The Aircraft Part You Can't Hold in Your Hand
- Craig Reid

- Jul 20
- 5 min read

On 30 October 2025, a JetBlue Airbus A320 experienced something that most passengers would find incomprehensible. The aircraft pitched down - uncommanded. Not because of a mechanical failure, nor because of pilot error. Because solar radiation had corrupted data inside the flight control computer.
The autopilot remained engaged, and the altitude loss was brief. But the event triggered one of the most significant rapid-response airworthiness actions in recent aviation history, an Emergency Airworthiness Directive from EASA requiring immediate software modification or hardware replacement across the entire global A320 family fleet before next flight.
More than 6,000 aircraft. Fixed in under 48 hours. Most passengers boarding an A320 that week had no idea it had happened.
Software is an aircraft part
There is a concept in aviation maintenance that the general public has never needed to understand. Software is treated as an aircraft component.
It has a part number, a version standard, and it has an approved configuration that must be maintained, documented, and verified in exactly the same way as a hydraulic actuator or a brake assembly. When software changes, whether through an update, a modification, or in the case of the JetBlue incident, corruption by external interference, it triggers the same airworthiness management process as any other component change.
The ELAC (Elevator and Aileron Computer) software standard at the centre of the November 2025 event was designated L104. The Emergency AD required operators to replace it with L103+ or replace the hardware entirely before the aircraft flew passengers again. That is a part number change on a maintenance release. The fact that the "part" in question is lines of code rather than a physical object is irrelevant from a regulatory standpoint.
Airlines manage software configuration across their fleets with the same rigour they apply to physical components, part number tracking, approved configuration lists, embodiment records, and maintenance system entries that track every change. A software update that hasn't been properly loaded, verified, and documented is a non-conformance in exactly the same sense as an unapproved part.
Most people outside the industry have never thought about this, but the November 2025 event made it impossible to ignore.
The Qantas data hack and what it means for aviation
This week The Australian reported that Qantas is navigating scrutiny over a significant data breach, involving passenger information. Whilst not directly related to aircraft software, the data story is relevant to a broader conversation the industry needs to have more loudly: cyber integrity in aviation is no longer purely an IT problem. It can also be an airworthiness problem.
Modern aircraft are not sealed mechanical systems. They are networked digital platforms that receive, transmit, and process data continuously, from maintenance systems, from ground stations, from satellite communications, from onboard sensors feeding flight management and control systems. The boundary between the aircraft's digital environment and the external world is real but permeable.
The attack surface has expanded dramatically as aviation has digitised.
Electronic flight bags replaced paper manuals, and introduced tablet management, software version control, and network connectivity into the cockpit. Digital maintenance records replaced paper logbooks, and introduced data integrity questions that paper, whatever its other limitations, never raised. Predictive maintenance systems ingest continuous data streams from aircraft systems, and those streams have to be transmitted, received, and protected.
Aircraft software updates, the kind that fixed 6,000 A320s in 48 hours, are increasingly delivered electronically rather than physically. The efficiency gains are real and significant. So is the question of what happens if that delivery mechanism is compromised.
How the industry manages it, and where the gaps are
Aviation's response to software and cyber integrity has been characterised by the same approach it applies to every safety challenge: systematic, layered, and generally slower than the threat environment.
Regulatory frameworks exist but are still maturing. EASA published its first dedicated cybersecurity certification framework for aviation in 2022. CASA is aligned with international standards through ICAO cybersecurity requirements. The frameworks exist, but they were developed for an environment where the primary threat was configuration error, not sophisticated external attack.
Software configuration management is well established. The processes for managing approved software standards, embodiment records, and version control are mature and effective. The November 2025 event demonstrated that when a software vulnerability is identified, the industry can respond at extraordinary scale and speed, ~6000 aircraft corrected in under 48 hours is a genuinely remarkable logistical achievement.
The supply chain question is less resolved. Aircraft software doesn't originate with airlines. It comes from OEMs, such as Airbus, Boeing, engine manufacturers, and avionics suppliers, through a supply chain that involves multiple parties and jurisdictions. The integrity of that supply chain, and the security of software delivery mechanisms, is an area where the industry's frameworks are still developing.
The human factors dimension is new territory. Engineers who trained on physical components are now managing software embodiment as part of their daily maintenance function. The skills required are different, and the failure modes are different. The consequence of a wrong software version loaded to a flight control computer is not always immediately visible, unlike a incorrectly torqued bolt or a missing cotter pin.
What passengers don't know, and what they should
When you board an Airbus A320 today, the aircraft's airworthiness is dependent not only on the physical condition of its structure, engines, and systems, but on the integrity of the software running inside dozens of computers. They control everything from flight management, fuel monitoring, elevator and aileron control, and navigation.
That software has a configuration, and that configuration must be controlled. And when it needs to change, whether because of a manufacturer update, a regulatory directive, or a solar flare corrupting a flight control computer over the Atlantic, the maintenance system responds.
The JetBlue event of October 2025 was not a failure of that system, it was a demonstration of it working, arguably imperfectly, under pressure, but effectively. A vulnerability was identified, characterised, and remediated across the global fleet in a timeframe that no other industry could replicate.
But it also revealed something the industry should be honest about.
The threat environment for aviation software is not static. Deliberate interference is a different category of risk entirely, and the frameworks that govern physical component security are continually being translated to the digital domain.
Aviation has always stayed ahead of the threat by being honest about where its vulnerabilities are. The software era requires the same honesty, and the part you can't hold in your hand is just as critical as the one you can.
Jotore Aviation Consulting provides maintenance strategy, regulatory compliance, and CAMO/AMO advisory services to Australian aviation operators. For more aviation industry analysis, visit www.jotoreaviation.au



Comments