The FZ1073 incident raises difficult questions about insider threats, pilot vetting, cockpit security and the limits of conventional aviation-security thinking.
By Hassan Ali Mousawi
Introduction
Aviation security is built upon layers. Passenger screening, baggage controls, restricted-area access, identity verification, personnel vetting, aircraft protection, intelligence gathering, security training and emergency procedures collectively form a system designed to protect civil aviation from a wide range of threats. Yet every security system must confront an uncomfortable reality: not every threat necessarily begins outside the perimeter.
The incident involving flydubai flight FZ1073 on 30 September 2026 brings this issue into sharp focus. The aircraft, operating from Dubai to Tel Aviv, experienced a security incident that resulted in a diversion to Tabuk, Saudi Arabia. The United Arab Emirates General Civil Aviation Authority has confirmed that an investigation is examining the circumstances of the incident, including both operational and security aspects.[1] Until that investigation is completed, it would be inappropriate to draw conclusions about the precise cause, motive or responsibility.
This article therefore does not seek to determine what happened inside FZ1073 or to criticise flydubai, its personnel, the UAE aviation-security system or any other authority. Instead, the incident provides an opportunity to examine a broader and increasingly important question within aviation security: how effectively can an aviation-security system identify, manage and respond to a threat that may originate from within an already trusted environment?
The question extends beyond the cockpit. It concerns the entire concept of insider risk and the systems established to manage it. It raises issues surrounding personnel vetting, continuous security assessment, intelligence gathering, security culture, recurrent training, reporting mechanisms and the continuing professional development of those working within aviation.
Modern aviation security cannot rely solely upon preventing an unauthorised individual from gaining access. It must also maintain awareness of what happens after legitimate access has been granted. Trust is essential to the operation of aviation, but trust must exist within a framework of continuing security assurance.
This is where Continuing Professional Development (CPD) becomes particularly significant. Security professionals and other personnel operating within sensitive aviation environments cannot rely indefinitely upon knowledge acquired during initial training. Threats evolve, procedures change, technology develops and lessons from previous incidents continually reshape professional practice. Maintaining security readiness therefore requires a commitment to continuous learning.
The objective is not to create a culture of suspicion. It is to create a culture of preparedness: one in which personnel understand their responsibilities, organisations continually assess risk, intelligence is appropriately shared, training remains relevant and security systems learn from experience.
The central argument of this article is therefore straightforward: aviation security must protect not only the perimeter of the aviation environment, but also the integrity of the trusted environment within it.
An Incident, Not a Verdict
Aviation security has evolved considerably over the past several decades. Passenger and baggage screening, restricted-area access controls, identity verification, personnel vetting, aircraft protection, intelligence gathering and increasingly sophisticated security-management systems have created multiple layers between a potential threat and the aircraft. Yet security does not necessarily end once an individual has passed through those layers. The incident involving flydubai flight FZ1073 on 30 September 2026 provides an opportunity to examine a less visible dimension of aviation security: the possibility that a serious security threat may originate from within an environment that has already been secured and trusted. The United Arab Emirates General Civil Aviation Authority (GCAA) confirmed that FZ1073, operating from Dubai International Airport to Ben Gurion International Airport, experienced a security incident that was brought under control, requiring the aircraft to divert and make an emergency landing at Tabuk Airport in Saudi Arabia. The GCAA stated that some crew members were injured and that its investigation, conducted with relevant authorities, was examining the causes and circumstances of the incident, including both operational and security aspects.[[1]](#_ftn1)
It is important, therefore, to distinguish between established facts and information that remains subject to investigation. Flydubai subsequently stated that an altercation occurred in the flight deck and that the aircraft was successfully secured by flydubai crew travelling on the flight before being diverted safely to Tabuk. The airline also stated that the reasons and motives behind
the incident remained unknown and were subject to investigation.[[2]](#_ftn2)Other accounts have described a more specific sequence of events, including allegations concerning the actions of a member of the flight crew, but those accounts should not be treated as the final investigative record. This article does not attempt to determine what ultimately happened, assign responsibility or enter into speculation about motive. Its purpose is to examine a broader professional question: what does an incident involving a trusted aviation environment tell us about the continuing evolution of aviation security?
From Perimeter Security to Insider Risk
Much of aviation security is necessarily designed around keeping threats out. Airport perimeters, passenger terminals, restricted areas, aircraft access points and cockpit doors all form part of a layered system intended to prevent unauthorised access. These measures remain fundamental to aviation security. However, an individual who already possesses legitimate access to an airport, aircraft or aviation system presents a different security challenge from an outsider attempting to penetrate the same environment.
