Explore Elite Risk Management Services

Private Strategic Group

Search

Article

Insider Risk Lessons for Security Leaders Following Flight FZ1073

2 OCT 2026

/

7 min read


Open door to a large airliner as seen from the stairs.

When a trusted employee can cause serious harm within seconds, an organization needs more than a successful background check. It needs ongoing assessment, controls that limit what one individual can do, and people prepared to respond. The incident aboard flydubai flight FZ1073 brings that challenge into focus for security leaders well beyond aviation.

On September 30, 2026, the Dubai to Tel Aviv flight diverted to Tabuk, Saudi Arabia, following a security incident that injured crew members, according to the UAE General Civil Aviation Authority. Flydubai confirmed an altercation in the flight deck. The causes and motives remain under investigation, and both the regulator and the airline have cautioned against speculation.

For organizations reviewing their own exposure, the priority is to examine how trusted access could be misused without drawing premature conclusions about this incident.

Assess Evidence Before Drawing Conclusions

Insider risk assessments should test competing explanations and guard against confirmation bias. Grievance, coercion, financial pressure, and ideological motivation may be relevant in some cases, but none should be assumed here. Concerns should be assessed through observable behavior and context, with clear thresholds for proportionate action.

Test Security Controls Against Trusted Access

Aviation has spent decades strengthening protection against external attackers through cockpit security, restricted zones, and access controls.

Those safeguards remain essential. However, controls that prevent unauthorized entry can also increase the autonomy of someone already inside. Security leaders should test each critical control against a practical question: what happens if the authorized person misuses their access?

The same challenge applies across:

  • Nuclear and energy facilities
  • Ports and maritime operations
  • Logistics and freight
  • Data centers
  • Financial institutions
  • Healthcare
  • Defense manufacturing
  • Critical IT and operational technology environments

Start with roles where one person can cause the greatest harm, and then examine the access, authority, and safeguards around them.

Combine Personnel Security with Operational Safeguards

The 2015 Germanwings flight 9525 disaster demonstrated the potential consequences of trusted access being deliberately misused. The co-pilot initiated a descent into terrain while alone in the cockpit and kept the door locked.

The broader lesson is that assessing people and limiting harmful actions serve different purposes. Vetting and ongoing assessment can identify emerging concerns; operational safeguards can constrain what an individual can do. Both are needed, alongside support and reporting mechanisms.

Examine What One Person Can Do

For security leaders, the operational question is whether procedures and technical controls remain effective when a trusted individual acts outside their authority. Aviation provides examples of safeguards to examine, with requirements and implementation varying by operator and jurisdiction. Procedural safeguards include:

  • Clear rules governing cockpit occupancy and measures to address the risk of a pilot being locked out
  • Cockpit access protocols that balance protection against unauthorized entry with emergency access
  • Crew resource management training that enables colleagues to challenge unsafe actions
  • Pre-flight and turnaround security checks

Technical measures can support oversight and review. Flight data monitoring identifies deviations for safety analysis, while cockpit voice and flight data recorders support investigation and reconstruction. Access logs and credential controls do the same for restricted systems and compartments. Beyond these, any proposed behavioral or physiological monitoring requires careful assessment of reliability, privacy, and proportionality.

These measures perform distinct functions. A record that helps reconstruct an incident does not necessarily enable intervention as it unfolds. Organizations should establish which controls can prevent or interrupt harmful activity, which detect concerns, and which support learning afterward.

Procedures also depend on consistent application and on colleagues feeling able to challenge departures from them, regardless of seniority.

Match Safeguards to the Time Available to Intervene

Some insider activity may develop over weeks or months. In safety-critical roles, including in transport, power generation, and hazardous processes, the interval between an action and serious harm may be seconds.

That intervention window should shape the control design.

Where consequences can be immediate, organizations need safeguards that limit individual actions even when warning signs have been missed. Exercises should test whether escalation and intervention can happen within the time actually available.

Treat Vetting as the Start of an Ongoing Process

The International Civil Aviation Organization (ICAO) Insider Threat Toolkit recommends recurrent background checks and encourages continuous vetting. It recognizes that an intention to misuse access may develop after employment begins.

Organizations therefore need ways to identify changes in risk throughout employment, with assessment proportionate to the role and its access.

A workplace grievance or behavioral change is not evidence of malicious intent. A multidisciplinary process should bring relevant information together under appropriate privacy and confidentiality safeguards, establish thresholds for assessment, and determine whether support, additional controls, or further investigation is warranted.

The aim is to address emerging concerns before harm occurs while maintaining employee trust.

Relevant information may already exist across the organization:

  • HR may see deteriorating performance.
  • Security may record an access violation.
  • A manager may observe confrontational behavior.
  • Occupational health may identify a need for support, subject to confidentiality.
  • IT may detect unusual system activity.
  • Colleagues may notice a significant behavioral change.

None of these observations alone establishes a threat. Considered together by appropriately authorized specialists, they may warrant a closer assessment.

Build Response Capability into the Program

Flydubai stated that on-duty crew traveling on FZ1073 secured the aircraft and landed it safely at Tabuk. The investigation will establish the full sequence of events. The wider planning lesson is to ensure that employees understand when to escalate concerns and how to respond safely within their roles.

Security leaders should ask whether their teams can recognize warning signs, challenge unsafe behavior, and act when a control fails. Scenario exercises can expose unclear authority, slow escalation, or excessive reliance on a single individual. 

Crisis24 helps organizations assess insider risk and strengthen preparedness through consulting, program development, and exercises. Reviewing how personnel security, operational safeguards, and response plans work together is a practical place to start.

Sharpen your 
view of risk

Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.