The people already inside the fence are now aviation’s most consequential security exposure. ICAO has written the defences; most States have yet to adopt them. A white paper by Capt. Amit Singh FRAeS, Safety Matters Foundation.
Executive summary
The people already inside the fence are now aviation’s most consequential security exposure, and the world’s States are implementing the defences against them too slowly. ICAO’s Insider Threat Toolkit sets out what good looks like, but most of it is guidance that no State is obliged to adopt, and the binding Annex 17 Standards beneath it are themselves unevenly applied.
The numbers make the case. In September 2025 only 46% of States reached 75% effective implementation (EI) of ICAO security Standards, against ICAO’s own milestone of 65% by 2027 (ICAO GASeP). Global safety-oversight EI sits at about 69% (ICAO USOAP report 2022–2024). Scheduled commercial accidents rose from 66 in 2023 to 95 in 2024, with fatalities up from 72 to 296 (ICAO Safety Report 2025). Meanwhile airline net margins are forecast to halve to 2.0% in 2026 (IATA, June 2026), the kind of squeeze that historically lands on staffing, training and vetting first.
The Safety Management System experience shows what happens when a framework is adopted without a culture to carry it: Annex 19 arrived in 2013 and became fully applicable by 2019, yet only six States had undergone ICAO’s SSP maturity assessment by January 2025 (ICAO USOAP FAQ). Insider-risk management must not repeat that pattern.
This paper recommends three things:
- ICAO should convert the toolkit’s core elements (an insider-risk programme, recurrent and event-driven vetting, a just reporting channel, and peer support for safety-sensitive staff) into Standards with an applicability date, and audit them under USAP-CMA.
- States should not wait. They should adopt those elements now in national regulation, on a published 36-month timetable, as the EU did for enhanced background checks and pilot peer support.
- Operators, airports and service providers should run insider risk as a joint safety–security programme, with named accountability at board level and measures funded as operating cost, not discretionary spend.
The insider threat and ICAO’s framework
An insider is anyone whose job gives them trusted access or knowledge: employees, contractors, agency and temporary staff, and crew. ICAO frames the risk as aviation workers carrying out or enabling an act against the system, whether through lack of awareness, complacency or malice (ICAO toolkit; IMO–ICAO toolkit note). That definition matters: most insider events are not terrorism. They are smuggling, theft, corruption, data misuse, coercion, and, at the sharp end, impaired or suicidal people in safety-critical seats.
ICAO’s response sits in two tiers. A thin layer of binding Standards in Annex 17, and a much larger body of guidance that States may adopt or ignore.
| Instrument | Legal force | What it covers |
|---|---|---|
| Annex 17, Amendment 17 (adopted Nov 2019) (summary) | Standard: binding unless a difference is filed | Who needs a background check and when; screening of all non-passengers entering security restricted areas; randomness and unpredictability; insider risk from external service providers |
| Annex 17, Amendment 18 (Standards 3.5.2, 4.2.5) (toolkit) | Standard | Recurrent background checks at intervals set by the State; immediate withdrawal of access when someone is found unsuitable |
| ICAO Insider Threat Toolkit | Guidance | Enhanced and event-driven vetting, behaviour detection, explosive trace detection on staff, security culture, reporting, staff welfare |
| ICAO Insider Risk Workshop and pamphlet (2023) | Training | Building insider scenarios and applying ICAO risk methodology |
| GASeP, 2nd edition (June 2024) | Strategic plan | Six priority areas, including security culture and human factors; EI milestones for States |
The gap is in the second half of the table. The measures that catch an insider before an act (a reporting culture that surfaces concerns, recurrent vetting triggered by life events, welfare support for people in distress, and an organisation-wide insider-risk programme) are almost all guidance. A State can be fully compliant with Annex 17 on paper and still have none of them.
Threats in the present scenario
The insider threat today is broad, routine and mostly criminal, with a rare but catastrophic tail. Osprey Flight Solutions’ global incident database for January 2024 to May 2025 records insider-enabled narcotics trafficking at airports in more than 20 countries across every region, heavy insider-facilitated gold smuggling at several Indian airports, migrant smuggling by bribed immigration staff, passenger extortion, and theft from baggage and cargo (Osprey, July 2025). ICAO itself recorded 31 acts of unlawful interference in 2024 (ICAO Annual Report 2024).
The threat now falls into six groups:
- Infiltration by violent groups: staff recruited or placed by terrorist or militia networks to move weapons, explosives or people.
- Criminal facilitation: smuggling of drugs, gold, weapons and people; corruption at screening, customs and immigration.
