قمرة القيادة هي أكثر الأماكن حماية في الطائرة، ومن يجلس داخلها مرّ بسلسلة طويلة من التأهيل والتدريب والفحوص والاختبارات الأمنية والمهنية.
كل ذلك لحماية الطائرة وركابها من أي خطر يأتي من الخارج، لكن حادثة طائرة فلاي دبي الأسبوع الماضي أعادت إلى الواجهة سؤالاً صعباً، ماذا يحدث عندما يكون مصدر الخطر داخل المكان الذي صُمم أصلاً للحماية من الخطر؟
هذه ليست مشكلة جديدة تماماً في صناعة الطيران، لكنها من أصعب معادلات السلامة والأمن فيها.
بعد أحداث 11 سبتمبر 2001 تغيرت قمرة القيادة، حينها استطاع المختطفون الوصول إلى الطيارين والسيطرة على الطائرات، فكان أحد أهم الدروس أن الوصول إلى القمرة يجب ألا يكون سهلاً، بعد ذلك أصبحت أبواب قمرة القيادة أكثر صلابة، ووضعت أنظمة وإجراءات تجعل فتحها من الخارج بالغ الصعوبة، وكان المنطق أنه إذا لم يستطع المهاجم الوصول إلى الطيارين فلن يستطيع السيطرة على الطائرة، وبالفعل أصبح الباب جزءاً أساسياً من منظومة أمن الطيران الحديثة.
لكن بعد سنوات ظهرت المشكلة من الاتجاه الآخر، في كارثة Germanwings عام 2015 خرج قائد الطائرة من قمرة القيادة وبقي مساعده (الذي يخطط للانتحار) داخلها، لم يتمكن القائد من العودة بعد أن أغلق الباب من الداخل وانتهت الرحلة بتحطم الطائرة في جبال الألب الفرنسية ومقتل جميع ركابها.
هنا أصبح الباب الذي صُمم لحماية قمرة القيادة جزءاً من أسباب الكارثة نفسها، ولذلك سارعت وكالة سلامة الطيران الأوروبية بعد الحادثة إلى التوصية بألا يبقى شخص واحد بمفرده داخل القمرة، قبل أن تنتقل لاحقاً إلى أسلوب أكثر مرونة يعتمد على تقييم المخاطر لدى كل شركة، ولا يختصر المشكلة في قاعدة واحدة فقط.
حادثة فلاي دبي الأخيرة تعيد السؤال مرة أخرى لكن بصورة مختلفة، نحن أمام نظام أمني بُني على افتراض أن الخطر سيحاول الوصول إلى قمرة القيادة من الخارج لكن ماذا لو بدأ الخطر من الداخل؟
هل تكفي آليات الاختيار والفحوص الطبية والأمنية وتقييم الحالة النفسية للطيارين؟ وهل نحتاج إلى مراقبة أفضل للتغيرات السلوكية التي قد تطرأ على الطيار خلال سنوات عمله؟
هل يمكن تصميم إجراءات داخل القمرة تسمح بالتدخل السريع عند وقوع اعتداء بين أفراد الطاقم، من دون أن نضعف في الوقت نفسه حمايتها من الاقتحام الخارجي؟ هذه هي الإشكالية الحقيقية.
الحل ليس أن نجعل باب قمرة القيادة أسهل في الفتح، لأننا بذلك قد نعيد الخطر الذي أُنشئ الباب المحصن من أجله أساساً، وليس منطقياً أيضاً أن تتحول قمرة القيادة إلى مكان يخضع فيه الطيار للمراقبة والشك المستمرين، فصناعة الطيران تعتمد كل يوم على آلاف الطيارين الذين ينقلون ملايين البشر بأمان، والحوادث التي يكون فيها أحد أفراد الطاقم مصدراً متعمداً للخطر استثنائية ونادرة للغاية.
لكن فلسفة سلامة الطيران لا تتعامل فقط مع ما يحدث كثيراً، إنها تهتم أيضاً بما يحدث نادراً ولكن قد تكون عواقبه كارثية.
لهذا لا أتوقع أن تكون نتيجة حادثة فلاي دبي مجرد إجراء واحد من نوع (أضف شخص ثالث إلى القمرة) أو (اجعل فتح الباب أكثر سهولة للطيارين)، لأن الحلول البسيطة لمثل هذه المشكلات لا تعيش طويلاً.
بعد Germanwings طُرحت قاعدة وجود شخصين داخل القمرة في كل الأوقات، ثم توصلت وكالة سلامة الطيران الأوروبية إلى أن الأفضل هو التعامل مع المسألة بمنظومة أوسع تشمل الفحص النفسي والأمني، وبرامج دعم الطيارين، واستقرار بيئة العمل، وقدرة الشركة نفسها على اكتشاف المخاطر النفسية والاجتماعية والتعامل معها.
وهنا ربما تكون نقطة التحول القادمة في أن تصبح منظومة السلامة أقدر على اكتشاف الإشارات غير الطبيعية قبل أن تصل إلى الطائرة، وهذا يفتح ملفات كثيرة تتعلق بآليات اختيار الطيارين والفحوصات النفسية الدورية وبرامج الإبلاغ السرية ودعم من يمر بضغوط نفسية أو مهنية ومشاركة المعلومات بين الجهات الأمنية وشركات الطيران عند وجود مؤشرات حقيقية، وربما إعادة تقييم بعض إجراءات العمل داخل قمرة القيادة نفسها.
