What the FZ1073 incident says about trust, authority and cross-border security. Friday 02/10/2026 A plane, carrying passengers who were on the FlyDubai aircraft bound for Israel from the United Arab Emirates, arrives at the Ben Gurion International Airport, in Lod, near Tel Aviv, Israel, September 30, 2026. Aviation security has spent decades making the cockpit door harder to cross. That was necessary. But the security incident aboard flydubai flight FZ1073 on 30 September has placed a different question in front of us: what happens when the risk emerges after the system has already decided that a person belongs on the trusted side of the door? I believe this is the more difficult security question, and it reaches far beyond aviation. There is still much we do not know about what happened, and that uncertainty should shape the way the incident is discussed. Preliminary accounts said that the flight, travelling from Dubai to Tel Aviv, experienced a serious “security incident” stemming from an altercation between the captain and the first officer. The aircraft was diverted and made an emergency landing at Tabuk Airport in Saudi Arabia. Injured crew members received medical care in the kingdom. UAE authorities have opened an investigation into the circumstances, motives, and operational and security aspects of the incident. The UAE ministry of foreign affairs said the probe will examine all circumstances surrounding the incident “including any possible connection to terrorist activity or intent, and whether it involved prior planning or direction”. But authorities have also explicitly urged the public not to pre-empt the investigation’s findings. That is the right approach. A serious security discussion does not require us to jump into conclusions that investigators have not yet established. What is already visible, however, is something important about the relationship between security and trust. The aircraft was Emirati, the incident unfolded in the air, and the safe diversion brought the response into Saudi Arabia. In a matter of minutes, what began as an internal security emergency became a cross-border operational problem involving an aircraft, a crew, passengers, an airport, medical care and several competent authorities. The UAE and Saudi Arabia therefore appear in this story not as an artificial comparison between two countries, but as two parts of the same security chain. One side had to regain control of the aircraft; the other had to be ready to receive what arrived. That matters to me because I have spent years in security environments where people tend to think of protection as a boundary: a gate, a permit, a restricted room, a badge, a password. These controls are essential, but they can create a false sense that the security question has been answered once access is granted. It has not. Access control asks whether someone is allowed to enter. The harder question begins after entry: how much authority does that person hold, what happens if the conditions supporting trust change, and how quickly can the system respond without waiting for a catastrophe to prove that something is wrong? This is where I think the FZ1073 incident deserves international attention. The lesson should not be that trusted professionals are inherently suspect. Aviation, energy, banking, healthcare and government could not function under permanent suspicion. Trust is operationally necessary. But trust should not be treated as permanent simply because it was justified yesterday. A person may have the correct identity, the correct clearance and the correct professional role, while the risk picture around that person changes later. Security systems need to be able to recognise that distinction without turning the workplace into a culture of fear. The UAE side of the response now has an obvious responsibility: establish the facts, examine the operational and security dimensions, and learn from whatever the investigation ultimately shows. Saudi Arabia’s role in the immediate outcome illustrates a different but equally important part of resilience. An emergency does not respect the organisational or national boundary in which it began. The receiving system must be capable of absorbing the problem safely. Tabuk was not the flight’s destination, yet it became part of the security solution. That is what real regional resilience often looks like: not a slogan about cooperation, but another system being ready when the first system suddenly needs somewhere safe to go. I would take that principle much further. A critical system should never depend entirely on the assumption that the authorised person will remain safe simply because he or she was authorised. Nor should it depend entirely on one courageous intervention when conditions deteriorate. The design itself should provide routes for challenge, escalation and recovery. Critical authority can be distributed where appropriate. Unusual behaviour can have clear escalation paths. Teams can be trained to question an abnormal action without treating the act of questioning as disloyalty. Emergency authority can be defined before an emergency, rather than negotiated while seconds are being lost. This is not only an aviation issue. A power station can have an authorised operator whose actions suddenly create danger. A bank can have a trusted employee with privileged access. A government network can have an administrator whose permissions remain valid even after circumstances have changed. A control room can have someone sitting at the correct console with the correct credentials while everyone around him assumes that the badge which opened the door also proves that every subsequent decision is safe. Different sectors use different technologies, but the weakness is recognisable: access is verified at one moment while trust is allowed to continue almost invisibly afterward. There is also a regional lesson in the journey from Dubai to Tabuk. Gulf states have invested heavily in aviation, infrastructure and emergency response because their economies depend on systems that cross borders every hour. The next step is to think about security in the same way. Resilience is not only the strength of the first organisation that encounters a crisis. It is also the ability of neighbouring systems to receive, stabilise and support when the crisis moves. In this case, an aircraft that could no longer continue its planned journey found a safe operational alternative in Saudi Arabia. That fact should remind us that redundancy is geographic as well as technical. My concern is that after incidents like this, organisations naturally look for the control that appears easiest to strengthen: another check, another barrier, another procedure. Sometimes that is exactly what is needed. But adding a stronger lock does not solve every problem that can occur behind the lock. The investigation into FZ1073 should be allowed to determine what failed, what worked and what needs to change in aviation. The broader security community, meanwhile, can ask a question that does not depend on knowing the motive: are our systems designed only to decide who may enter, or are they also designed to remain safe after trusted people are already inside? For decades, security has concentrated on keeping the wrong person outside the door. We should continue doing that. But high-consequence systems now need equal maturity on the other side of it. Trust must be strong enough for people to do their jobs, yet flexible enough for the system to respond when circumstances change. And when an emergency crosses a boundary, institutional or national, the next system must be ready to carry part of the burden. The route from Dubai to an emergency landing in Tabuk showed both sides of that reality in a single flight.
The Arab Weekly
Original source


