SCW Icons
hero bg no divider
Blog

코드 한 줄, 백만 달러

Matias Madou, Ph.D.
Published Nov 13, 2017
Last updated on Mar 09, 2026

If I asked you how much it would cost to change just one line of computer code in a device that's already in service, what number would come to mind? A few hundred dollars? Maybe thousands?

According to Aviation Today, it costs $1 million for a commercial airline to update a line of code in its planes. For a cost so substantial, they would likely need a compelling reason to take the steps required to make any update to their airplane's systems, which really got me thinking about a number of factors.

Breaking down the cost

While the article doesn't outline what comprises the $1 million cost, I think it's a viable figure. I'm not an expert specifically in airline software updates, but I can assume a few of the steps the airline is forced to take in this situation.

First, the airline needs to discover a flaw or vulnerability that necessitates the update. The cited example consists of research performed by the U.S. Department of Homeland Security (DHS)  on a Boeing 757. The results - a remote hack after only two days of work - are more than compelling enough for any airline to take note.

From there, software developers need to analyze the findings, write new code, and test it in a safe environment to ensure the issue is fixed. Now comes the tricky part. The airline needs to ground each vulnerable or flawed aircraft, apply the new code, test it to ensure it works with that specific plane, and then recertify that plan for commercial flight.

According to airfleets.net, Southwest Airlines currently has 499 Boeing 737-700 planes in its fleet. Consider the time and money investment involved if a security flaw emerged in this particular plane model.

Not just an airline challenge

Clearly, airlines should have a vested interest in employing sound secure coding principles from the start. After giving it a few moments'thought, I could see numerous industries and situations where a similar cost might apply. Instead of worrying about airplanes falling out of the sky due to a hacked vulnerability, what about medical devices like pacemakers? How much does it cost to recall and update a half-million lifesaving pieces of electronics?

In the automotive industry, we continue to hear talk and security concerns about self-driving cars. Yet, even our "typical'vehicles rely more heavily than ever on connectivity to the internet, which leads directly to some troubling - if entertaining - safety concerns.

It's a simple fact that it costs much more money and takes more effort and time to update devices or systems after they've been released into a production environment, or before they've been mass produced, than it does to build security into your initial development process. Yet, we still continue to see new preventable software flaws and cybersecurity vulnerabilities every day, underscoring the need for companies to look for ways to build secure software development into their development culture.

The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing's 737, it would "bankrupt" them if a cyber vulnerability was specific to systems on board 737s

리소스 보기
리소스 보기

항공 전자 장비의 코드 한 줄을 변경하는 데 드는 비용은 백만 달러이며 구현하는 데 1년이 걸립니다.보잉 737을 기반으로 운항하는 사우스웨스트 항공의 경우 이 항공사는 “파산”할 수 있습니다.

더 많은 것에 관심이 있으세요?

Matias Madou, Ph.D. is a security expert, researcher, and CTO and co-founder of Secure Code Warrior. Matias obtained his Ph.D. in Application Security from Ghent University, focusing on static analysis solutions. He later joined Fortify in the US, where he realized that it was insufficient to solely detect code problems without aiding developers in writing secure code. This inspired him to develop products that assist developers, alleviate the burden of security, and exceed customers' expectations. When he is not at his desk as part of Team Awesome, he enjoys being on stage presenting at conferences including RSA Conference, BlackHat and DefCon.

learn more

Secure Code Warrior는 전체 소프트웨어 개발 라이프사이클에서 코드를 보호하고 사이버 보안을 최우선으로 생각하는 문화를 조성할 수 있도록 조직을 위해 여기 있습니다.AppSec 관리자, 개발자, CISO 또는 보안 관련 누구든 관계없이 조직이 안전하지 않은 코드와 관련된 위험을 줄일 수 있도록 도와드릴 수 있습니다.

