IT infrastructure

Case Studies: Aviation Cybersecurity Breaches Affecting Commercial Aircraft Operators

read more
Cybersecurity Breaches blog image

May 20, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers several examples of Cybersecurity Breaches Introduction The following examples illustrate how vulnerabilities, whether in operations, IT infrastructure, or third-party systems, can impact aviation safety, continuity, and reputation. British Airways Data Breach (2018) Type: Data Theft Impact: 500,000 customer records compromised Method: Injection of malicious code via third-party scripts on the website and mobile…

Assessing ISMS Vulnerabilities in the Supply Chain and IT Infrastructure

read more
IT Infrastructure blog image

April 30, 2025

Steven Bentley

Sofema Aviation Services (SAS) Considers key issues related to the assessment of vulnerabilities within the operational supply chain Introduction To mitigate risks related to supply chain and IT infrastructure vulnerabilities in an EASA-compliant Information Security Management System (ISMS) under Regulation (EU) 2023/203, a structured and proactive approach is essential. Consider the following: Understanding the Nature…

Cyber Integration into an EASA Part 145 Organization – Risk Management Framework

read more
A digital image featuring a business professional interacting with a risk management dashboard, highlighting key cybersecurity elements such as data protection, analytics, and compliance. The Sofema Aviation Services (SAS) logo appears in the top left corner, with the text: "Cyber Integration into an EASA Part 145 Organization Risk Management Framework." The image represents the importance of cyber risk management in aviation maintenance organizations under EASA regulations.

February 07, 2025

Steven Bentley

Sofema Aviation Services (SAS) considers the challenges related to phishing, ransomware, data breaches, and insider threat exposures (both intentional and accidental) within the framework of an EASA Part 145 organization. Challenges in Cybersecurity for Part 145 Organizations EASA Part 145 organizations, as integral components of the aviation safety chain, face distinct challenges in managing information…