incident response

EASA Part IS Auditor & Risk Assessor Skill Set Requirements

read more
EASA Part IS Auditor and Risk Assessor skill set requirements displayed over a digital cybersecurity background with a lock icon.

November 11, 2025

Steven Bentley

Sofema Aviation Services (SAS) Takes a deep dive into the Role of the Part IS Auditor Introduction The typical skillset required for a Part-IS Auditor or Safety System Risk Assessor primarily centers on aviation safety regulatory expertise and risk management, supplemented by information security knowledge. The premise that the existing broad skillset (Safety/Compliance) can typically address 90% of the task is generally supported by the…

What is the Position Regarding the Use of GSM Mobile Phones to Comply with EASA ISMS requirements?

read more
A smartphone with a glowing security padlock icon on its screen, placed on a high-tech circuit board. The text asks about the use of GSM mobile phones to comply with EASA ISMS requirements.

November 06, 2025

Steven Bentley

Specific Exposures and Threat Scenarios Malware/Ransomware Initial Access (Exploitation via device) General Ransomware Campaigns: Ransomware actors often gain initial access through phishing campaigns targeting aviation employees or by exploiting exposed VPN/RDP servers. Mobile devices are the primary target for phishing/social engineering attempts. Ransomware group LockBit demanded $200 million from Boeing in 2023. Attacks on airport…

Part 145 – Information Security Foundations – Cyber Threat Landscape

read more
A digital security interface featuring a glowing shield with a keyhole, symbolizing cybersecurity protection. A person’s hand is interacting with the interface, emphasizing digital security measures. The Sofema Aviation Services logo is in the top-left corner, with a text overlay discussing Part 145 information security foundations and the cyber threat landscape.

February 28, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the challenges related to phishing, ransomware, data breaches, and insider threat exposures (both intentional and accidental) within the context of EASA Part 145 organizations, together with a high-level mitigation review. Introduction The European Union Aviation Safety Agency (EASA) mandates comprehensive management of information security risks in aviation to safeguard operations,…