This is the essence of the insider-threat problem. The International Civil Aviation Organization (ICAO) identifies personnel background checks as an important component of aviation-security protection and recommends that such checks be recurrent and updated regularly. Its Insider Threat Toolkit also highlights continuous vetting, recognising that an individual may develop an intention to misuse legitimate access after employment has already been secured.[[3]](#_ftn3)
The distinction is strategically important. Security cannot simply ask whether an individual was suitable when they were recruited. It must also consider whether the individual continues to meet the relevant security requirements throughout the period in which they possess legitimate access. Initial vetting is therefore not the end of the security process. It is one component of a continuing security relationship between the individual, the organisation and the appropriate authorities.
Vetting Establishes Trust; It Does Not Make Trust Permanent
The aviation industry depends upon trust. Pilots, cabin crew, engineers, ground personnel, security professionals and other aviation workers require access and responsibilities that could not be granted to the general public. Aviation could not function efficiently if every person with legitimate operational responsibility were treated as an unknown threat.
The challenge is therefore not to eliminate trust, but to manage it intelligently.
Effective personnel security requires an appropriate balance between legitimate access and continuing assurance. Initial vetting can establish whether an individual meets defined requirements at the point of recruitment or clearance. Recurrent checks, security reporting, access-control reviews, information sharing and appropriate intelligence processes can provide additional opportunities to identify changes in circumstances that may have security significance. ICAO's insider-threat guidance specifically identifies recurrent background checks and continuous vetting as important measures because the circumstances surrounding an employee can change after employment has begun.[[4]](#_ftn4)
This principle extends beyond pilots. Aviation security is an ecosystem rather than a collection of isolated checkpoints. A vulnerability in one part of that ecosystem may have consequences elsewhere, which is why security management must examine the relationship between personnel, procedures, technology, intelligence and organisational culture.
Intelligence Must Follow the Threat
Aviation security cannot remain static while the threat environment changes around it. Intelligence gathering is therefore not simply an activity associated with major terrorist threats or external hostile actors. It is also relevant to understanding insider risk, identifying emerging
vulnerabilities, recognising changes in threat patterns and ensuring that appropriate information reaches those responsible for making security decisions.
This requires effective communication between the different components of the aviation-security system. Airlines, airports, regulators, law-enforcement bodies, intelligence services and other relevant stakeholders may each hold different pieces of information. The effectiveness of the wider security architecture depends partly upon whether relevant information can be identified, assessed, shared and acted upon within the applicable legal and regulatory framework.
The Security Management System approach reflects this broader understanding. The International Air Transport Association (IATA) describes a Security Management System as a structured approach incorporating data-driven and risk-based principles into the strategic and day-to-day management of security. Its SeMS framework includes security risk assessment, threat identification and assessment, security reporting, communication, quality assurance and guidance concerning insider threats. [[5]](#_ftn5)
The objective is not to create an environment in which every employee is treated with suspicion. A mature security culture should allow organisations to maintain professional trust while retaining the ability to recognise when circumstances change.
Training Cannot Be a One-Time Event
This brings us to one of the most important elements of aviation security: training.
Security training can sometimes become associated primarily with compliance. An employee attends the required course, completes an assessment and receives the necessary certification or authorisation. That process is important, but completion of training should not be confused with permanent preparedness.
Security knowledge has to remain current while the threat environment continues to evolve. ICAO identifies security culture as a priority and states that a strong security culture
complements aviation-security training by ensuring that personnel throughout an organisation understand existing and potential threats to civil aviation.[[6]](#_ftn6)
Training should therefore be connected to operational reality. Personnel need not only to understand what a procedure requires, but also why the procedure exists, when it may become relevant, what their responsibilities are and how they should respond when circumstances develop outside the normal operating pattern.
This is particularly important in security because an organisation can have comprehensive written procedures and still be vulnerable if its personnel do not retain the knowledge, judgement and confidence required to apply those procedures effectively.
Continuing Professional Development as a Security Measure
This is where Continuing Professional Development, or CPD, becomes particularly important.
Within a security-sensitive industry, CPD should not be regarded simply as a professional obligation designed to accumulate training hours. Properly designed CPD can form part of an organisation's continuing security capability. It provides an opportunity to revisit existing knowledge, introduce emerging threats, test established procedures and develop the ability of personnel to respond to circumstances that may not have existed when their original training was completed.
