top of page


Recovering from Information Security Incidents Under EASA Part-IS (IS.I.OR.220)
Containing an incident isn't the finish line. A manipulated navigation database can still let an aircraft appear to work perfectly — which is exactly why "available" and "safe" are not the same thing. Recovery under EASA Part-IS is the discipline in between: finding the real cause before removing the file, restoring systems to a state that is both safe and secure, and verifying it before anything returns to service.

Luka Pace Bonello
Jul 65 min read


Responding to Information Security Incidents Under EASA Part-IS (IS.I.OR.220)
When a confirmed incident occurs under IS.I.OR.220, the objective is not to fix what went wrong. The goal is control — limit the impact on aviation safety, contain the threat, and create conditions for a proper resolution. Repair comes later. This article covers what incident response actually requires, including why your response measure itself may carry immediate safety risk.

Luka Pace Bonello
May 287 min read


How to Detect Incidents and Vulnerabilities Under EASA Part-IS (IS.I.OR.220)
Incident and vulnerability detection under EASA Part-IS begins with the collection and analysis of information security events. This article explains how monitoring, internal reporting, external intelligence, and auditing work together to identify abnormal activity, detect incidents early, and uncover vulnerabilities that may impact aviation safety and operational integrity.

Luka Pace Bonello
May 86 min read


EASA Part-IS: How to Tell the Difference Between a Vulnerability and an Incident (And Why You Must)
Understanding the distinction between vulnerabilities and incidents is critical for effective EASA Part-IS compliance. This article provides a clear, practical breakdown of IS.I.OR.220, helping organisations correctly assess, manage, and respond to each. It offers structured guidance to strengthen your ISMS, support informed decision-making, and ensure a proactive, risk-based approach to aviation information security.

Luka Pace Bonello
Apr 106 min read
bottom of page