The official picture changed on 3 October. The UAE Attorney-General said the investigation into flydubai flight FZ1073 had revealed that the co-pilot attempted to carry out a terrorist act, attacking the captain inside the flight deck with a crash axe and trying to take control of the aircraft. The investigation is still continuing into the full circumstances, motives and any links.

Written by Abdulla Saeed Alhebsi, Author and Researcher specializing in Security, Heritage, Risk Management, and Control Room Operations

That final sentence matters. It gives us enough verified information to ask harder security questions, but not a licence to invent a biography, ideology or network that investigators have not established. The official statement is available from Emirates News Agency (WAM).

What stays with me is not only the weapon or the location. It is the uncomfortable fact that the person identified by investigators was not trying to force his way through a protected door. He was already on the trusted side of it. For years, security has become exceptionally good at deciding who may enter sensitive spaces. The next challenge is more difficult: what do we do when risk changes after legitimate access has already been granted?

Hungary’s manufacturing, logistics and transport networks depend on skilled people who need deep access to complex systems. The UAE faces the same reality across aviation, ports and energy. FZ1073 is therefore a reminder that the most difficult security question begins after vetting has worked and a professional has legitimately entered the system.

In industrial environments, a badge or administrator account is often treated as a binary fact: valid or invalid. Risk is rarely so neat. High-consequence actions can require an additional human check, unusual behaviour can trigger temporary review, and colleagues can have a protected route to challenge something that does not fit the task.

I do not believe the answer is permanent suspicion. Aviation, energy, mining, banking and government cannot function if every trusted professional is treated as a potential offender. Trust is operationally necessary. But trust and authority are not the same thing. A person may remain trusted while a particular action deserves a second check; a credential may remain valid while circumstances justify a temporary restriction; a colleague may raise a concern without making an accusation. Mature security creates room for those distinctions.

If you missed it: Flydubai resumes Budapest flights as airline expands network to more than 125 destinations!

The other half of the story deserves equal attention. The UAE General Civil Aviation Authority praised the captain, crew and passengers whose swift intervention helped bring the situation under control. That is not a footnote. It shows why resilience is ultimately more than prevention. A system can fail to detect a threat early and still prevent catastrophe if people understand their roles, challenge abnormal behaviour and act before authority becomes paralysis.

Continuous trust review should never become a licence for profiling. Nationality, religion or private belief are not substitutes for evidence. A defensible system focuses on behaviour relevant to the role, unusual attempts to exercise authority, high-consequence actions and clear escalation channels. It should also protect the person being reviewed: temporary verification is not a verdict, and raising a concern is not proof of guilt.

There is a design principle here that applies far beyond aviation. The higher the consequence of an action, the less comfortable we should be with irreversible single-person authority. That may mean a second human check, segmented permissions, a rehearsed transfer of control, or a way for colleagues to pause an abnormal action without first proving malicious intent. These measures are not dramatic, which is precisely why they can work.

Hungary and the UAE have every reason to protect professional trust. The way to protect it is not to make it permanent, but to make authority proportionate to the action being taken.