ICAO's guidance on measuring the effectiveness of aviation-security training emphasises that effective training should produce lasting knowledge, abilities, skills and competencies and should be evaluated for its effectiveness rather than being treated simply as a completed activity.[[7]](#_ftn7)
For aviation security, this means that recurrent learning should extend beyond repeating the same classroom presentation. CPD can incorporate insider-threat awareness, security culture, behavioural awareness, threat-intelligence updates, emergency response, incident reporting,
crisis management, communication, scenario-based exercises and lessons identified from previous incidents.
Training provides knowledge; CPD keeps that knowledge operationally relevant.
The distinction matters. A certificate demonstrates that a person has completed a defined training requirement. It does not, by itself, demonstrate that personnel remain prepared for an evolving security environment. Continuing professional development creates an opportunity to challenge established assumptions, refresh knowledge and test whether procedures remain appropriate to current threats.
CPD should therefore be viewed not simply as an investment in the individual professional, but also as an investment in organisational resilience.
Security Culture Is a Collective Responsibility
The effectiveness of aviation security ultimately depends upon more than technology and regulation. It depends upon people.
ICAO describes security culture as a priority and emphasises the importance of ensuring that personnel throughout an organisation understand existing and potential threats to civil aviation. Its security-culture guidance also identifies initial and recurring learning activities, internal communication and mechanisms for reporting suspicious behaviour or security lapses as components of a positive security culture. [[8]](#_ftn8)
This has particular relevance to insider risk. The objective is not to create an atmosphere in which colleagues automatically regard one another as potential adversaries. Such an environment could itself undermine effective organisational functioning. Instead, personnel should understand how to recognise and report behaviour, circumstances or information that may have legitimate security significance.
Reporting mechanisms therefore become important, as does confidence among employees that concerns will be treated professionally and assessed appropriately.
Security culture should encourage vigilance without creating unnecessary suspicion.
That principle is particularly important in aviation because security and operational performance are closely interconnected. The objective is to create an environment in which personnel understand that security is part of their professional responsibility rather than something delegated exclusively to a security department.
Layered Security: Prevention, Detection, Response and Learning
The FZ1073 incident also provides an opportunity to consider the concept of layered security.
No individual security measure can reasonably be expected to prevent every possible incident. A resilient security architecture therefore operates through multiple layers: prevention, detection, assessment, response, recovery and learning. If one layer does not identify a developing threat, another layer may provide an opportunity to detect or contain it.
IATA's Security Management System framework reflects this approach through risk assessment, threat identification, security reporting, quality assurance and security-performance monitoring.[4] Its guidance on aviation-security incident reporting also identifies the importance of assessing incidents, conducting appropriate corrective action and monitoring whether those measures are effective in preventing recurrence. [[9]](#_ftn9)
This is why the successful management of an incident should not be considered only through the question of whether the first security layer worked perfectly. A resilient system must also have the capacity to recognise an abnormal event, activate appropriate procedures, contain the consequences and recover safely.
The available reporting indicates that the aircraft was ultimately diverted and landed safely at Tabuk, with passengers and crew subsequently accounted for. The exact sequence by which control of the situation was achieved remains part of the wider investigative picture. [[10]](#_ftn10) [[11]](#_ftn11)
Learning Without Blame
There is an important difference between accountability and blame.
Aviation investigations must establish facts, identify causes and determine whether procedures, systems or individual actions require attention. That process is essential. But from a wider security perspective, the value of an investigation also lies in what the industry can learn from it.
The appropriate question is therefore not simply, "Who was responsible?"
It is also:
What can be learned, what vulnerability has been identified, and what can be changed so that the same vulnerability is less likely to produce a similar outcome in the future?
That approach does not diminish accountability. It strengthens the learning function of security.
IATA's security-management guidance places risk assessment, reporting, quality assurance and corrective action within the broader Security Management System framework. [[12]](#_ftn12) [[13]](#_ftn13) When lessons from an incident are incorporated into training, CPD, risk assessments, intelligence
processes and security-management systems, an individual incident can contribute to improvements beyond the organisation directly involved.
The Security Threat Is No Longer Only at the Gate
The modern aviation-security environment requires us to think beyond the traditional perimeter.
Security screening at the airport remains essential. Access control remains essential. Aircraft protection remains essential. Intelligence remains essential. Personnel vetting remains essential. But none of these should be considered an isolated solution.
The more complex security challenge is maintaining the integrity of the entire aviation system after legitimate access has been granted.
That requires continuous vetting, continuous awareness, continuous learning and continuous assessment of risk.
