Airlines win relief from compensation when a hack delays flights

A new Transportation Department rule lets carriers skip meal vouchers and hotels for cyberattack delays if they meet security rules.

CSBadmin
2 Min Read

A cyberattack grounding a flight will no longer obligate the airline to put you up for the night, under a rule the Transportation Department published last week.

From next month, carriers that meet applicable cybersecurity regulations are cleared to skip meal vouchers and hotel rooms when a cyberattack causes a delay or cancellation.

The mechanism sits inside a broader rule. It adds a new cause-of-delay category for tracking data and trims air carrier duties to customers across 10 event types. Cybersecurity attacks, provided the carrier complies with security rules, is one of them.

Those 10 events are defined as not controllable, which strips the obligation to supply amenities or compensation through customer service plans when a disruption traces back to them. Sophie Hayashi, counsel in the transportation group at Crowell and Moring, laid out the effect in a client alert.

Airline customer service plans carry no legal force on their own, though the department insists it will hold carriers to the pledges they publish.

Advocacy groups are divided. FlyersRights complained the change skipped public comment and promised to watch for shrinking amenities, with president Paul Hudson arguing that cybersecurity is an airline responsibility and a hack-driven delay should not count as beyond the carrier’s control. The National Consumers League offered a more mixed reading.

That is the trade at the center of the rule. Conditioning relief on regulatory compliance gives airlines a reason to hit baseline controls. Skeptics answer that calling an attack uncontrollable also drains the pressure to build systems that survive one.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.