top of page


How to Assess Information Security Risks Under EASA Part-IS: A Practical Safety-Focused Approach
Assessing information security risks under EASA Part-IS requires more than technical analysis. It demands a structured, safety-focused approach that identifies how compromised information could affect safe operations. Using a practical CAMO maintenance data scenario, this article breaks down how to evaluate impact, reason through likelihood, derive risk, and ensure assessments are aligned with aviation safety principles.

Luka Pace Bonello
Feb 266 min read


EASA Part-IS Risk Assessments Explained: Protecting Aviation Safety in the Digital Age
Information security risk assessment under EASA Part-IS transforms information security from a technical concern into a core aviation safety function. By identifying threat scenarios, assessing safety impact, and evaluating likelihood, organisations can understand where digital risks may affect safe operations and ensure protective measures are focused where they matter most.

Luka Pace Bonello
Feb 175 min read


Having the Right People Is the Key to Successful Part-IS Compliance
Part IS compliance depends on people, not technology alone. This article explains which roles matter, why clear accountability is essential, and how the right people make your ISMS effective and compliant.

Luka Pace Bonello
Jan 67 min read


Part-IS: Building a Safety-Focused Information Security Management System.
As aviation becomes increasingly digital, protecting information has become inseparable from protecting safety. EASA Part-IS introduces a framework that strengthens existing safety and compliance systems through the integration of information security. This article breaks down what a safety-focused ISMS looks like in practice - from leadership and scope to incident response and continuous improvement - and explores the mindset shift needed to make Part-IS work.

Luka Pace Bonello
Dec 15, 20255 min read


The Rise of Aviation Information Security & EASA Part-IS
As aviation becomes increasingly digital and connected, protecting data and systems is now as vital as flight safety itself. The industry’s growing reliance on technology brings new risks that can impact operations and trust. EASA’s Part-IS regulation marks a major step forward, requiring aviation organisations to manage information security just as they do safety. This shift highlights a simple truth: cybersecurity is now an essential part of keeping aviation safe.

Luka Pace Bonello
Apr 3, 20245 min read
bottom of page