Securing the Skies: Aviation’s Top Security Leaders to Watch

Related

Share

Aviation runs on trust measured in safety margins, and its cybersecurity leadership carries a version of the same burden: operational technology that cannot go down, regulators on several continents, and passengers who never see the work unless it fails. The seven leaders below secure airlines from Dallas to Rotterdam, one of the world’s busiest international airports, and the factories that build the aircraft. Their common discipline is resilience under public scrutiny.

Arie Taal – CISO, Transavia

Arie Taal is the newest arrival on this list, appointed CISO of Transavia in August 2026, and his formation explains why the Dutch leisure carrier chose him. He has spent more than two decades as partner and director of his own Rotterdam advisory, FIN2ITion, fusing information security, privacy, IT audit, and governance for organisations where IT security and physical security converge. The preceding years read as a tour of Dutch critical services and commerce: programme manager in the CISO office at grid operator Enexis, CISO of Avans Hogeschool where he built an organisation-wide security strategy and won board funding for a multi-year continuity programme, and before that programme director for security and data privacy across Albert Heijn, Gall & Gall, and Etos. He also designed the group-wide security architecture roadmap at SD Worx and ran GDPR implementation training for some 400 staff at UWV. His self-described strength is translation: turning NIS2, ISO 27001, supply chain risk, and incident governance into programmes boards can actually decide on.

Marcio Garcia – Group CISO and CTO, International Airlines Group

Holding the group’s technology and security mandates at once, Marcio Garcia occupies one of aviation’s widest briefs. Group CTO of International Airlines Group since September 2023 and Group CISO since November 2024, he sets security and technology direction across British Airways, Iberia, Vueling, and Aer Lingus from London. His route was engineering rather than audit, but security runs through it: before six and a half years at Vueling rising from cloud architect to head of data and cloud architecture, he spent nearly four years as an infrastructure and solutions architect at TAP Portugal, and before that worked as a systems and security engineer at AnubisNetworks, a systems and security architect at Bizdirect, and an infrastructure and security specialist at Vertical One, implementing ISO 27001 policy alongside the platforms. Thirty years in IT, much of it spent automating the systems he now secures, gives him a builder’s view of airline technology estates. When the person accountable for the platforms is also accountable for their protection, trade-offs get made with both sides of the ledger visible.

Shawn Irving – CISO, American Airlines

Shawn Irving has come back to where he started. He became VP and CISO of American Airlines in June 2024, more than twenty years after serving as the carrier’s IT security manager from 2001 to 2004. The intervening career gave him breadth few aviation security chiefs can match: six years as CISO of distributor Ferguson plc, three as VP and CISO of Michaels Stores, and seven years at Southwest Airlines, where he rose through IT audit and compliance to senior manager of information security services, designing and delivering an enterprise-wide, multi-year roadmap across a complex multi-data-centre environment with a team of 85. Earlier still came IT audit leadership at Sabre, Centex, and Brinker International, and five years at Comerica Bank as a telecommunications risk and control specialist. Corporate finance, internal audit, infrastructure operations, and outsourcing negotiation all feature. At the world’s largest airline by fleet, that operational range matters more than pedigree.

Christian Keller – Head of Information Security, Swiss International Air Lines

A decade is a long time to defend one airline, and Christian Keller has led information security at SWISS, based at Zurich Airport, since February 2016. His title understates a remit covering security management, IT compliance, and risk for the Lufthansa Group flag carrier, and his staying power says something about delivery. The formation was Switzerland’s financial plumbing: five years as security officer at SIX Group, the stock exchange operator, handling corporate security management and PCI compliance. Before that he sold and built security technology rather than governed it, as a partner and CIO at ASec IT Solutions representing security vendors across Germany, Switzerland, and Austria, and in roles at Oracle, Resilience, and Tufin, after six and a half years at Check Point and a start as a security engineer at Sun Microsystems in 1997. Nearly three decades into the field, Keller represents the vendor-fluent, finance-hardened strain of European airline security leadership.

Mick McHugh – Group CISO, Virgin Australia

Government cyber programmes were Mick McHugh‘s training ground, and the pace of the private sector seems to suit him. Group CISO of Virgin Australia since December 2023, based in Brisbane, he builds enterprise cyber maturity for an airline mid-transformation while keeping the board engaged on technology risk. He arrived from Tabcorp, where he served eighteen months as CISO after leading the wagering group’s threat intelligence function, and before that spent more than five years in the Australian Government, first as Director of Cyber Analysis in Canberra and then coordinating global programmes out of Melbourne. His self-description emphasises commercial acumen and leading by action rather than framework recitation, and his career backs it: national-level analysis, threat intelligence, wagering industry security, and now aviation, each move closer to operations that cannot pause.

Patrick Reidy – CISO, GE Aerospace

Every aircraft engine GE Aerospace ships carries software and data that Patrick Reidy‘s organisation protects. CISO since November 2020, based in Cincinnati, he leads security for the aerospace manufacturer at a moment when supply chain and OT security have become board-level aviation concerns. The preparation was unusually broad. He spent five years as CISO of the FBI, running global security strategy, operations, and architecture, building insider threat programmes and countering advanced persistent threats. He then moved to CSC, first as its global CISO and then as Vice President and General Manager of a 2,000-person cybersecurity business unit delivering managed and consulting services across a dozen countries. Five years as SVP and CISO of L Brands followed, covering Victoria’s Secret, Bath & Body Works, Pink, La Senza, and Henri Bendel. Earlier came six years as a principal information security engineer at MITRE and five as chief engineer of commercial security operations at Trident Data Systems. Aerospace security is aviation security’s upstream half, and Reidy holds it.

Mark Ward – CISO, Heathrow

Recovering from a major cyber incident is the assignment nobody wants, and Mark Ward took it. Interserve engaged him in 2020 to direct a multi-stream investigation and recovery programme after a serious breach, coordinating internal teams, external consultants, law enforcement, and regulators through a four-month restoration, then asked him to take on the Group CISO role alongside it, where he ran a cyber uplift programme, stood up an outsourced 24/7 SOC, and moved the business onto an ISO 27000 framework. He came to that assignment already seasoned: Group CISO of Provident Financial, CISO of Vanquis Bank, CISO for RSA’s Scandinavian business, and security lead for the RBS spin-out Williams & Glyn. Nearly four years as CISO of Three UK followed, building a strategy spanning technical, information, and physical security for the mobile operator while chairing the industry’s Communications Crime and Strategy Group. He has been CISO of Heathrow since October 2025.

What This Group Says About Aviation Security

Airlines learned early that trust is the product, and these seven careers show the sector’s security leadership maturing the same way. They come from federal investigation, exchange operators, retailers, consultancies, and audit rooms, not from a single pipeline, and they converge on the same requirements: operational resilience, regulatory fluency, and calm under incident pressure. Aviation’s attack surface now runs from engine factories to departure boards. This is the bench securing it.

Related reading:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.