Digital infrastructure resilience is now a business risk – how protected are Georgia’s aviation, banking and energy systems?

The UK air-traffic-control outage in September 2026 showed that critical digital infrastructure does not have to be hacked to fail. Bad data, software faults, dependencies and recovery design can be enough. Georgia has meaningful safeguards across aviation, banking and energy, but public evidence points to different levels of maturity rather than uniform protection.

Key Takeaway

A four-hour outage in Britain’s air-traffic-control system led to more than 2,000 flight cancellations and affected hundreds of thousands of passengers. Reporting cited a flight plan containing spurious data as a likely trigger and raised questions about the lack of a dedicated independent backup for the affected processing function. The investigation was still live, so the precise cause should not be treated as final. The broader lesson is firmer: critical digital systems can fail because of data, software, upgrades, communications or recovery design – not only because of cyberattacks.

For Georgia, that lesson is most relevant to aviation, banking and energy. All three depend on continuous digital control, and disruption can quickly become an economic event: cancelled flights, unavailable payments, interrupted electricity supply, business downtime and loss of trust.

According to an assessment by BTU researchers, public evidence does not justify calling any of the three sectors “fully protected”. It does, however, reveal different levels of maturity: banking has the clearest formal supervisory cyber-risk framework; aviation publicly documents layered technical redundancy; and energy has modernised dispatch, data and information-security systems, while sector-wide resilience evidence remains less visible.

 

When a single fault becomes a business risk

Digital resilience is broader than cybersecurity. An organisation may be well protected against an external attack and still fail because of incorrect data, a software defect, a communications outage, a third-party dependency or an unsuccessful update. The relevant question is therefore not only whether an incident can be prevented, but whether the system can fail safely, preserve a critical function and recover quickly.

That is the economic lesson of the British disruption. Aircraft, crews and airports could remain physically functional while a central information-processing failure slowed a much larger network. A digital single point of failure can propagate through an entire supply chain.

Aviation: visible redundancy, but not enough public information for a complete resilience assessment

Georgia’s aviation system is growing. According to the Georgian Civil Aviation Agency, airports handled a record 8,494,640 passengers and 38,218 flights in 2025. According to calculations by BTU researchers, that is an average of about 23.3 thousand passengers per calendar day, although seasonal traffic makes the figure only a scale indicator. In the first quarter of 2026, passenger traffic rose another 4.28% year on year and the number of flights increased by 8.70%.

Public technical information from Sakaeronavigatsia indicates meaningful redundancy. Its INDRA air-traffic-management system in Tbilisi is described as having double protection that activates within seconds, plus a third, system-independent backup intended to prevent interruption. Its air-ground voice communications also use additional independent backup systems, while radar infrastructure provides double coverage of Georgian airspace.

Yet public sources do not reveal the complete backup topology of every critical component, measured recovery times, the results of recent failover exercises or all third-party software dependencies. The defensible conclusion is therefore that important resilience mechanisms exist – not that digital failure risk has been eliminated.

The Georgian Civil Aviation Agency also has a formal information-security management function, including an action plan, incident information collection and follow-up monitoring. Its broader aviation-security oversight score improved to 89.75% in the 2024 ICAO audit. That is a strong institutional signal, but it should not be misread as a standalone measure of digital resilience.

Banking: the most formalised public framework

Among the three sectors, commercial banking has the clearest publicly documented supervisory requirements. Since 2019, the National Bank of Georgia has required commercial banks to maintain a cybersecurity-management framework proportionate to their size and complexity and fully integrated into overall risk management. The framework covers risk identification, protection, detection, response and recovery.

This matters because banking infrastructure goes well beyond a mobile app. It includes settlement systems, databases, card processing, identity, open banking and external service providers. The National Bank’s 2024 reporting highlights business-continuity planning across scenarios including outsourced cloud services, as well as supervisory work on operational and cyber risks associated with open banking, digital banking, remote identification and electronic signatures.

In May 2026, the National Bank completed a major upgrade of Georgia’s real-time gross settlement and clearing infrastructure, moving to the ISO 20022 financial-messaging standard. All commercial banks, microbanks and the State Treasury participated. The upgrade strengthens interoperability and reliability, but modernisation does not mean zero risk: more connected infrastructure makes testing, recovery and supplier-risk management even more important.