- Sabotage and tampering: maintenance, ramp or catering access used to damage aircraft or systems, sometimes for grievance or money rather than ideology.
- Cyber and data misuse: credentials used to steal data, alter records or plant malware; recently dismissed staff whose access is not yet revoked.
- Impaired or suicidal crew: the safety-sensitive insider in distress, where the line between safety and security disappears.
- Organisational insiders: third-party ground handlers and contractors whose ownership, loyalties or vetting a State does not control.
Economic stress raises every one of these. Osprey assesses that inflation, cost cutting and financial hardship among staff increase the likelihood of criminal and malicious insider activity (Osprey).
Selected insider cases, newest first
| Date | Case | Insider type | Outcome |
|---|---|---|---|
| May 2025 | India’s BCAS revokes the security clearance of ground handler Çelebi on national-security grounds (newsonair; Tribune) | Organisational | Operations at 9 airports and over 10,000 staff moved to other handlers overnight; Delhi High Court upheld the order |
| May 2025 | Dozens of Beirut airport workers dismissed over suspected Hezbollah links (Osprey) | Infiltration | Alleged smuggling of gold and weapons |
| Nov 2024 | Seven customs officers at Islamabad investigated (Osprey) | Criminal facilitation | Military-grade night-vision equipment smuggled |
| Oct 2023 | Off-duty pilot in a Horizon Air jump seat tries to pull the engine fire handles (US DoJ; CBS) | Impaired crew | Crew restrained him; more than 80 people landed safely |
| Mar 2022 | China Eastern MU5735 dives from cruise (Bloomberg via Insurance Journal) | Possible deliberate act, not officially concluded | 132 killed |
| 2020 | Former flight-school instructor in Florida alters maintenance status of grounded aircraft (Osprey) | Cyber | Unairworthy aircraft shown as cleared to fly |
| Jul 2019 | American Airlines mechanic glues foam into a navigation system at Miami (Osprey) | Sabotage, financial grievance | Take-off rejected; three-year sentence |
| Aug 2018 | Credentialed ground service agent steals and crashes a Horizon Air Q400 at Seattle (FBI) | Lawful access misused | FBI found no security rule broken until the theft itself |
| Feb 2016 | Daallo Airlines: a security official carries a laptop bomb through screening at Mogadishu (Osprey) | Infiltration | Hull breached in flight; bomber killed |
| Oct 2015 | Metrojet 9268 bombed after departing Sharm el-Sheikh (CNN; ICCT) | Suspected airport insider | 224 killed |
| Mar 2015 | Germanwings 9525: co-pilot with concealed mental illness crashes the aircraft (EASA) | Suicidal crew | 150 killed |
Two lessons run through the table. First, several of these people held valid credentials and broke no rule until the act; access control alone would not have stopped them. Second, the deadliest events involve people inside the aircraft. Bloomberg’s analysis found that if intentional acts were counted, they would be the second-largest cause of airline deaths worldwide, and surveys suggest 4% to 8% of airline pilots have contemplated suicide, roughly the general-population rate (Bloomberg via Insurance Journal). A security system that screens bags but cannot see distress is guarding the wrong door.
Why aviation keeps lagging
Aviation lags because its global system is built on consensus and voluntary uptake, and the measures that matter most for insiders sit in the voluntary tier. Under the Chicago Convention a State must either comply with a Standard or file a difference; guidance material carries no obligation at all, and ICAO’s audits measure Standards, not guidance. A State that ignores the Insider Threat Toolkit loses nothing in its audit score.
Even the binding layer is weakly implemented. ICAO’s Global Aviation Security Plan aims for 65% of States at 75% EI by 2027, 80% by 2030 and all States by 2033 (GASeP 2nd edition). In September 2025 the figure was 46% (ICAO).
ICAO GASeP: share of States at or above 75% effective implementation of security Standards
| Year | Share of States | Status |
|---|---|---|
| 2025 (Sept) | 46% | Actual |
| 2027 | 65% | GASeP milestone |
| 2030 | 80% | GASeP milestone |
| 2033 | 100% | GASeP milestone |
Source: ICAO GASeP progress page (Sept 2025); GASeP 2nd edition milestones. A 19-point gap must close in two years.
Five structural reasons keep the gap open:
- Standards are slow by design. Amendment 17 to Annex 17, adopted in November 2019, made screening of all non-passengers and insider measures explicit, four years after Metrojet and Germanwings (summary).
- Deadlines bend. Even the EU postponed its new background-check and cybersecurity requirements because of COVID-19 (Regulation (EU) 2020/910).
- Change follows disaster. EASA’s pilot peer-support, psychological-assessment and alcohol-testing rules came three years after Germanwings and applied only from February 2021, six years after the crash (EASA; Hogrefe).
