Skip to content

A gradual release of Avioverse begins in October 2026. Request early access →

Aviation Information Security, Explained

What information security means in an aviation organisation: the C·I·A·A pillars, threat actors, and how an attack gets in.

Dionysis Kefalas10 min readFor Part-145, CAMO and Air Ops staff

Part 2 of 4 in Part-IS Implementation Show parts
  1. 1Part-IS Requirements, Scope and Deadlines
  2. 2Aviation Information Security, Explained
  3. 3Aviation Cyber Incidents and Their Lessons
  4. 4Part-IS Shop-Floor Practice and Reporting

Quotes checked on against EASA Easy Access Rules for Information Security (Regulations (EU) 2022/1645 and (EU) 2023/203) — 5 Dec 2025 revision.

On this page

Three terms people mix up

Information security, cybersecurity and IT security are used interchangeably in conversation. They are not the same job.

TermWhat it meansDay-to-day example
Information securityThe term Article 3 defines. The sentence is the quote below, not this table.A work order in the maintenance system.
CybersecurityProtecting digital systems, networks and data against attacks carried out through cyberspace.Stopping ransomware from encrypting the server that holds maintenance and inspection records.
IT securityProtecting the computers, servers and networks themselves.Patching the workstation that runs the records software.

Part-IS does not leave these words to intuition. Article 3 of Implementing Regulation (EU) 2023/203 is the vocabulary the rest of this guide uses.

Article 3 (full rule text)Definitions

For the purpose of this Regulation, the following definitions shall apply:

(1)‘information security’ means the preservation of confidentiality, integrity, authenticity and availability of network and information systems;

(2)‘information security event’ means an identified occurrence of a system, service or network state indicating a possible breach of the information security policy or failure of information security controls, or a previously unknown situation that can be relevant for information security;

(3)‘incident’ means any event having an actual adverse effect on the security of network and information systems as defined in Article 4(7) of Directive (EU) 2016/1148;

(4)‘information security risk’ means the risk to organisational civil aviation operations, assets, individuals, and other organisations due to the potential of an information security event. Information security risks are associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets;

(5)‘threat’ means a potential violation of information security which exists when there is an entity, circumstance, action or event that could cause harm;

(6)‘vulnerability’ means a flaw or weakness in an asset or a system, procedures, design, implementation, or information security measures that could be exploited and results in a breach or violation of the information security policy.

Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.

The headings below are the properties named in point (1). The workshop story at the end of this page uses the other words in the same article. The reporting rule is quoted in the first guide of this series. It is not restated here.

The pillars — C·I·A·A

Each property in point (1) fails in a different way.

Confidentiality

Only authorised people see the information.

  • Example: customer contracts, employee data, the OEM portal credentials used for CMM access.
  • Breach: a phished mailbox exposing every purchase order and certificate ever emailed through it.

Integrity

Information is accurate and has not been tampered with.

  • Example: a measured value in a test or inspection record.
  • Breach: a corrupted or manipulated test value leading to an unairworthy component being released — a direct safety impact.

Authenticity

Information genuinely comes from who it claims to come from.

  • Example: an EASA Form 1 PDF received from a supplier.
  • Breach: a forged release certificate accompanying a counterfeit or bogus part.

Availability

Information and systems are there when you need them.

  • Example: the maintenance data system and CMM library during maintenance.
  • Breach: ransomware locks the records — work stops, aircraft go AOG.

Who is the threat?

"Hacker" is not one person. The actors behind information security attacks differ in motivation, patience and skill — and knowing which one is most likely matters when deciding what to defend first:

ActorMotivationTypical action
CybercriminalsMoney — ransom, fraud, resale of dataRansomware, business email compromise, invoice fraud. By far the most likely attacker for a maintenance, CAMO or operations organisation.
State-sponsored groupsEspionage, disruption, strategic advantageLong, quiet intrusions into aviation and defence supply chains to steal technical data.
HacktivistsIdeology, publicityWebsite defacement, leaks, denial-of-service around political events.
InsidersGrievance, money — or simply carelessnessA leaver who keeps access; an employee who plugs in an unknown USB stick. The negligent insider is more common than the malicious one.
Opportunists ('script kiddies')Curiosity, bragging rightsAutomated scans for anything unpatched and exposed to the internet — they do not care who you are.

The key point: most attacks are not targeted at any organisation specifically — they are mass-scale and automated. You do not need to be interesting to be a victim; you only need to be reachable.

How organisations get hacked

An intrusion often starts through one of these doors.

Phishing & spear-phishing

  • Fake emails that look legitimate, carrying a poisoned link or attachment.
  • Spear-phishing is the targeted version: "Hi, please review the attached revised CMM" — apparently from the quality manager.
  • Business email compromise (BEC): the attacker sits inside a real mailbox and asks you to change a supplier's bank details.

Social engineering

  • Manipulating people instead of machines: a phone call "from IT" asking for your password (vishing).
  • Pretexting: someone in a hi-vis vest tailgating into the workshop "for the audit".
  • QR codes on posters or invoices that lead to credential-harvesting pages (quishing).

Malware & ransomware

  • Malicious software delivered via attachments, cracked/pirated tools, or compromised websites.
  • Ransomware encrypts files and demands payment — modern crews also steal the data first and threaten to publish it (double extortion).
  • One click on one machine can take down the whole network over a weekend.

