Aviation Information Security, Explained
What information security means in an aviation organisation: the C·I·A·A pillars, threat actors, and how an attack gets in.
Dionysis Kefalas10 min readFor Part-145, CAMO and Air Ops staff
Part 2 of 4 in Part-IS Implementation Show parts
- 1Part-IS Requirements, Scope and Deadlines
- 2Aviation Information Security, Explained
- 3Aviation Cyber Incidents and Their Lessons
- 4Part-IS Shop-Floor Practice and Reporting
Quotes checked on against EASA Easy Access Rules for Information Security (Regulations (EU) 2022/1645 and (EU) 2023/203) — 5 Dec 2025 revision.
On this page
Three terms people mix up
Information security, cybersecurity and IT security are used interchangeably in conversation. They are not the same job.
The legal definitions
Part-IS does not leave these words to intuition. Article 3 of Implementing Regulation (EU) 2023/203 is the vocabulary the rest of this guide uses.
For the purpose of this Regulation, the following definitions shall apply:
(1)‘information security’ means the preservation of confidentiality, integrity, authenticity and availability of network and information systems;
(2)‘information security event’ means an identified occurrence of a system, service or network state indicating a possible breach of the information security policy or failure of information security controls, or a previously unknown situation that can be relevant for information security;
(3)‘incident’ means any event having an actual adverse effect on the security of network and information systems as defined in Article 4(7) of Directive (EU) 2016/1148;
(4)‘information security risk’ means the risk to organisational civil aviation operations, assets, individuals, and other organisations due to the potential of an information security event. Information security risks are associated with the potential that threats will exploit vulnerabilities of an information asset or group of information assets;
(5)‘threat’ means a potential violation of information security which exists when there is an entity, circumstance, action or event that could cause harm;
(6)‘vulnerability’ means a flaw or weakness in an asset or a system, procedures, design, implementation, or information security measures that could be exploited and results in a breach or violation of the information security policy.
Quoted word for word from Implementing Regulation (EU) 2023/203, Easy Access Rules for Information Security, 5 Dec 2025 revision.
The headings below are the properties named in point (1). The workshop story at the end of this page uses the other words in the same article. The reporting rule is quoted in the first guide of this series. It is not restated here.
The pillars — C·I·A·A
Each property in point (1) fails in a different way.
Confidentiality
Only authorised people see the information.
- Example: customer contracts, employee data, the OEM portal credentials used for CMM access.
- Breach: a phished mailbox exposing every purchase order and certificate ever emailed through it.
Integrity
Information is accurate and has not been tampered with.
- Example: a measured value in a test or inspection record.
- Breach: a corrupted or manipulated test value leading to an unairworthy component being released — a direct safety impact.
Authenticity
Information genuinely comes from who it claims to come from.
- Example: an EASA Form 1 PDF received from a supplier.
- Breach: a forged release certificate accompanying a counterfeit or bogus part.
Availability
Information and systems are there when you need them.
- Example: the maintenance data system and CMM library during maintenance.
- Breach: ransomware locks the records — work stops, aircraft go AOG.
Who is the threat?
"Hacker" is not one person. The actors behind information security attacks differ in motivation, patience and skill — and knowing which one is most likely matters when deciding what to defend first:
The key point: most attacks are not targeted at any organisation specifically — they are mass-scale and automated. You do not need to be interesting to be a victim; you only need to be reachable.
How organisations get hacked
An intrusion often starts through one of these doors.
Phishing & spear-phishing
- Fake emails that look legitimate, carrying a poisoned link or attachment.
- Spear-phishing is the targeted version: "Hi, please review the attached revised CMM" — apparently from the quality manager.
- Business email compromise (BEC): the attacker sits inside a real mailbox and asks you to change a supplier's bank details.
Social engineering
- Manipulating people instead of machines: a phone call "from IT" asking for your password (vishing).
- Pretexting: someone in a hi-vis vest tailgating into the workshop "for the audit".
- QR codes on posters or invoices that lead to credential-harvesting pages (quishing).
Malware & ransomware
- Malicious software delivered via attachments, cracked/pirated tools, or compromised websites.
- Ransomware encrypts files and demands payment — modern crews also steal the data first and threaten to publish it (double extortion).
- One click on one machine can take down the whole network over a weekend.
Removable media (USB)
- Infected USB sticks moving between machines — the classic way into networks that are otherwise isolated.
- Directly relevant where USB sticks carry test profiles or software updates to test and tooling equipment.
Stolen & weak credentials
- Password reuse: one leaked website password unlocks work accounts (credential stuffing).
- Default passwords on equipment and admin panels that nobody ever changed.
- Infostealer malware on a private PC silently harvesting every saved password — including the OEM portal login.
Unpatched & legacy systems
- Known vulnerabilities with public exploits — attackers scan for them soon after disclosure.
- The "do not touch it, it works" Windows PC controlling a test bench or tooling station is a standing invitation.
- Supply-chain variant: a compromised vendor or software update arrives already trusted.
The attacks
The vectors above are the doors in. These are the attacks that come through them, and what each one does to the organisation that gets hit. Sourced incidents are in the next guide. This page does not retell them.
In a maintenance, CAMO or operations organisation, a stopped job, a leaked file or a broken login can become the risk in point (4). The first guide quotes the rules that apply to that risk.
Vulnerabilities you will recognise
None of the attacks above lands without a weakness to land on. These are the vulnerabilities an honest walk-through of a typical Part-145 — and just as often a CAMO office or an operations department — will turn up:
- Shared logins for the CMMS, the airworthiness-records system or the certification stamp terminal — no traceability, no accountability.
- One flat network: office systems and workshop/test equipment on the same network segment — one phished laptop can reach the bench PCs.
- Legacy operating systems on tool and test-equipment controllers that no longer receive updates.
- Open file shares holding scanned certificates, work packs and continuing-airworthiness records, with no access control, in maintenance, CAMO and ops alike.
- Leavers and contractors whose accounts and badge access are never revoked.
- No backups — or backups on the same network that the ransomware will encrypt too.
Threat × vulnerability = risk
Put the pieces together and the abstract definitions from Article 3 become one concrete storyline:
The threat. A criminal group mass-mails a fake 'updated supplier portal' login page. That is the threat in point (5).
The vulnerability. A stores clerk reuses the same password everywhere, and there is no multi-factor authentication. Nothing has happened yet. That is the risk in point (4).
The event — then the incident. The clerk enters credentials on the fake page. That is the event in point (2). The attacker logs into the real mailbox, watches the traffic, then sends customers 'updated bank details'. That is the incident in point (3).
The safety angle. The same mailbox handles release certificates and AD compliance correspondence — its integrity and authenticity are now gone, and the consequences are no longer confined to the finance department.
The first guide quotes who the regulations apply to, the dates, and the reporting rule. Sourced incidents are in the next guide.
Educational content, not regulatory compliance advice. Verify against the current regulation text before relying on it.
In this series
Related
Written by Dionysis Kefalas. Retired Hellenic Air Force Captain and founder of Avioverse. About the author
Metis opens with Avioverse in October 2026 · request early access.