Breaking NewsBusinessNiaja News

FlyDubai: Experts Call for Stringent Security Audit of Aviation Personnel to Avert Insider Threat

Chinedu Eze

Shocked by the averted terror incident involving FlyDubai air operations from Dubai to Tell-Aviv, experts in the aviation industry have called for more stringent scrutiny of aviation personnel.

An insider threat is a malicious threat to an organisation that comes from people within the organisation, such as employees, former employees, contractors or business associates, who have insider information concerning the organisation’s security practices, data and computer systems.

In the aviation sector, industry personnel who work at sensitive areas of the airport or the airlines are profiled regularly and are even monitored to know what they do outside work and the kind of relationships they keep.

Industry security consultant and CEO of Centurion Securities, Group Capt John Ojikutu (rtd) observed that major security challenge is caused by insider threat in which aviation security officials could be recruited by terrorists to carry out maximum damage at airport facilities.

“Insider threats can come from airport staff when and where there are no sufficient background checks on them before employment. There are others who have been disengaged but whose ID cards and On Duty Card (ODC) have not been retrieved from them and they somehow gain access to security-controlled areas. There are also issues of workers or contractors who are not adequately processed for access into to security-controlled areas.  

“There are many accesses into the security-controlled areas that need to be fortified, outside the 23km perimeter fence, especially around the cargo terminals, the general aviation operation terminals,” Ojikutu said.

In a telephone interview with THISDAY, Ojikutu identified ways insider threats could be averted in civil aviation.

According to him, there are about six primary defence layers in aviation security principally for passengers and those close to air flights

“These include pre-passenger ticketing screening. This requires your background checks or profiling before tickets can be sold to you: how many airlines do this? It is from here that the passengers on watchlist are separated from those on No-fly-list. Passengers on watchlist are given enhanced screening at all layers but those on No-fly-list are handed over to the State Security Services immediately,” he said.

After the general check-in and security screening process, Ojukutu said airline Check-in-Counter Screening is to recheck the pre-passenger ticket screening before the boarding pass is issued.

Other security screening procedure include hold or checked-in baggage screening, airport access control, airport passenger/carryon bag checkpoint screening; passenger Immigration and State Security Verification Checkpoint; airline boarding gate secondary/verification checkpoint and on-board security by Court Marshalls only known to the onboard airline captain.

“These procedures are adopted for the crew and anyone working around the aircraft on the apron and in the aircraft operating areas. The airport must have a security fence different or separated in regulated standard from the perimeter fence especially where the perimeter fence cannot be enhanced to meet the security fence standards. Murtala Muhammed International Airport (MMA), Lagos has no security fence and the perimeter fence has not been enhanced yet to meet the Standard for a security fence since the International Civil Aviation Organisation (ICAO) 2004 Audits Report had directed,” Ojikutu said.

Meanwhile, the attempted terrorist attack on FlyDubai Flight FZ1073, highlighted the severe and complex challenge of insider threats in commercial aviation. The late-September 2026 incident—where Omani co-pilot, Hamam al-Hammami used a cockpit crash axe to attack Captain Smit Machchhar in a failed attempt to crash the plane into Tel Aviv—proves that perimeter security is ineffective when the threat originates from within the flight deck. 

Reports indicate that aviation experts and investigators are focusing on key security vulnerabilities exposed by the incident.

The incident has forced aviation security organisations and government apparatus to review security measures taken in the past in response of terrorism attacks.  For example, since the September 11 attacks 2001 in the US, heavily reinforced and locked cockpit doors have been standard across the industry to protect the flight deck from external hijackers. However, as seen on Flight FZ1073, this design also creates an isolated space where a rogue pilot can lock out help. A catastrophe was only averted because Captain Machchhar fought back and managed to unlock the door, allowing off-duty crew and passengers to breach the cockpit and subdue the attacker. 

The incident exposed critical gaps in intelligence sharing and background screening. Al-Hammami had previously been banned from flying by Oman Air due to his radical, extremist views. Despite this, he managed to bypass screening protocols and secure a pilot position at FlyDubai in early 2026. This lapse has placed both Emirati and Israeli vetting procedures under intense scrutiny.

The co-pilot carried out the attack using the aircraft’s required onboard crash axe. While safety regulations mandate having these tools inside the cockpit for emergency evacuations, an insider with nefarious intent can easily weaponise them, turning a standard safety asset into a tactical vulnerability.

For years, airlines and manufacturers have advocated for moving toward single-pilot operations during the cruise phase of flights to cut costs. Security analysts note that if Flight FZ1073 had been operating under a single-pilot model, the attacker would have faced no immediate opposition, making a catastrophic crash almost inevitable. The incident heavily reinforces decisions by regulators, like the European Union Aviation Safety Agency (EASA), to restrict single-pilot frameworks.

The industry is now facing calls from global aviation bodies to shift focus from passenger-centric screening toward continuous human risk management and unified, international vetting registries for safety-critical personnel. 

THISDAY learnt that one of the most tragic air crashed attributed to insider threat was the 2015 Sharm El Sheikh aircraft explosion which is widely recognised as a classic example of an insider threat in aviation.

It was the downing of Metrojet Flight 9268 (also known as Kogalymavia Flight 9268) on 31 October 2015. The aircraft, Airbus A321 exploded and broke up mid-air over the northern Sinai Peninsula just 23 minutes after taking off from the Sharm El-Sheikh International Airport.

All 224 people on board—comprising 217 passengers and 7 crew members, predominantly Russian tourists returning to Saint Petersburg—were killed, making it the deadliest aviation disaster in Russian history.

The former Rector of the Nigerian College of Aviation Technology (NCAT), Samuel Caulcrick, reacting to the averted terror attack involving FlyDubai incident, said the aviation ecosystem was fundamentally built on trust, but warned that the system could be compromised when that trust was abused.

Caulcrick, explained that the FlyDubai Flight FZ1073 incident, had ensured the need for the industry to re-examine its approach to insider threats.

He identified operational trust, systemic trust and regulatory surveillance as the major pillars supporting aviation safety.

He said: “Pilots step into the cockpit trusting that engineers have released a perfectly airworthy machine, handlers have loaded cargo correctly and fuelers have provided the right grade and amount of fuel.

 “Trust is not left to chance. It is maintained through continuous surveillance, unannounced audits, mandatory safety reporting, and strict licensing. This is why aviation relies on a ‘Just Culture’ that encourages transparent error reporting.”

It is expected that international aviation regulators and governments would make radical changes in air transport system to further secure global air travel.

Leave a Reply

Your email address will not be published. Required fields are marked *