Program,” she said.
Ken Munro, the founder of Pen Test Partners, said some aviation manufacturers don’t like standing up and talking about any bugs they might have, but not Boeing.
“Boeing was very open,” he said. “We disclosed what we found privately to them, and they received it well. They were very helpful in interacting with us, which is a big kudos to them.”
Since the VDP’s inception in 2019, Boeing Enterprise Security has reviewed and evaluated all submissions related to Boeing infrastructure, products and services.
Submissions related to products are forwarded to the PSE team, who investigate the concern and identify the best resolution.
Daniel Phillips, the operations lead for the Product Security Incident Response and Vulnerability Management team, said the work requires working collaboratively across the company to respond to potential concerns.
"A reported concern requires my team to efficiently understand systems and their technologies, stakeholder positions and perspectives, so we can effectively work together to formulate the appropriate response," he said.
Munro called his collaboration with Boeing a model for the industry.
“I’ve probably disclosed about 200 vulnerabilities per year to companies with disclosure programs in the transport and financial services sectors,” he said. “The most important part is having people with the right mindset, and Boeing really distinguished itself. They received the vulnerability, took it seriously, and proactively worked to fix the code.”
By Ivan Gale