Military flight plan reportedly triggered the NATS outage, unless you ask the MoD
Flight data filed for a UK military aircraft reportedly set off the 8 September NATS failure, according to the Financial Times. The Ministry of Defence says there was no error on its part. Mark Fermor on what a single filing emptying the national schedule says about resilience.

Why it matters
What this means for organisations holding critical data
Flight data filed for a UK military aircraft reportedly set off the 8 September NATS failure, according to the Financial Times. The Ministry of Defence says there was no error on its part. Mark Fermor on what a single filing emptying the national schedule says about resilience.
A flight plan submitted by a UK military aircraft caused the air traffic control failure that disrupted UK airspace on 8 September, according to four people briefed on the incident who spoke to the Financial Times. The Ministry of Defence says it does not believe there was any indication of an error on the part of the military.
Both things are currently on the record, and neither has been confirmed by an investigator. What is not in dispute is the outage itself, the political response to it, and what it exposes about the resilience of systems the country depends on.
What is established
At around lunchtime on 8 September, NATS experienced an issue with its flight processing system at the Swanwick centre affecting the data available to controllers. Transport minister Keir Mather told the House of Commons on 10 September that Secretary of State for Transport Heidi Alexander had asked the Civil Aviation Authority to conduct an independent review to establish the cause, with an update due within six months. NATS chief executive Martin Rolfe was given until 16 September to report to ministers on what went wrong.
NATS restored the system the same day, describing it as a very complex recovery that created difficulties for the whole aviation network. The company has not published a technical explanation and has promised a full investigation. Mather told MPs the fault was technical and not believed to be cyber-related, and that civil and military air traffic control systems are separate.
What has been reported, and who disputes it
The FT''s account, carried by The Guardian with attribution, is that four people briefed on the incident said the shutdown was caused by a flight plan submitted by a UK military aircraft. No investigator has attributed the outage to the military flight, its operator or any individual.
The MoD''s position is that it would be inappropriate to comment further until the NATS investigation concludes. So for now the public record holds two incompatible statements: a report that a military filing triggered the failure, and a denial that the military made an error. Both can be true at once, which is precisely the uncomfortable part. In the 2023 failure the flight plan that brought down the system was filed in accordance with standard procedures and was found not to be defective. The filing was not the fault. The system that could not absorb it was.
The 2023 precedent makes this hard to wave away
On 28 August 2023, the Flight Plan Reception Suite Automated at Swanwick failed on a single valid flight plan after confusing Deauville in France with Devil''s Lake in North Dakota. The primary system generated a critical exception and disconnected itself, as designed. The standby system received the same plan and failed the same way, within about twenty seconds. More than 700,000 passengers were affected.
The CAA''s independent review, published in November 2024, made 34 recommendations. Mather told the Commons all 34 have been implemented. Whether the 8 September failure belongs to the same class, a valid filing that both primary and standby paths could not reconcile, is one of the questions the new CAA review is positioned to answer.
Resilience is the story, not the aircraft
Simon Hoare MP put it directly to the minister: it is slightly ludicrous that NATS has put all its eggs in one basket, with no shadow, back-up or secondary scheme. Mather accepted the point, telling MPs that resilience is clearly not where it needs to be.
That exchange should be pinned to the wall of every organisation that runs a critical process. When automated flight data processing stops, controllers revert to manual working. The 2023 review quantified the gap: the system could process about 800 flight plans an hour, and manual input reduced that to about 60. Safety is preserved; throughput collapses; recovery is measured in days because aircraft and crews finish the day out of position.
This is what a single point of failure looks like in practice. Not an explosion, not a hack, but one input the system could not digest, and no independent path around it.
What organisations should take from this
First, test your systems against valid inputs, not just attacks. The 2023 failure was caused by a correctly filed plan. If the FT''s account is accurate, the 2026 failure may prove the same. Adversaries are optional; complexity alone will do the job.
Second, redundancy means independence. A standby system that consumes the same input, with the same logic, as the primary is not a backup. It is a second copy of the same failure waiting its turn. True resilience requires diverse paths: different systems, different data sources and, for the records that matter most, storage that is not reachable from the failure domain at all. That is the premise of Offline Secure Storage: what is disconnected cannot be taken down by the thing that just failed.
Third, publish your failure maths. NATS knew an outage becomes days of disruption because manual working caps throughput at a fraction of normal. Every organisation should know its own ratio: what happens to capacity the hour your primary system steps aside.
Sources
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