Removable media (USB)

  • Infected USB sticks moving between machines — the classic way into networks that are otherwise isolated.
  • Directly relevant where USB sticks carry test profiles or software updates to test and tooling equipment.

Stolen & weak credentials

  • Password reuse: one leaked website password unlocks work accounts (credential stuffing).
  • Default passwords on equipment and admin panels that nobody ever changed.
  • Infostealer malware on a private PC silently harvesting every saved password — including the OEM portal login.

Unpatched & legacy systems

  • Known vulnerabilities with public exploits — attackers scan for them soon after disclosure.
  • The "do not touch it, it works" Windows PC controlling a test bench or tooling station is a standing invitation.
  • Supply-chain variant: a compromised vendor or software update arrives already trusted.

The attacks

The vectors above are the doors in. These are the attacks that come through them, and what each one does to the organisation that gets hit. Sourced incidents are in the next guide. This page does not retell them.

AttackWhat it isResult
Malware (virus · worm · trojan · spyware)Umbrella term for hostile software. A virus attaches to files and spreads when they are opened; a worm spreads across the network by itself; a trojan hides inside something that looks legitimate (an invoice, a free tool); spyware and keyloggers silently record what you type.Stolen data and passwords, remote control of the machine — usually the quiet first stage of a bigger attack.
RansomwareMalware that encrypts files and demands payment for the key. Modern gangs steal the data first and threaten to publish it if the victim refuses (double extortion).Work stops, records become unreachable, releases are blocked — aircraft go AOG. The stolen data can still leak.
DDoS — distributed denial of serviceHijacked machines (a botnet) flood a website or service with traffic until it collapses. Nothing is stolen — reachability itself is the target.Customers and partners are cut off — portals, webmail, booking, OEM sites. Flights keep flying, but business and communication stop. Sometimes used as a smokescreen for a quieter intrusion happening at the same time.
Phishing & business email compromise (BEC)Fraudulent messages harvesting credentials or delivering malware. BEC is the follow-on: the attacker controls or convincingly impersonates a real business mailbox and redirects payments, orders or documents.Mailbox takeover, fraud (changed bank details on real invoices), leaked correspondence — and the foothold for nearly everything else in this table.
Man-in-the-middleThe attacker silently sits between the user and the service — a rogue 'free Wi-Fi' hotspot or spoofed network — reading and, if wanted, altering the traffic.Captured credentials and data, possibly altered content in transit — and the user notices nothing at all.
Credential attacks — brute force & stuffingAutomated guessing of weak passwords (brute force), or replaying leaked email/password pairs from other breaches against a target's services (credential stuffing).Account takeover without any system ever being 'hacked'. Without MFA, one reused password equals full access.
Zero-day & unpatched exploitsAttacks through a software vulnerability the vendor has no fix for yet (zero-day) — or one they fixed months ago that was never installed.A breach even when nobody clicked anything. The practical defences are fast patching, detection, and network segmentation.
Supply-chain attackCompromise of a trusted supplier — a software update, a service provider, a vendor portal — so the attack arrives pre-trusted inside the environment.The attacker inherits the supplier's access. The organisation's own perimeter never saw an attack.
Web-application attacksAttacks on a public website or portal: injected scripts that skim what users type, or SQL injection that pulls the database behind a web form.Customer data stolen at the point of entry — the organisation's own website turned into the attacker's tool.

In a maintenance, CAMO or operations organisation, a stopped job, a leaked file or a broken login can become the risk in point (4). The first guide quotes the rules that apply to that risk.

Vulnerabilities you will recognise

None of the attacks above lands without a weakness to land on. These are the vulnerabilities an honest walk-through of a typical Part-145 — and just as often a CAMO office or an operations department — will turn up:

  • Shared logins for the CMMS, the airworthiness-records system or the certification stamp terminal — no traceability, no accountability.
  • One flat network: office systems and workshop/test equipment on the same network segment — one phished laptop can reach the bench PCs.
  • Legacy operating systems on tool and test-equipment controllers that no longer receive updates.
  • Open file shares holding scanned certificates, work packs and continuing-airworthiness records, with no access control, in maintenance, CAMO and ops alike.
  • Leavers and contractors whose accounts and badge access are never revoked.
  • No backups — or backups on the same network that the ransomware will encrypt too.

Threat × vulnerability = risk

Put the pieces together and the abstract definitions from Article 3 become one concrete storyline:

The threat. A criminal group mass-mails a fake 'updated supplier portal' login page. That is the threat in point (5).

The vulnerability. A stores clerk reuses the same password everywhere, and there is no multi-factor authentication. Nothing has happened yet. That is the risk in point (4).

The event — then the incident. The clerk enters credentials on the fake page. That is the event in point (2). The attacker logs into the real mailbox, watches the traffic, then sends customers 'updated bank details'. That is the incident in point (3).

The safety angle. The same mailbox handles release certificates and AD compliance correspondence — its integrity and authenticity are now gone, and the consequences are no longer confined to the finance department.

The first guide quotes who the regulations apply to, the dates, and the reporting rule. Sourced incidents are in the next guide.

Educational content, not regulatory compliance advice. Verify against the current regulation text before relying on it.