The Vulnerability of Centralized Systems to Cyberattacks

The Vulnerability of Centralized Systems to Cyberattacks

Recent cyberattacks on water systems across various states highlight the dangers faced by cyber-physical systems that underpin critical infrastructures. These incidents are frequent enough now that people pay little attention unless directly affected. In 2024, over 859,000 cyberattacks were recorded, averaging nearly 100 per hour, with financial losses amounting to nearly $17 billion, a stark increase from $2.7 billion in 2018. Among these, nearly 4,900 attacks specifically targeted crucial infrastructure that supports both our physical and digital economies.

One significant attack targeted Canvas, a learning management system utilized by K-12 schools, colleges, universities, and corporate training centers. In May, a ransomware attack disrupted its services, impacting millions of users. Such attacks expose vulnerabilities in centralized data management sites, disrupting services for vast populations.

A crucial infrastructure affected daily by over 2.5 million people is air travel, dependent on centralized data management systems. These systems manage airline ticket processing, crew scheduling, and ground operations. A critical component is the passenger service system, overseeing the complete lifecycle of air passengers. These systems have grown complex over time, with features that allow agencies to sell tickets and assign seats. While centralization enhances the efficiency and fluidity of air travel, it simultaneously heightens vulnerability to cyberattacks, threatening to halt operations.

A recent cyberattack on European airports required a manual processing return due to system failures. Handling 2.5 to 3 million passengers daily in the U.S. manually would cripple the air system, challenging the Transportation Security Administration’s ability to conduct necessary security checks, thus compromising aviation security.

Another example of system vulnerability, not caused by an attack, occurred with American Airlines on July 28. A computer outage highlighted how susceptible cyber-physical systems have become. A similar incident resulted from a CrowdStrike software update bug in July 2024, forcing airlines to adopt manual check-ins and paper tickets temporarily. Delta Airlines faced about $500 million in losses due to canceled flights and refunds issued. While this disruption arose from an operating system update bug rather than a cyberattack, the damage was extensive, illustrating the impact when centralized data management systems fail.

Many other critical infrastructures implement centralized or hybrid management systems, aiming for more efficient oversight. These systems, while efficient, are prone to cyberattacks that can momentarily paralyze vital parts of our digital economy. The Federal Reserve operates through a decentralized network of 12 banks, yet many transactions pass through a centralized system. Any network compromise can delay payments and slow financial activities.

Centralization boosts efficiency and introduces vulnerabilities. This balance of benefits and risks is crucial in the design and function of complex systems. Our ever-connected digital economy necessitates ongoing evaluation of this balance, with frequent benefits frequently accrued, while risk management usually averts the worst outcomes. Nevertheless, adverse events, such as those encountered by Canvas, remind us of the inherent risks. These are the costs of a connected digital economy, a price paid routinely despite the lack of full awareness of the associated risks.

While rare, these events can be exceedingly disruptive and costly when they occur. For digital economy infrastructures, the consequences can be severe.

Sheldon H. Jacobson, Ph.D., is a professor of Computer Science at the University of Illinois Urbana-Champaign, focusing on data-driven risk-based decision-making in public policy evaluation.

© 2026 Nexstar Media Inc. All rights reserved. This material cannot be published, broadcast, rewritten, or redistributed.

Leave a Reply

Your email address will not be published. Required fields are marked *