top of page


Responding to Information Security Vulnerabilities Under EASA Part-IS (IS.I.OR.220)
Not every vulnerability needs fixing. But every one of them needs a decision. Under IS.I.OR.220, the act of logging a weakness and setting it aside is itself a risk position — and it needs to be a deliberate one. This article covers how vulnerability response should actually work: CVSS scoring, contextual risk assessment, and when treatment becomes mandatory under EASA Part-IS.

Luka Pace Bonello
Jun 145 min read


How to Reduce Information Security Risk Under EASA Part-IS
Reducing information security risk under EASA Part-IS goes beyond theory. This article explains how aviation organisations can apply risk treatment in practice, using a real flight operations example. Learn how to reduce risk levels through targeted security controls, structured decision-making, and a practical risk treatment plan aligned with Part-IS requirements.

Luka Pace Bonello
Mar 267 min read


Information Security Risk Treatment under EASA Part-IS: A Practical Guide
How should aviation organisations treat information security risks under EASA Part-IS? This article explains how unacceptable cyber risks should be reduced, documented, and managed in practice under IS.I.OR.210. Using a realistic flight operations example, it shows how aviation organisations move from risk identification to effective risk treatment while protecting aviation safety.

Luka Pace Bonello
Mar 136 min read
bottom of page