Drone cybersecurity starts with choosing the right device
Estonia's Information System Authority (RIA) and the International Centre for Defence and Security (ICDS/RKK) have published an analysis of drone-related cyber threats along with mitigation recommendations. Experts say security begins with selecting the right device and following basic cyber hygiene.

Drones are becoming increasingly common as work and support tools, but their use also carries cyber risks. Beyond general security flaws and data leaks, drone-specific threats must be considered, such as disruption or spoofing of communications and satellite navigation.
An analysis by Estonia's Information System Authority (RIA) together with the International Centre for Defence and Security (ICDS, known locally as RKK) outlines the main cyber threats linked to drones and offers recommendations for reducing them. A modern drone is essentially a flying computer. Unlike ordinary networked devices, where a cyberattack mainly threatens data or device function, an attack on a drone can also have physical consequences — disruptions to communication or satellite navigation can affect its flight path and, in the worst case, lead to loss of control.
According to Nikolai Kunitsyn, an analyst at RIA's threat analysis and prevention department, drone cybersecurity is becoming more important as drone use expands. The more drones are used as work tools and within various services, he said, the more important it becomes to assess what data a drone collects, where it goes, how its control is protected, and what it does if communication or navigation fails to work as expected.
Security starts at the point of purchase
Since many technical security measures depend on the manufacturer and the device's built-in solutions, cybersecurity begins with the choice of drone itself. Kunitsyn noted that users can reduce risk by favoring devices with secure features and by following cyber hygiene practices during use. When choosing a drone, preference should go to devices with encrypted communication, support for multiple satellite systems, cryptographically signed updates, and frequency-hopping radio links. It is also important to buy the drone and its control device from a trustworthy, official retailer.
Many familiar cyber hygiene principles also apply to drones: software on both the drone and controller should be updated regularly, only from official sources; strong, unique passwords and, where possible, multi-factor authentication should protect accounts; a separate device and network should be used for drone control where feasible; and flight logs and sensitive records should be encrypted, with unneeded data deleted.
Cybersecurity is not limited to software and data — even brief physical access to a drone or its controller can pose a threat, so devices should not be left unattended. Before takeoff, operators should consider how the drone will behave if it loses connection or control, and program appropriate responses where possible. Monitoring the drone during flight is also advisable, even in automatic mode.
Globally, drones made by China's DJI are the most widespread. While DJI drones are not technically more dangerous than others, using Chinese-made devices requires considering the country's legal framework as well — Chinese companies' obligation to cooperate with state intelligence services means legal and political risks around data handling must also be weighed. Kunitsyn stressed this does not mean avoiding DJI drones altogether; to reduce risk, he recommended using Local Data Mode (LDM) when possible, which disables the internet connection during flight and prevents data transmission to the manufacturer's servers.
The full drone cybersecurity analysis is available on RIA's website.


