Air traffic control operates against one governing constraint: uninterrupted system availability. Controllers managing separation between aircraft have no manual process that scales to the traffic volumes a major hub demands. When systems fail, regulators require a reduction in throughput, and at Heathrow that reduction translates into held departures, extended inbound queues, and a recovery that takes hours after capacity is restored. NATS, the UK's primary air traffic control provider, is accounting for exactly that scenario following a massive disruption at Heathrow, and its chief said Wednesday that a cyber attack has been ruled out.
The statement came with a qualifier. "We have at this point ruled out cyber," the head of NATS said, keeping the investigation open while setting aside the most alarming class of cause. What the organization has not publicly disclosed is which system component failed, what redundancy mechanisms were engaged, or how long the disruption lasted.
The reliability record
Ruling out a cyber cause points the investigation toward internal failure modes: hardware, software, or operational process. For the airlines, the classification may be secondary to the frequency. Their response cast this as a third major failure from NATS in three years, shifting the question from what broke this time to whether the underlying architecture is adequate for the operational demands placed on it.
ATC infrastructure is built with redundant data paths and failover systems specifically to keep component faults contained and invisible to aircraft operators. When those safeguards hold, a failure never reaches the airspace level. The disruption at Heathrow demonstrates they did not hold, and NATS has not yet said where in the system that protection broke down.