لكن كل حل من هذه الحلول يحمل مشكلة أخرى، إذا شددت الفحوص النفسية أكثر من اللازم، فقد يخشى الطيار من طلب المساعدة حتى لا يفقد وظيفته، وإذا وسعت تبادل المعلومات الأمنية، تدخلت في مناطق حساسة تتعلق بالخصوصية، وإذا جعلت الوصول إلى القمرة أسهل في حالات الطوارئ فقد تصبح أكثر عرضة للاقتحام.
هنا تحديداً تكمن طبيعة سلامة الطيران، فهي ليست اختياراً بين الأمان والخطر، بل موازنة مستمرة بين أخطار مختلفة.
لقد نجحت صناعة الطيران طوال ربع قرن في جعل قمرة القيادة حصناً يصعب الوصول إليه، لكن حادثة فلاي دبي تعيد أمامها الجزء الأصعب من المعادلة.
المنظمة الدولية للطيران المدني ICAO وضعت منذ سنوات معايير لمواجهة التهديدات الداخلية Insider Threat، تشمل التحقق من الخلفيات وتقييم المخاطر ونقاط الضعف ومراقبة الوصول إلى المناطق الحساسة، لكن الحادثة الأخيرة تطرح نسخة أكثر تعقيداً من السؤال، ماذا نفعل عندما يكون مصدر التهديد نفسه أحد الشخصين اللذين صُممت أكثر منطقة محمية في الطائرة لتكون تحت سيطرتهما؟
الباب المحصن يستطيع أن يمنع شخصاً خطيراً من الدخول، لكنه لا يستطيع أن يعرف شيئاً عن الشخص الموجود خلفه.
The cockpit is the most protected area in the aircraft, and anyone sitting inside it has gone through a long series of qualifications, training, checks, and security and professional tests.
All of this is to protect the aircraft and its passengers from any external threat, but the Flydubai incident last week brought back a difficult question: what happens when the source of danger is inside the very place designed to protect against danger?
This is not a completely new problem in the aviation industry, but it is one of the most challenging safety and security equations within it.
After the events of September 11, 2001, the cockpit changed; at that time, hijackers were able to reach the pilots and take control of the planes. One of the key lessons learned was that access to the cockpit should not be easy. Subsequently, cockpit doors became more robust, and systems and procedures were put in place to make opening them from the outside extremely difficult. The logic was that if an attacker could not reach the pilots, they would not be able to take control of the aircraft, and indeed, the door became an essential part of modern aviation security.
However, years later, the problem emerged from the other direction. In the Germanwings disaster in 2015, the captain left the cockpit and his co-pilot (who was planning to commit suicide) remained inside. The captain was unable to return after the door was closed from the inside, and the flight ended with the aircraft crashing in the French Alps, killing all on board.
Here, the door designed to protect the cockpit became part of the reasons for the disaster itself. Therefore, the European Aviation Safety Agency quickly recommended that no one should be left alone in the cockpit. Later, it moved to a more flexible approach based on risk assessment by each airline, rather than reducing the problem to a single rule.
The recent Flydubai incident raises the question again but in a different light. We are faced with a security system built on the assumption that the threat will attempt to access the cockpit from the outside, but what if the threat originates from within?
Are the selection mechanisms, medical and security checks, and psychological evaluations of pilots sufficient? Do we need better monitoring of behavioral changes that may occur in pilots over their years of service?
Can procedures be designed within the cockpit that allow for rapid intervention in the event of an assault among crew members, without simultaneously weakening its protection against external intrusion? This is the real dilemma.
The solution is not to make the cockpit door easier to open, as this could reintroduce the danger for which the fortified door was originally created. It is also not logical for the cockpit to become a place where the pilot is under constant surveillance and suspicion, as the aviation industry relies every day on thousands of pilots who safely transport millions of people, and incidents where a crew member is a deliberate source of danger are exceptional and extremely rare.
However, the philosophy of aviation safety does not only deal with what happens frequently; it also cares about what happens rarely but could have catastrophic consequences.
For this reason, I do not expect the outcome of the Flydubai incident to be a simple measure like (adding a third person to the cockpit) or (making it easier for pilots to open the door), because simple solutions to such problems do not last long.
After Germanwings, the rule of having two people in the cockpit at all times was proposed, and then the European Aviation Safety Agency concluded that it is better to address the issue with a broader system that includes psychological and security assessments, pilot support programs, workplace stability, and the company's ability to detect and address psychological and social risks.
Here, perhaps, lies the next turning point in making the safety system more capable of detecting abnormal signals before they reach the aircraft. This opens many files related to pilot selection mechanisms, periodic psychological assessments, confidential reporting programs, support for those undergoing psychological or professional stress, and sharing information between security agencies and airlines when there are real indicators, as well as possibly reevaluating some operational procedures within the cockpit itself.
But each of these solutions carries another problem. If psychological assessments are tightened too much, pilots may fear seeking help lest they lose their jobs. If the exchange of security information is broadened, it may intrude into sensitive areas related to privacy. If access to the cockpit is made easier in emergencies, it may become more susceptible to intrusion.
Herein lies the nature of aviation safety; it is not a choice between safety and danger, but a continuous balancing act between different risks.
The aviation industry has succeeded for a quarter of a century in making the cockpit a fortress that is difficult to access, but the Flydubai incident presents it with the most challenging part of the equation.
The International Civil Aviation Organization (ICAO) has set standards for addressing insider threats for years, including background checks, risk assessments, vulnerability assessments, and monitoring access to sensitive areas. However, the recent incident poses a more complex version of the question: what do we do when the source of the threat is one of the two individuals for whom the most protected area in the aircraft was designed to be under their control?
The fortified door can prevent a dangerous person from entering, but it cannot know anything about the person behind it.