Energy: modern digital control, but fragmented public evidence

Energy has the clearest link between digital failure and physical consequences. Georgian State Electrosystem operates 3,550 kilometres of transmission lines and 93 substations, with the National Dispatch Centre controlling the grid in real time.

GSE completed a major SCADA upgrade in 2020, modernising software and hardware for supervisory control, data acquisition and dispatch. In 2023 it launched procurement for an MPLS-based data-transport backbone intended to serve SCADA, IT, metering and other functions. A new dispatcher software system followed in 2024.

A further signal came from the Electricity System Commercial Operator, ESCO, which reported that in 2025 it became the first Georgian energy company to obtain ISO 27001 information-security certification. This demonstrates progress in formalising security management, but a certification at one organisation cannot be treated as proof of resilience across the entire power chain.

Georgia also has a legal framework for critical information systems. The Law on Information Security defines systems whose uninterrupted operation is essential to economic security and normal public life and establishes obligations for information-asset and security management. The consolidated law includes amendments through 2025 and is published as current to May 1, 2026.

Three sectors, three different risk patterns

Aviation’s core risk is network interdependence: failure in central traffic management, data processing or communications can propagate quickly to airlines and airports. Banking’s risk is the length of the digital supply chain, which spans institutions, payment rails, card networks, cloud services, software vendors and customer devices. Energy combines digital and physical infrastructure, so a cyber or software incident can affect not only information but operational control and electricity supply.

BTU Researchers’ Assessment

According to an assessment by BTU researchers, Georgia has meaningful institutional and technical foundations for digital resilience in all three sectors, but the quality and visibility of evidence differ. Banking shows the clearest formal supervisory framework for cybersecurity, continuity and recovery. Aviation publicly documents layered backup technology and international oversight. Energy has made material progress through SCADA modernisation, data-network investment and information-security certification, yet public sector-wide resilience-test results remain limited.

The answer to “how protected is Georgia?” should therefore be neither complacent nor alarmist. The country is not starting from zero, and there is concrete evidence of modern systems and redundancy. But the British case is a reminder that technology on paper is not enough. Resilience is demonstrated only when backup and recovery work on the day the primary system fails.

Why This Matters for Georgia

For Georgian businesses, critical-infrastructure resilience is no longer an IT department issue. A failed payment, a disrupted flight or an electricity outage can immediately affect revenue, logistics, staffing and customer confidence. Companies need to understand not only their own cyber controls but also the resilience of the infrastructure and suppliers on which their operations depend.

The practical shift is from asking “Are we protected?” to asking: Where do we still have a single critical point? How quickly can service be restored? Is the backup genuinely independent of the primary system? What happens if the main technology supplier becomes unavailable? When was the last realistic failover exercise?

Conclusion

Digital resilience is becoming part of Georgia’s economic competitiveness. As aviation, finance and energy become more automated, the ability to tolerate faults matters as much as speed and efficiency. The next phase should therefore combine technology investment with transparent, safe-to-disclose evidence of resilience: tested backups, measured recovery times, third-party risk controls, cross-sector exercises and lessons learned from significant incidents.

Trust in a digital economy is not created by promising that systems will never fail. It is created by evidence that critical services can continue when they do.

Data and Main Sources

The Guardian, 12 September 2026 – UK air-traffic-control outage; source material supplied by the user.

Georgian Civil Aviation Agency – aviation statistics and information-security / safety oversight. https://gcaa.ge/

Sakaeronavigatsia – Air Traffic Management, Communication and Radar infrastructure. https://airnav.ge/

National Bank of Georgia – Cybersecurity Management Framework, Payment Systems, 2026 RTGS modernisation and supervisory reporting. https://nbg.gov.ge/

Georgian State Electrosystem – SCADA modernisation, data-transport network and dispatcher systems. https://www.gse.com.ge/

Electricity System Commercial Operator (ESCO) – ISO 27001 certification and market information. https://esco.ge/

Legislative Herald of Georgia – Law on Information Security. https://matsne.gov.ge/en/document/view/1679424

Prepared by the academic team of Business and Technology University and the BTUAI Research Team, Tbilisi, Georgia.

 

Recent Posts