cyber threats

What is the Position Regarding the Use of GSM Mobile Phones to Comply with EASA ISMS requirements?

read more
A smartphone with a glowing security padlock icon on its screen, placed on a high-tech circuit board. The text asks about the use of GSM mobile phones to comply with EASA ISMS requirements.

November 06, 2025

Steven Bentley

Specific Exposures and Threat Scenarios Malware/Ransomware Initial Access (Exploitation via device) General Ransomware Campaigns: Ransomware actors often gain initial access through phishing campaigns targeting aviation employees or by exploiting exposed VPN/RDP servers. Mobile devices are the primary target for phishing/social engineering attempts. Ransomware group LockBit demanded $200 million from Boeing in 2023. Attacks on airport…

Part 145 Cybersecurity Essentials – Protect Your Maintenance Operations Against Cyber Threats with the New SOL Training

read more
Part - 145 - Cybersecurity - Essentials

September 23, 2025

Steven Bentley

Sofema Aviation Services (SAS) is pleased to announce a new training available through Sofema Online (SOL): Part 145 Cybersecurity Essentials Enrol today What is the training about? The Part 145 Cybersecurity Essentials course by Sofema Online offers a focused introduction to the key cybersecurity principles, risks, and regulatory expectations that affect EASA Part 145-approved organisations….

Lessons Learned from Real-World Cyber Threats – In Aviation Organizations, Operators, CAMOs, and Maintainers

read more
Cyber Threats blog image

May 22, 2025

Steven Bentley

Sofema Aviation Services (SAS) shares lessons learned from real world Cyber Threats Introduction See the following typical examples and mitigations to “take away” Cybersecurity is a shared responsibility across all aviation functions. Whether managing aircraft configuration, scheduling maintenance, or overseeing day-to-day operations, Operators, CAMOs, and Maintainers must build cyber resilience into their core processes (not…

EASA is Driving Information & Cyber Security Regulations – WHY?

read more
Cyber-Security-Regulations – WHY?

March 05, 2025

Steven Bentley

Sofema Aviation Services considers key aspects of Information & Cyber Security Management, since EASA is mandating Aviation Information and Cyber Security Regulations. Cyber threats pose a significant risk to aviation safety, operational continuity, and compliance with international standards.While organizations are responsible for managing their security risks, a regulatory framework ensures a harmonized, risk-based, and proactive…