데모 예약
공유 대상:
linkedin brandsSocialx logo
작성자
Matias Madou, Ph.D.
Published Nov 13, 2017

Matias Madou, Ph.D. is a security expert, researcher, and CTO and co-founder of Secure Code Warrior. Matias obtained his Ph.D. in Application Security from Ghent University, focusing on static analysis solutions. He later joined Fortify in the US, where he realized that it was insufficient to solely detect code problems without aiding developers in writing secure code. This inspired him to develop products that assist developers, alleviate the burden of security, and exceed customers' expectations. When he is not at his desk as part of Team Awesome, he enjoys being on stage presenting at conferences including RSA Conference, BlackHat and DefCon.

Matias is a researcher and developer with more than 15 years of hands-on software security experience. He has developed solutions for companies such as Fortify Software and his own company Sensei Security. Over his career, Matias has led multiple application security research projects which have led to commercial products and boasts over 10 patents under his belt. When he is away from his desk, Matias has served as an instructor for advanced application security training courses and regularly speaks at global conferences including RSA Conference, Black Hat, DefCon, BSIMM, OWASP AppSec and BruCon.

Matias holds a Ph.D. in Computer Engineering from Ghent University, where he studied application security through program obfuscation to hide the inner workings of an application.

공유 대상:
linkedin brandsSocialx logo

If I asked you how much it would cost to change just one line of computer code in a device that's already in service, what number would come to mind? A few hundred dollars? Maybe thousands?

According to Aviation Today, it costs $1 million for a commercial airline to update a line of code in its planes. For a cost so substantial, they would likely need a compelling reason to take the steps required to make any update to their airplane's systems, which really got me thinking about a number of factors.

Breaking down the cost

While the article doesn't outline what comprises the $1 million cost, I think it's a viable figure. I'm not an expert specifically in airline software updates, but I can assume a few of the steps the airline is forced to take in this situation.

First, the airline needs to discover a flaw or vulnerability that necessitates the update. The cited example consists of research performed by the U.S. Department of Homeland Security (DHS)  on a Boeing 757. The results - a remote hack after only two days of work - are more than compelling enough for any airline to take note.

From there, software developers need to analyze the findings, write new code, and test it in a safe environment to ensure the issue is fixed. Now comes the tricky part. The airline needs to ground each vulnerable or flawed aircraft, apply the new code, test it to ensure it works with that specific plane, and then recertify that plan for commercial flight.

According to airfleets.net, Southwest Airlines currently has 499 Boeing 737-700 planes in its fleet. Consider the time and money investment involved if a security flaw emerged in this particular plane model.

Not just an airline challenge

Clearly, airlines should have a vested interest in employing sound secure coding principles from the start. After giving it a few moments'thought, I could see numerous industries and situations where a similar cost might apply. Instead of worrying about airplanes falling out of the sky due to a hacked vulnerability, what about medical devices like pacemakers? How much does it cost to recall and update a half-million lifesaving pieces of electronics?

In the automotive industry, we continue to hear talk and security concerns about self-driving cars. Yet, even our "typical'vehicles rely more heavily than ever on connectivity to the internet, which leads directly to some troubling - if entertaining - safety concerns.

It's a simple fact that it costs much more money and takes more effort and time to update devices or systems after they've been released into a production environment, or before they've been mass produced, than it does to build security into your initial development process. Yet, we still continue to see new preventable software flaws and cybersecurity vulnerabilities every day, underscoring the need for companies to look for ways to build secure software development into their development culture.

The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing's 737, it would "bankrupt" them if a cyber vulnerability was specific to systems on board 737s

리소스 보기
리소스 보기

보고서를 다운로드하려면 아래 양식을 작성하세요.

당사 제품 및/또는 관련 보안 코딩 주제에 대한 정보를 보내실 수 있도록 귀하의 동의를 구합니다.당사는 항상 귀하의 개인 정보를 최대한의 주의를 기울여 취급하며 마케팅 목적으로 다른 회사에 절대 판매하지 않습니다.

제출
scw success icon
scw error icon
양식을 제출하려면 'Analytics' 쿠키를 활성화하십시오.완료되면 언제든지 다시 비활성화할 수 있습니다.

