MENA News
Oct 2, 2026


Yusuf Hasan, Senior Aviation Security Advisor at ICAO, discusses the practical challenges of building aviation security systems that can adapt to changing threats, make effective use of technology and develop lasting national capability across the Middle East.
[For more news, click here]
Aviation security depends on more than regulations, screening systems and periodic assessments. As airports expand and security risks evolve, authorities also need the people, institutional structures and processes to apply those measures consistently and improve them over time.
For Yusuf Hasan, Senior Aviation Security Advisor at the International Civil Aviation Organization (ICAO), the practical experience of working across these different environments has reinforced the importance of implementation. Hasan has worked across aviation security and capacity-building initiatives in the region, including through CASP-MID, the Cooperative Aviation Security Programme for the Middle East, which supports states in strengthening aviation security implementation and developing sustainable national capabilities.
In this exclusive interview with Tech Revolt, Hasan discusses what makes aviation security frameworks effective in practice, why closing an assessment finding is not the same as reducing risk, and where technology and regional cooperation can contribute to stronger and more sustainable national capabilities.
1. From your work across the Middle East, what have you learned about the factors that make aviation security frameworks work effectively in practice?
One of the main lessons I have learned is that a security framework is only as effective as its implementation on the ground. Having legislation, regulations and procedures in place is important, but it is not sufficient.
In my experience across the Middle East, the most effective frameworks are built around three things: clear accountability, competent people, and continuous improvement.
First, everyone needs to understand who is responsible for what, from the regulator and airport operator to airlines, security service providers and frontline personnel. Second, we need sustainable capacity: trained people, effective supervision, appropriate
resources and strong management systems. And third, security has to be continuously tested and improved through inspections, audits, covert tests and corrective actions.
I have also learned that we cannot simply take a model that works in one country and copy it into another. The framework has to respect the national context while still achieving the required security outcomes.
Ultimately, I would say that a good aviation security framework is one that translates international standards into practical, measurable and sustainable security outcomes.
2. When a security assessment identifies a vulnerability, what determines whether it leads to meaningful improvement rather than simply a documented finding?
The assessment itself is only the starting point. The real value comes from what happens after the finding is identified.
I would look at four things: ownership, root cause, corrective action and verification.
First, there must be clear ownership. Someone needs to be accountable for addressing the vulnerability. Second, we need to understand the root cause rather than simply treating the symptom. Is the issue related to legislation, procedures, training, supervision, resources, technology or organizational culture?
Third, the corrective action needs to be specific, realistic and risk-based, with clear responsibilities and timelines. And finally, there needs to be verification that the corrective action actually worked.
This is particularly important because sometimes an organization can close a finding administratively without necessarily reducing the underlying risk.
Success would be measured not by the number of findings closed, but by whether the vulnerability has actually been reduced and the improvement can be sustained over time.
3. How is technology changing the way aviation security risks are identified and managed, and where do you see the greatest potential for it to make a practical difference?
Technology is fundamentally changing aviation security from a model that has traditionally been heavily dependent on periodic inspections and compliance checks toward one that can become much more data-driven, predictive and continuous.
We now have the ability to bring together information from security screening systems, access control, incident reporting, audits, inspections, training, passenger and operational data, and other sources to identify patterns and emerging risks.
There is strong potential in three areas:
Risk intelligence and analytics — using data to identify patterns and prioritize emerging threats.
Smart screening and detection technologies, including advanced imaging, biometrics and automated threat detection, which can improve both security effectiveness and operational efficiency.
Third, digital assurance and performance monitoring. Instead of waiting for an assessment to identify a problem, authorities can increasingly monitor indicators continuously and intervene earlier.
But technology is an enabler, not the solution by itself. It needs to be supported by competent people, good governance, appropriate procedures and strong cybersecurity.
So my view is that the greatest practical opportunity is not simply introducing more technology, but using technology to help decision-makers see risk earlier, allocate resources better and measure whether security measures are actually working.
4. How can a risk-based approach help aviation authorities determine where limited security resources will have the greatest impact?
A risk-based approach allows authorities to move away from treating every security issue as having the same priority.
Resources are always limited, so the question becomes: where can a particular resource reduce the greatest security risk?
I would start by assessing the threat, the vulnerability and the potential consequences, and then consider the effectiveness of existing controls. This allows authorities to distinguish between risks that require immediate intervention, risks that can be managed through existing measures, and areas where additional investment may provide limited additional security benefit.
It also helps authorities make better decisions about where to invest in people, training, technology, infrastructure and oversight.
For example, rather than simply increasing resources across the entire system, an authority can identify the specific airport, process, threat, passenger flow, cargo operation or security function where the risk is highest and target resources there.
Importantly, risk-based security does not mean reducing security. It means putting the strongest controls where they produce the greatest reduction in risk.
That is particularly important in aviation because security has to be effective while maintaining operational efficiency and facilitating legitimate travel and trade.
5. How can regional cooperation strengthen aviation security when airports and authorities operate under different national systems and requirements?
Regional cooperation is extremely important because aviation threats do not stop at national borders, while our regulatory and operational systems often do.
In the Middle East, I have seen that countries can have different legislation, institutional structures, resources and operating environments, but they often face many of the same security challenges.
Cooperation can therefore add value in several ways: sharing information and good practices, harmonizing approaches where appropriate, developing common capabilities, conducting joint training and exercises, and learning from each other's experiences.
But regional cooperation does not mean that every country needs to have an identical system. The objective should be to establish a common security outcome and facilitate interoperability while respecting national requirements.
This is where regional programmes such as CASP-MID can play an important role — bringing States together, identifying common needs, supporting capacity building and helping translate international standards into sustainable national capabilities.
I also believe that cooperation should move beyond individual training activities. The real objective should be to build long-term regional capacity and communities of practice, so that countries can continue learning from each other after a particular project or mission has finished.
Ultimately, regional cooperation makes the aviation security system stronger because the security chain is interconnected — the overall system is only as resilient as its weakest link.
A Changing Security Landscape
Aviation security will have to keep up with a sector that is growing and becoming more reliant on technology. For governments and aviation leaders, that means continuing to invest in experienced people, strong institutions and the systems needed to keep security measures working as operations change.
The Middle East is a good example of the challenge. Aviation is expanding quickly across the region, while each country has its own regulations, infrastructure and way of
working. Keeping security standards high will require countries to continue working together and developing the expertise to deal with new risks as they emerge.
Technology will continue to change how aviation security is managed, but the people responsible for making those systems work will remain central to the process.

Related Articles
Zest Equity on the Next Generation of Private Market Infrastructure
Exclusive: Nikita Astionov on the Security Risks of Giving AI Agents More Control
How Can Gulf Enterprises Measure Their AI Security Readiness? SANS Institute Has a Framework
Related Articles