- Vetting runs into national law. Recurrent checks need access to criminal, intelligence and sometimes financial records, and cross-border sharing for a mobile workforce. Privacy, labour and data-protection law differ by State, and many authorities lack the legal basis or the systems.
- Security and safety are run in silos. Insider risk spans both. Security regulators own vetting and access; safety regulators own crew medicals and SMS; HR owns welfare. Nobody owns the person.
States can act without waiting for ICAO
Nothing stops a State from adopting the toolkit in national regulation today, and some already have. The EU made enhanced background checks binding, repeated at least every 12 months, and required every operator’s security programme to include an internal insider-threat and security-culture policy (Regulation (EU) 2019/103). India’s civil aviation ministry announced in 2019 that it treated insider risk as the next major challenge and would restrict staff movement and run periodic assessments (Hindustan Times), and in 2025 BCAS showed it can act within a day when a contractor raises national-security concerns.
What is missing elsewhere is predictability. Industry plans and budgets in multi-year cycles. A State that publishes a dated, phased timetable for insider-risk rules gives operators time to fund them and removes the excuse that the rules arrived without warning.
The SMS lesson: adopted on paper, unchanged in culture
Safety Management Systems were meant to move aviation from reacting to accidents to managing risk before it materialises. Annex 19 was adopted in 2013 and its State Safety Programme (SSP) and SMS requirements were fully applicable by 2019. Seven years on, the evidence is that many States have the documents but not the behaviour.
- Oversight capability is stuck near two-thirds. The global average safety EI was 68.67% across ICAO’s 2022–2024 audit triennium (ICAO USOAP report). An SSP sits on top of that oversight foundation; it cannot be stronger than it.
- Almost no State has had its SSP’s maturity independently assessed. By January 2025 ICAO had run SSP Implementation Assessments in only six States: Australia, Brazil, Canada, Czechia, Italy and Singapore (ICAO USOAP FAQ).
- Targets have slipped rather than been met. The 2023–2025 Global Aviation Safety Plan asked States to implement the foundation of an SSP by 2023 and have an SSP that is “present” by 2025 and “present and effective” by 2028 (GASP 2023–2025). The 2026–2028 edition removed the EI targets of its predecessor after States raised concerns (GASP 2026–2028).
- Regions report the same gap. ICAO’s Middle East group lists slow SSP development as one of the region’s main challenges, with three States still below 60% EI (MID SEIG/7). IATA’s ground-operations forum notes that SMS is applied at discretion in ground handling, which itself remains largely unregulated (IATA SIRM 30).
The reason is cultural, not technical. An SMS depends on people reporting errors and concerns without fear, and on managers acting on those reports even when it costs money. Where reporting is punished, where production pressure overrides risk findings, or where the safety manager has no access to the accountable executive, the SMS becomes a manual on a shelf.
Insider-risk management depends on exactly the same ingredients: colleagues who report worrying behaviour, a person in distress who asks for help, a supervisor who acts on a gut feeling. If we roll out the Insider Threat Toolkit the way SMS was rolled out, as a compliance document without a culture change, we will get the same result. The two programmes should be built together, on one reporting system and one just-culture policy, so that the investment in culture is made once and serves both.
Commercial growth versus safety and security
Aviation is carrying more people than ever on thinner margins and thinner staffing, and the safety record is already showing strain. Traffic passed pre-pandemic levels with more than 37 million departures in 2024, the same year the accident rate rose from 1.87 to 2.56 per million departures (ICAO Safety Report 2025). In 2026 the Middle East conflict and a fuel shock have cut forecast airline profits in half.
| Indicator | Value | Source |
|---|---|---|
| Passengers forecast for 2026 | Just over 5.1 billion | IATA, June 2026 |
| Passenger load factor, 2026 | 84%, a record | IATA |
| Industry net margin, 2026 | 2.0% (4.2% in 2025) | IATA press release |
| Net profit per passenger, 2026 | US$4.50 (US$9.10 in 2025) | IATA |
| Scheduled accidents, 2024 | 95 (66 in 2023) | ICAO |
| Fatalities, 2024 | 296 (72 in 2023) | ICAO |
| Ground-handling staff turnover, San Francisco | About 100% a year | Airside International |
| US screener vacancy rate, 2024 | About 20% | RSDI |
IATA notes the industry has never earned a net margin above 5%. When margins compress, the levers that move fastest are outsourcing, headcount, wages and training hours, and every one of them widens the insider gap:
- Turnover defeats vetting. A workforce that turns over every year is a workforce whose background checks are always new and whose colleagues never know each other well enough to notice a change. One airport study found that a 69% wage rise for entry-level screeners cut their turnover by 80%, and that retaining screeners improves breach detection (UC Berkeley Labor Center).