If I asked you how much it would cost to change just one line of computer code in a device that's already in service, what number would come to mind? A few hundred dollars? Maybe thousands?

According to Aviation Today, it costs $1 million for a commercial airline to update a line of code in its planes. For a cost so substantial, they would likely need a compelling reason to take the steps required to make any update to their airplane's systems, which really got me thinking about a number of factors.

Breaking down the cost

While the article doesn't outline what comprises the $1 million cost, I think it's a viable figure. I'm not an expert specifically in airline software updates, but I can assume a few of the steps the airline is forced to take in this situation.

First, the airline needs to discover a flaw or vulnerability that necessitates the update. The cited example consists of research performed by the U.S. Department of Homeland Security (DHS)  on a Boeing 757. The results - a remote hack after only two days of work - are more than compelling enough for any airline to take note.

From there, software developers need to analyze the findings, write new code, and test it in a safe environment to ensure the issue is fixed. Now comes the tricky part. The airline needs to ground each vulnerable or flawed aircraft, apply the new code, test it to ensure it works with that specific plane, and then recertify that plan for commercial flight.

According to airfleets.net, Southwest Airlines currently has 499 Boeing 737-700 planes in its fleet. Consider the time and money investment involved if a security flaw emerged in this particular plane model.

Not just an airline challenge

Clearly, airlines should have a vested interest in employing sound secure coding principles from the start. After giving it a few moments'thought, I could see numerous industries and situations where a similar cost might apply. Instead of worrying about airplanes falling out of the sky due to a hacked vulnerability, what about medical devices like pacemakers? How much does it cost to recall and update a half-million lifesaving pieces of electronics?

In the automotive industry, we continue to hear talk and security concerns about self-driving cars. Yet, even our "typical'vehicles rely more heavily than ever on connectivity to the internet, which leads directly to some troubling - if entertaining - safety concerns.

It's a simple fact that it costs much more money and takes more effort and time to update devices or systems after they've been released into a production environment, or before they've been mass produced, than it does to build security into your initial development process. Yet, we still continue to see new preventable software flaws and cybersecurity vulnerabilities every day, underscoring the need for companies to look for ways to build secure software development into their development culture.

The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing's 737, it would "bankrupt" them if a cyber vulnerability was specific to systems on board 737s

웨비나 보기
시작하기
learn more

아래 링크를 클릭하고 이 리소스의 PDF를 다운로드하십시오.

Secure Code Warrior는 전체 소프트웨어 개발 라이프사이클에서 코드를 보호하고 사이버 보안을 최우선으로 생각하는 문화를 조성할 수 있도록 조직을 위해 여기 있습니다.AppSec 관리자, 개발자, CISO 또는 보안 관련 누구든 관계없이 조직이 안전하지 않은 코드와 관련된 위험을 줄일 수 있도록 도와드릴 수 있습니다.

보고서 보기데모 예약
리소스 보기
공유 대상:
linkedin brandsSocialx logo
더 많은 것에 관심이 있으세요?

공유 대상:
linkedin brandsSocialx logo
작성자
Matias Madou, Ph.D.
Published Nov 13, 2017

Matias Madou, Ph.D. is a security expert, researcher, and CTO and co-founder of Secure Code Warrior. Matias obtained his Ph.D. in Application Security from Ghent University, focusing on static analysis solutions. He later joined Fortify in the US, where he realized that it was insufficient to solely detect code problems without aiding developers in writing secure code. This inspired him to develop products that assist developers, alleviate the burden of security, and exceed customers' expectations. When he is not at his desk as part of Team Awesome, he enjoys being on stage presenting at conferences including RSA Conference, BlackHat and DefCon.

Matias is a researcher and developer with more than 15 years of hands-on software security experience. He has developed solutions for companies such as Fortify Software and his own company Sensei Security. Over his career, Matias has led multiple application security research projects which have led to commercial products and boasts over 10 patents under his belt. When he is away from his desk, Matias has served as an instructor for advanced application security training courses and regularly speaks at global conferences including RSA Conference, Black Hat, DefCon, BSIMM, OWASP AppSec and BruCon.

