Nashville International Airport (BNA) isn't a startup with a slick attack surface - it's critical national infrastructure. The Metropolitan Nashville Airport Authority (MNAA) runs BNA and John C. Tune Airport, facilities that handled 24.7 million passengers in 2024 and support 80,000 jobs across the region. The threat model here is physical-cyber convergence: OT/ICS systems governing airfield operations, baggage handling, access control, and building management all sit on networks that can't afford to go down. A breach isn't about data exfiltration headlines - it's about operational disruption to a system that generates $13.8 billion in annual economic impact and routes to 114 nonstop destinations.
MNAA is in the middle of a $3 billion growth and expansion plan, which means new infrastructure, new systems, and new attack surfaces being stood up at scale. Cybersecurity in this environment spans IT and OT domains: securing network architecture for expanding terminal facilities, hardening SCADA and building automation systems, managing vendor risk across a massive third-party ecosystem (airlines, TSA, concessionaires), and maintaining compliance with TSA security directives and federal aviation regulations. The team operates in a space where availability and integrity aren't abstract security goals - they're operational mandates tied to passenger safety and regional commerce.
Middle Tennessee's growth has made BNA one of the fastest-expanding airports in the country. That pace creates pressure on security teams to keep up with infrastructure that's being built faster than most environments. The work here is grounded in securing legacy OT systems alongside modern IT stacks, incident response planning for facilities that never close, and building security into expansion projects from the ground up rather than retrofitting it later. For anyone who wants their threat model written in concrete and steel, this is a place where the stakes are tangible and the scope is broad.






