Twenty-five years after the September 11 attacks, aviation security in the United States looks dramatically different.

Many of the measures travelers now take for granted…reinforced cockpit doors, advanced checkpoint screening, checked baggage screening, air marshals, stronger employee background checks and increasingly sophisticated identity verification…grew out of the fundamental reassessment of aviation security that followed 9/11.

The system is far from perfect. It continues to face questions about efficiency, consistency, privacy and the role of government versus private-sector screening. But there is no question that the aviation security environment today is substantially stronger than it was on September 10, 2001.

And perhaps the most important lesson from the past 25 years is this: security must continue to evolve because the threat continues to evolve.

The Creation of TSA Changed Aviation Security

 

The most significant structural change following 9/11 was the creation of the Transportation Security Administration.

Within roughly a year, the federal government built an organization of more than 50,000 employees and transferred responsibility for passenger screening at U.S. airports away from airlines and their contractors.

That was an enormous undertaking.

Before 9/11, passenger screening was ultimately an airline expense. Airlines hired contractors to meet federal screening requirements, but the regulatory standards themselves were inadequate for the threat environment the country faced.

The aviation industry also did not fully understand the level of threat confronting it, in part because of broader intelligence failures before the attacks.

Something had to change.

TSA has certainly experienced mistakes, growing pains and legitimate criticism during its history, but taking aviation security screening out of the hands of individual airlines was, in my view, the right decision.

One argument I strongly disagree with is the characterization of the entire airport security system as “security theater.”

No security system can guarantee 100% protection. That has never been a realistic goal.

The objective is to create reasonable layers of protection that make successful attacks significantly more difficult while giving travelers confidence that the aviation system is safe enough to use.

If the entire system were merely theater, adversaries would have successfully exploited it repeatedly over the past 25 years.

They have not.

Technology Has Transformed the Security Checkpoint

 

Technology has also fundamentally changed airport screening.

Over the past two decades, TSA has introduced increasingly sophisticated X-ray technology, upgraded metal detectors, body-imaging systems and facial recognition technology within portions of the passenger identification process.

One of the most important technological developments is the increasing use of Computed Tomography, or CT, scanners at passenger checkpoints.

The aviation industry has used CT technology for years to screen checked baggage. Now similar technology is replacing older X-ray equipment at checkpoints, giving security personnel a far more detailed view of the contents of carry-on baggage.

The result should ultimately be both stronger security and a more efficient passenger experience.

That second goal matters.

Immediately after 9/11, travelers were understandably willing to accept significant inconvenience and intrusive security procedures. They had witnessed the consequences of aviation terrorism firsthand.

Twenty-five years later, travelers expect security to work differently.

They want protection, but they also expect convenience. Showing up at an airport two or three hours before a flight simply to account for an unpredictable security process is increasingly difficult for travelers to accept.

The next generation of airport security must therefore become both more capable and less burdensome.

Some of the Most Important Improvements Were Policy Changes

 

Technology tends to receive the most attention, but one of the most consequential security improvements following 9/11 was much simpler: changing what passengers were allowed to carry aboard an aircraft.

Prior to the attacks, knives up to 4 inches in length were permitted aboard commercial flights.

That policy failure directly contributed to the ability of the 9/11 hijackers to take control of aircraft.

Changing those rules was one of the most important improvements the aviation security system made.

Other major changes included securing flight decks and dramatically revising protocols for responding to hijackings.

Thousands of federal air marshals were also hired and deployed, particularly on flights considered to present elevated risks.

At the same time, Congress addressed vulnerabilities that were not directly responsible for 9/11 but represented significant weaknesses in the overall aviation system.

The Aviation and Transportation Security Act of 2001 mandated improvements including checked baggage screening, air cargo security and stronger background-check requirements for aviation workers.

These layered measures are important because aviation security cannot focus exclusively on preventing the last attack.

It must identify vulnerabilities before adversaries exploit them.

Should Airport Security Become More Privatized?

 

The question of whether airport screening should remain primarily federal or become increasingly privatized will likely remain part of the aviation policy debate for years.

It is important to recognize that private screening already exists within the TSA system.

Through the Screening Partnership Program, airports can use private screening contractors rather than TSA-employed screeners.

The important distinction is that these contractors operate under TSA standards and TSA oversight. Neither airlines nor airports are not responsible for hiring or paying the screening workforce.