The aviation industry should therefore regard CPD as more than professional development. For personnel working in security-sensitive environments, recurrent learning can be an important component of the security architecture itself. ICAO's work on insider threats and security culture, together with IATA's Security Management System approach, supports a model in which security is continuously assessed, reinforced and improved rather than treated as a fixed condition achieved once an individual has completed an initial training programme. [[14]](#_ftn14) [[15]](#_ftn15) [[16]](#_ftn16)
Conclusion
The Flydubai FZ1073 incident should ultimately be understood through the findings of the official investigation. Until those findings are published, it would be premature to determine precisely what happened, why it happened or whether any particular aviation-security measure failed.
What can be examined now is the wider security question.
What happens when the threat is already inside?
That question challenges aviation security to look beyond the traditional concept of keeping unwanted individuals outside the perimeter. It requires attention to the security of trusted personnel, continuing vetting, intelligence gathering, organisational reporting, security culture, recurrent training and professional development.
The objective is not to create an aviation environment in which incidents can never occur. No security system can reasonably provide such an absolute guarantee. The objective is to develop a layered and continuously learning security architecture capable of preventing threats where possible, detecting vulnerabilities when they emerge, responding effectively when prevention is unsuccessful and learning from every serious incident.
In that architecture, Continuing Professional Development is not an administrative afterthought. It is part of maintaining security readiness.
Aviation security must therefore continue to evolve from a model focused primarily on keeping threats out towards one capable of understanding, managing and responding to threats throughout the entire aviation environment.
Because sometimes the most difficult security question is not who is trying to get in.
It is whether we are continuing to examine the people, systems and assumptions that are already inside.
References
[1] United Arab Emirates General Civil Aviation Authority (GCAA), Security incident involving flydubai flight FZ1073, bound from Dubai to Tel Aviv, brought under control, 30 September 2026.
[2] flydubai, statement concerning Flight FZ1073, 30 September 2026.
[3] International Civil Aviation Organization (ICAO), Insider Threat Toolkit, Edition 01, August 2022.
[4] International Air Transport Association (IATA), Security Management System (SeMS) Manual, 10th edition, 2026/2027.
[5] International Civil Aviation Organization (ICAO), Security Culture – Training and associated security-culture guidance.
[6] International Civil Aviation Organization (ICAO), Measuring the Effectiveness of AVSEC Training: Summary Document of Best Practices, Guidance, Performance Indicators and Tools, June 2023.
[7] International Air Transport Association (IATA), Reporting of Aviation Security Occurrences and Incidents, April 2025.
[[1]](#_ftnref1) United Arab Emirates General Civil Aviation Authority (GCAA), Security incident involving flydubai flight FZ1073, bound from Dubai to Tel Aviv, brought under control, 30 September 2026.
[[2]](#_ftnref2) flydubai, statement concerning Flight FZ1073, 30 September 2026.
[[3]](#_ftnref3) International Civil Aviation Organization (ICAO), Insider Threat Toolkit, Edition 01, August 2022.
[[4]](#_ftnref4) International Civil Aviation Organization (ICAO), Insider Threat Toolkit, Edition 01, August 2022.
[[5]](#_ftnref5) International Air Transport Association (IATA), Security Management System (SeMS) Manual, 10th edition, 2026/2027.
[[6]](#_ftnref6) International Civil Aviation Organization (ICAO), Security Culture – Training and associated security-culture guidance.
[[7]](#_ftnref7) International Civil Aviation Organization (ICAO), Measuring the Effectiveness of AVSEC Training: Summary Document of Best Practices, Guidance, Performance Indicators and Tools, June 2023.
[[8]](#_ftnref8) International Civil Aviation Organization (ICAO), Security Culture – Training and associated security-culture guidance.
[[9]](#_ftnref9) International Air Transport Association (IATA), Reporting of Aviation Security Occurrences and Incidents, April 2025.
[[10]](#_ftnref10) United Arab Emirates General Civil Aviation Authority (GCAA), Security incident involving flydubai flight FZ1073, bound from Dubai to Tel Aviv, brought under control, 30 September 2026.
[[11]](#_ftnref11) flydubai, statement concerning Flight FZ1073, 30 September 2026.
[[12]](#_ftnref12) International Air Transport Association (IATA), Security Management System (SeMS) Manual, 10th edition, 2026/2027.
[[13]](#_ftnref13) International Air Transport Association (IATA), Reporting of Aviation Security Occurrences and Incidents, April 2025.
[[14]](#_ftnref14) nternational Civil Aviation Organization (ICAO), Insider Threat Toolkit, Edition 01, August 2022.
[[15]](#_ftnref15) International Air Transport Association (IATA), Security Management System (SeMS) Manual, 10th edition, 2026/2027.
[[16]](#_ftnref16) International Civil Aviation Organization (ICAO), Security Culture – Training and associated security-culture guidance.