information security risks

What is the Position Regarding the Use of GSM Mobile Phones to Comply with EASA ISMS requirements?

read more
A smartphone with a glowing security padlock icon on its screen, placed on a high-tech circuit board. The text asks about the use of GSM mobile phones to comply with EASA ISMS requirements.

November 06, 2025

Steven Bentley

Specific Exposures and Threat Scenarios Malware/Ransomware Initial Access (Exploitation via device) General Ransomware Campaigns: Ransomware actors often gain initial access through phishing campaigns targeting aviation employees or by exploiting exposed VPN/RDP servers. Mobile devices are the primary target for phishing/social engineering attempts. Ransomware group LockBit demanded $200 million from Boeing in 2023. Attacks on airport…

EASA Reference Listing for Aviation Cyber Security Initiatives – R1

read more
A professional pointing at a digital interface displaying documents and a security lock icon, representing the EASA Reference Listing for Aviation Cyber Security Initiatives – R1.

February 14, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers a number of core documents used in support of EASA compliant cyber security initiatives. AMC 20-42 Airworthiness Information Security Risk Assessment Date: June 2023Description: Guidance for assessing airworthiness information security risks, including threats and mitigations. COMMISSION DELEGATED REGULATION (EU) 2022/1645 Date: July 2022Description: Rules for managing aviation information security risks impacting safety. COMMISSION IMPLEMENTING REGULATION (EU) 2023/203 Date: October 2022Description:…

EASA 2024 Regulatory Update Operations, Maintenance and CAMO Management

read more
Aircraft maintenance professionals inspecting and working on an open engine, representing updates in EASA 2024 regulations for operations, maintenance, and CAMO management.

February 12, 2025

Steven Bentley

Sofema Aviation Services (SAS) reviews key changes introduced in the EASA 2024 Regulatory Update, impacting operations and maintenance under EASA regulations. During 2024, the European Union Aviation Safety Agency (EASA) introduced several significant updates to regulations concerning maintenance operations and Continuing Airworthiness Management Organisations (CAMOs). Key developments include: Easy Access Rules for Continuing Airworthiness (Revision…