- Outsourcing fragments accountability. Ground handling, catering, cleaning and screening are often contracted out, and a contractor’s staff sit outside the airline’s culture and reporting lines. The Çelebi case showed how much of a country’s airside workforce a single contractor can hold.
- Financial stress is a motive. The 2019 Miami sabotage was committed by a mechanic in financial difficulty seeking overtime, and Osprey ties cost-of-living pressure directly to higher insider risk (Osprey).
- Commercial priority sets the tone. When on-time performance and aircraft utilisation are what gets rewarded, staff learn that raising a concern is a cost. That is the opposite of the culture both SMS and insider-risk management need.
None of this argues against growth. It argues that growth must carry its safety and security cost, built into fares, charges and contracts, rather than being financed by quiet erosion of the human layer.
What States and operators should do now
A State that starts today can have insider-risk management running and audited within 36 months, using measures already written by ICAO and already proven in Europe. The roadmap is phased so that each step can be funded and checked before the next.
| Phase | Actions | Gate |
|---|---|---|
| Months 0 to 6: Commit | Accountable executive named; gap analysis against the toolkit; national timetable published; one just-culture policy | Regulator approves plan |
| Months 6 to 18: Build | Insider-risk programme live; event-driven recurrent vetting; peer support for all crew; random staff screening | First audit passed |
| Months 18 to 36: Embed | Joint safety-security reporting; contractor clauses enforced; culture survey with public KPIs; State audit and ICAO review | Ongoing USAP-CMA oversight |
Foundation for all three phases: one reporting system and one just culture for safety and security.
The first phase costs little and signals intent; the second carries most of the expense; the third makes the programme permanent by putting it under audit.
For ICAO
- Elevate the toolkit’s core into Annex 17 Standards with a firm applicability date: an organisational insider-risk programme, event-driven recurrent vetting, a confidential reporting channel, and access to peer support for safety-sensitive staff.
- Add insider-risk protocol questions to USAP-CMA, so that implementation shows up in a State’s EI score.
- Issue joint safety–security guidance linking Annex 17 and Annex 19, so that States build one reporting and just-culture system, not two.
- Support a mechanism for cross-border sharing of vetting outcomes for crews and contractors who work in several States.
For States
- Publish a dated national timetable now, without waiting for an Annex amendment, and consult industry on cost.
- Make background checks recurrent and event-driven, with defined triggers such as a criminal charge, a disciplinary finding or a security incident, and revoke access immediately on an adverse finding.
- Mandate peer support and confidential help-seeking for pilots, cabin crew, controllers and engineers, with protection from automatic licence loss for those who come forward early.
- Require insider-risk clauses in every airside contract: vetting standards, staff turnover reporting, audit rights, and the right to suspend a contractor on security grounds.
- Create a single focal point that sees security, safety and HR signals about the same person, within national privacy law.
For airlines, airports and service providers
- Name an accountable executive for insider risk and report on it to the board, as for SMS.
- Run one reporting system for safety and security concerns, governed by a just-culture policy that staff can see is applied.
- Screen all staff entering security restricted areas, with random and unpredictable additional checks, and use explosive trace detection where the risk warrants it.
- Apply least-privilege access, both physical and digital, and revoke credentials on the day employment ends.
- Treat wages, rosters and turnover as security metrics. Track turnover by role and contractor and act when it rises.
- Measure culture: run an annual anonymous survey on willingness to report and trust in management, and publish the trend.
Conclusion
The insider threat is not new, and neither is the answer. ICAO has written the toolkit, run the workshops and set the milestones. What is missing is obligation and pace. Less than half of States meet ICAO’s own security implementation benchmark, the safety framework adopted in 2013 is still largely unassessed, and the industry is entering a period of record traffic and collapsing margins in which the human layer of defence is the easiest thing to cut.
Aviation does not have to wait for another Germanwings or Metrojet to act. Europe has already shown that States can turn guidance into law in a few years: enhanced background checks, mandatory insider policies and pilot peer support are all binding there. Every other State can do the same on its own authority, and ICAO can make it universal. The cost of acting is measured in programmes and salaries. The cost of waiting is measured in lives.
Figures are as published by the linked sources, accessed on 1 October 2026. Incident descriptions summarise public reporting; several investigations remain open, and no cause is asserted beyond what official or cited sources state. Views are those of the author.
Discover more from Safety Matters Foundation
Subscribe to get the latest posts sent to your email.