That is very different from the pre-9/11 model.

Recent proposals for privatization range considerably in scope.

Some would expand the Screening Partnership Program from its relatively limited number of participating airports to potentially hundreds of smaller airports.

Others have suggested going much further — eliminating TSA entirely, returning passenger screening responsibility to airlines and shifting regulatory responsibilities elsewhere in the federal government.

I believe returning to the pre-9/11 airline-controlled screening model would be a serious step backward.

Expanding the existing Screening Partnership Program deserves a more nuanced discussion.

The question is not simply whether private screening can work. We already know it can operate successfully in certain airports.

The more important question is whether the quality and consistency of that performance can be replicated across 200 or more airports.

Scaling a program from approximately 20 airports to hundreds is an entirely different operational challenge.

Why Airport Security Procedures Can Still Feel Inconsistent

 

Travelers frequently notice that screening procedures vary between airports.

Unfortunately, some level of inconsistency will likely continue.

One reason is technology.

Not every airport has the same generation of screening equipment. An airport operating newer CT scanners may have different procedures than a checkpoint using older technology.

There can also be differences in how federal policies and procedures are interpreted and implemented locally.

A substantial expansion of privatized screening could create additional consistency challenges, making strong federal standards and oversight even more important.

Travelers should not have to relearn the security process every time they enter a different airport.

As technology becomes more standardized, the industry should continue working toward a screening experience that is both predictable for passengers and effective from a security standpoint.

Teaching the Lessons of 9/11 to the Next Generation

 

One concern I have as we move farther away from September 11, 2001, is that the aviation industry may gradually lose some of its institutional memory.

At Metropolitan State University of Denver, we have deliberately taken a different approach.

MSU Denver was an early adopter of a dedicated Aviation Security course.

When we began teaching the course, we discovered there was not an accurate, current textbook capable of addressing the subject comprehensively, so Dr. Jeffrey S. Forrest and I wrote one.

Today, Practical Aviation Security: Predicting and Preventing Future Threats is in its fourth edition and is used by aviation and homeland security programs in universities across the United States and internationally.

Every student in our department is required to take a three-credit-hour aviation security course.

Unfortunately, some universities that created similar courses after 9/11 have since removed them from their curricula, sometimes replacing an entire aviation security course with a single chapter inside a broader airport management class.

That concerns me.

The farther we move away from 9/11, the easier it becomes to forget why many of today’s security systems exist.

The next generation of aviation professionals must understand not simply the procedures currently in place, but the history, vulnerabilities and threat environment that produced them.

The Next Aviation Security Threats Are Already Here

 

The traditional threats to aviation have not disappeared.

Bombings, hijackings and active-shooter events will remain part of the security landscape.

The insider threat is particularly difficult to prevent because individuals with legitimate access to aviation facilities and systems can potentially exploit that access.

But entirely new threats have also emerged.

Armed drones present a significant challenge to airports around the world. Technologies capable of addressing some of these threats clearly exist in the military environment, but regulatory and operational barriers continue to complicate civilian airport deployment.

Cybersecurity represents another major front.

Airports and aviation systems are increasingly interconnected. Cyberattacks against infrastructure occur every day, and the aviation industry has already experienced significant cyber incidents.

As a result, today’s airport security professional must increasingly understand both physical security and cybersecurity.

The two can no longer be treated as entirely separate disciplines.

That is why cybersecurity, drones and insider threats are now central topics both in our textbook and in the classroom.

The Most Important Lesson After 25 Years

 

Aviation security is fundamentally about adaptation.

The measures that protect aviation today are not identical to those introduced immediately after 9/11, nor should they be.

Technology changes.

Passenger expectations change.

Airports change.

And adversaries change.

The challenge for aviation security professionals is to improve convenience without sacrificing protection, embrace new technology without creating unnecessary vulnerabilities, and remember the lessons of the past while preparing for threats that may look very different in the future.

Twenty-five years after 9/11, the aviation security system is stronger than it was.

Our responsibility now is to make sure that another 25 years of distance does not become 25 years of complacency.

Jeffrey C. Price
Leading Edge Strategies
Professor of Aviation and Aerospace Science, Metropolitan State University of Denver
Co-author, Practical Aviation Security: Predicting and Preventing Future Threats