Matias holds a Ph.D. in Computer Engineering from Ghent University, where he studied application security through program obfuscation to hide the inner workings of an application.

공유 대상:
linkedin brandsSocialx logo

If I asked you how much it would cost to change just one line of computer code in a device that's already in service, what number would come to mind? A few hundred dollars? Maybe thousands?

According to Aviation Today, it costs $1 million for a commercial airline to update a line of code in its planes. For a cost so substantial, they would likely need a compelling reason to take the steps required to make any update to their airplane's systems, which really got me thinking about a number of factors.

Breaking down the cost

While the article doesn't outline what comprises the $1 million cost, I think it's a viable figure. I'm not an expert specifically in airline software updates, but I can assume a few of the steps the airline is forced to take in this situation.

First, the airline needs to discover a flaw or vulnerability that necessitates the update. The cited example consists of research performed by the U.S. Department of Homeland Security (DHS)  on a Boeing 757. The results - a remote hack after only two days of work - are more than compelling enough for any airline to take note.

From there, software developers need to analyze the findings, write new code, and test it in a safe environment to ensure the issue is fixed. Now comes the tricky part. The airline needs to ground each vulnerable or flawed aircraft, apply the new code, test it to ensure it works with that specific plane, and then recertify that plan for commercial flight.

According to airfleets.net, Southwest Airlines currently has 499 Boeing 737-700 planes in its fleet. Consider the time and money investment involved if a security flaw emerged in this particular plane model.

Not just an airline challenge

Clearly, airlines should have a vested interest in employing sound secure coding principles from the start. After giving it a few moments'thought, I could see numerous industries and situations where a similar cost might apply. Instead of worrying about airplanes falling out of the sky due to a hacked vulnerability, what about medical devices like pacemakers? How much does it cost to recall and update a half-million lifesaving pieces of electronics?

In the automotive industry, we continue to hear talk and security concerns about self-driving cars. Yet, even our "typical'vehicles rely more heavily than ever on connectivity to the internet, which leads directly to some troubling - if entertaining - safety concerns.

It's a simple fact that it costs much more money and takes more effort and time to update devices or systems after they've been released into a production environment, or before they've been mass produced, than it does to build security into your initial development process. Yet, we still continue to see new preventable software flaws and cybersecurity vulnerabilities every day, underscoring the need for companies to look for ways to build secure software development into their development culture.

The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing's 737, it would "bankrupt" them if a cyber vulnerability was specific to systems on board 737s

목차

PDF 다운로드
리소스 보기
더 많은 것에 관심이 있으세요?

Matias Madou, Ph.D. is a security expert, researcher, and CTO and co-founder of Secure Code Warrior. Matias obtained his Ph.D. in Application Security from Ghent University, focusing on static analysis solutions. He later joined Fortify in the US, where he realized that it was insufficient to solely detect code problems without aiding developers in writing secure code. This inspired him to develop products that assist developers, alleviate the burden of security, and exceed customers' expectations. When he is not at his desk as part of Team Awesome, he enjoys being on stage presenting at conferences including RSA Conference, BlackHat and DefCon.

learn more

Secure Code Warrior는 전체 소프트웨어 개발 라이프사이클에서 코드를 보호하고 사이버 보안을 최우선으로 생각하는 문화를 조성할 수 있도록 조직을 위해 여기 있습니다.AppSec 관리자, 개발자, CISO 또는 보안 관련 누구든 관계없이 조직이 안전하지 않은 코드와 관련된 위험을 줄일 수 있도록 도와드릴 수 있습니다.

데모 예약다운로드
공유 대상:
linkedin brandsSocialx logo
리소스 허브

시작하는 데 도움이 되는 리소스

더 많은 게시물
리소스 허브

시작하는 데 도움이 되는 리소스

더 많은 게시물