Baton Rouge Metropolitan Airport Prioritizes Cyber Security Investment Through Risk Assessment banner image
BTR Transparent

Baton Rouge Metropolitan Airport Prioritizes Cyber Security Investment Through Risk Assessment

Baton Rouge Metropolitan Airport Prioritizes Cyber Security Investment Through Risk Assessment
Baton Rouge Metropolitan Airport (BTR) is Louisiana’s second-largest commercial airport by passenger volume, serving the state capital and communities across the surrounding region. The airport provides connections to five major U.S. hubs through American Airlines, Delta Air Lines, and United Airlines. In 2025, BTR served approximately 847,000 arriving and departing passengers, marking its second consecutive year of record passenger traffic.

Supporting that level of activity requires a mix of business technology, airport operational systems, personnel, airlines, tenants, vendors, and third-party services. As the airport’s technology environment continued to grow, leadership wanted a better understanding of the cyber risks across the organization. 

The goal was to establish a baseline for the airport’s current cybersecurity posture, identify its most significant areas of risk, and use that information to guide future projects and investment. The airport also wanted to take greater ownership of its security processes rather than relying on disconnected activities or outside support. 

The Challenge 

Baton Rouge Metropolitan Airport needed a better understanding of what was happening across its technology and operational environments. Without a complete view of its current risks, it was difficult to determine where attention was most needed, or which security initiatives should come first. 

The airport’s key challenges were: 

  • Limited visibility of cybersecurity risks, control gaps, responsibilities, and dependencies across the environment.
  • Difficulty prioritizing future security projects and tying those projects to operational needs and available budgets.
  • A need to bring greater consistency and ownership to cybersecurity activities across the airport. 

The airport considered multiple cybersecurity providers before selecting Bridewell. Following interviews with different companies, the team felt most comfortable with Bridewell’s experience, particularly its work in complex and operationally sensitive environments. The airport also felt Bridewell understood that the assessment needed to reflect how BTR operates rather than applying a standard approach without context.

The Solution 

Bridewell conducted an onsite risk assessment over the course of two days, collaborating directly with personnel responsible for technology, airport operations, security processes, critical systems, and vendor relationships. 

The assessment looked at how cyber risks were identified and managed, how responsibilities were assigned, how controls operated in practice, how the airport would respond to an incident or operational disruption, and how these items all influenced the passenger journey. Bridewell reviewed areas including cybersecurity governance, risk management, IT and operational technology, asset visibility, third-party dependencies, access controls, incident response, business continuity, disaster recovery, backups, and security awareness. 

From the airport’s perspective, one of the strongest parts of the engagement was the level of preparation and organization. The project plan was clear, the onsite sessions were well structured, and the questions reflected an understanding of both the technologies in use and the people responsible for them. The assessment also went beyond confirming whether a policy, process, or control existed. Bridewell asked how those controls worked in practice, who owned them, how decisions were made, and what would happen under different operational scenarios. That made the engagement feel specific to BTR rather than like a generic checklist exercise. 

The process required significant input from the airport team, but that was viewed as a benefit rather than a burden. The questions challenged personnel to examine existing assumptions, responsibilities, and dependencies in more detail and helped surface issues that may not have been obvious through a documentation review alone. 

The Results 

The assessment gave Baton Rouge Metropolitan Airport a much clearer view of its cybersecurity position and what needed to happen next. Key results include: 

  • Greater visibility of cybersecurity risks, control gaps, responsibilities, and dependencies across the airport.
  • A prioritized roadmap that is helping BTR plan future cybersecurity projects and budget for security improvements.
  • Increased ownership of cybersecurity processes within the airport, giving the organization more control over how security is managed day to day. 

Since the engagement, Bridewell has had several discussions with BTR to support the airport’s work to bring more of its cybersecurity processes under direct airport ownership. As the airport works towards becoming its own Authority, BTR has incorporated future security initiatives into its budget planning. The assessment and the executive report have given the airport a clearer basis for deciding where to invest, what to prioritize, and how to develop its cybersecurity program over time.


Industry

Aviation

Featured Services