Sagi Waitzman is the CTO of Cyviation, an aviation cybersecurity company. It maps the computer systems on board an aircraft into a digital twin and runs risk assessments so airlines can comply with new cyber regulations. His customers are airlines and companies that manage private jets. He joined us in Episode 28 (January 23, 2026).
Most people picture airline cybersecurity as ground systems: ticketing, crew scheduling, airport networks. Sagi's point (04:37) was that Cyviation checks the airplane itself. A modern aircraft has so many computers that it has, in his words, its own server room inside.
The team maps every computer system on the plane, then analyzes versions, connections and everything they can pull from documentation and maintenance (MRO) records. The output says whether there is a risk, what it is and what it could affect, including chain effects where an attacker enters through one system and reaches another. Airlines use that structured risk assessment to meet new regulations coming into force this year.
I think the most important thing that people need to understand that you can't do pen test to an airplane.
— Sagi Waitzman, Episode 28
Like, so testing physically an airplane mean that you will be on the ground for about a year until it can be certified again.
— Sagi Waitzman, Episode 28
Like, in our point of view, we don't hire developers, we hire only managers, okay, and every manager has its own AI agent that you need to make sure that he's doing the best job he can do.
— Sagi Waitzman, Episode 28
Sam built the flight ops cyber radar (01:13), a dashboard that lists risks across airline operations: ground VHF interference, a fuel logistics portal, an upstream vendor credential leak and RFID relay latency. Its critical alert was unexpected API activity from a third-party vendor in crew scheduling, from an atypical geography, with a tactical directive to isolate the vendor subnet and rotate credentials, plus an AI-written command briefing.
Sagi liked the UI and the red alert. But he said it showed what most people think airline cybersecurity is, the ground side, while Cyviation assesses the aircraft's onboard systems.
In the news segment, Sagi said he uses vibe coding for internal tools but not yet for production, and that a good idea and good execution still matter more than how easy it is to write code. For more on this industry, see our AI in aviation page.
Sagi Waitzman is the CTO of Cyviation, an AI-first aviation cybersecurity company. He joined Built This Week in Episode 28 in January 2026 to talk about aircraft cyber risk and how his team builds with AI agents.
Sagi said physically testing an airplane would mean it sits on the ground for about a year until it can be certified again, and nobody wants to fly a plane a hacker was probing the day before. Cyviation does a risk assessment on a digital twin instead.
Cyviation feeds aircraft documentation and maintenance (MRO) data into AI to build a digital twin of the plane's computer systems. Before AI, that meant going through more than 100 documents by hand.
According to Sagi, the regulator puts responsibility on whoever manages the airplane day to day, such as an airline or a private jet management company, not the manufacturer.