top of page

EASA Part-IS Risk Assessments Explained: Protecting Aviation Safety in the Digital Age

  • Writer: Luka Pace Bonello
    Luka Pace Bonello
  • Feb 17
  • 5 min read

Information security risk assessment sits at the heart of compliance with EASA Part-IS. It is the process that turns cybersecurity from a purely technical concern into a core aviation safety function.


Part-IS requires organisations to adopt a risk-based approach to managing information security. This means identifying the threats that could compromise safety-relevant information, understanding the safety consequences if those threats materialise, and determining whether the resulting risk is acceptable.


When performed properly, a risk assessment does more than satisfy regulatory expectations. It provides decision-makers with clarity on where safety could be compromised through digital systems and enables resources to be directed toward protecting what matters most. This makes risk assessment a core phase of the risk management process.


This article sets the foundation for understanding information security risk assessment under Part-IS and explains how it extends existing aviation safety risk management practices.


I share regular, practical insights on EASA Part-IS and aviation cybersecurity. Subscribers also receive my Free Part-IS Starter Checklist.


Subscribe to the Aviation Cybersecurity Brief now!


Wooden blocks spelling "RISK" stacked on a table, with a hand holding a ruler beside them. Blue background, suggesting measurement.

Understanding Risk in the Part-IS Context


Risk assessment under Part-IS focuses on the potential impact of information security threats on aviation safety.


The objective is to understand:


  • How severe the safety consequences could be.

  • How likely the threat scenario is to occur.

  • Whether the resulting risk is acceptable.


This approach mirrors established safety risk management principles. In safety management, hazards are identified and assessed to understand the consequences they may produce. Under Part-IS, threat scenarios serve a similar purpose.


The critical difference lies in intent.


Safety hazards typically arise from unintentional failures such as mechanical defects, human error, or environmental conditions. Information security threats involve deliberate actions taken by threat actors seeking to compromise systems or data.


Despite this difference, the outcome can be the same: degraded safety margins.

 

What is a Threat Scenario?


A threat scenario describes how a threat actor could compromise safety-relevant information.


It is not a vague possibility. It is a structured description of how an attack could unfold, step by step, leading to an operational consequence.


For example, an attacker seeking to alter aircraft maintenance data might:


  1. Gain access to the organisational network;

  2. Obtain valid user credentials;

  3. Access a CAMO maintenance system; and

  4. Modify maintenance planning data.


Each step represents a realistic pathway toward a safety consequence.


Part-IS is concerned with information that supports safe operations. This includes maintenance data, operational procedures, navigation data, load control information, and other information essential to safe flight and airworthiness.


Understanding how such information could be compromised is fundamental to managing safety risk in a digital aviation environment.

 

Likelihood: Considering Intent, Capability, and Opportunity


Likelihood assesses how plausible it is that a threat scenario could succeed.


Unlike safety occurrences, which often involve statistical probabilities, security threats involve intention. This means likelihood must be assessed by considering conditions that enable or discourage attack success.


Factors influencing likelihood include:


  • Exposure of the targeted system or data.

  • Attractiveness of the target to threat actors.

  • Threat actor capability and motivation.

  • Effectiveness of existing safeguards.

  • Opportunity to execute the attack without detection.


This structured reasoning provides a realistic understanding of likelihood without attempting to assign false precision to unpredictable human behaviour and capability.


Impact: Linking Information Security to Aviation Safety


Impact assessment is what distinguishes Part-IS risk assessments from traditional information security risk assessments.


The primary question is not financial loss, operational disruption, or reputational damage. The primary question is whether aviation safety could be affected.


Impact should be evaluated using the same safety severity concepts already applied within your organisation’s Safety Management System (SMS). This ensures consistency and reinforces the principle that information security supports safety.


Using safety severity terminology also enables competent authorities and safety professionals to understand information security risks without translation into unfamiliar technical language.


This alignment strengthens organisational integration and regulatory transparency.

 

Deriving and Evaluating Risk


Once impact and likelihood are assessed, the organisation derives a risk level using a structured method such as a risk matrix (table 1), applying the traditional risk equation:


Risk = Likelihood x Impact



Table 1: Example risk matrix used to derive a risk level.


The purpose of risk evaluation is to determine whether the risk is acceptable.


If the risk falls within acceptable limits (for example, 'Low' to 'Medium'), the decision is documented and monitored.


If the risk exceeds acceptable thresholds (for example, 'High' to 'Critical') the organisation must consider measures to reduce it where existing defences or controls are not sufficient. In Part-IS terms, this process is referred to as risk treatment.


This mirrors the safety principle of maintaining risks within an acceptable level of safety.

 

Being Pragmatic and Relevant


A risk assessment is only valuable if it reflects operational reality.


Threat scenarios should focus on safety-critical processes and information, credible threat actors, realistic attack methods, and current threat trends.


Developing purely theoretical scenarios leads to assessments that do not reflect operational risk and therefore do not support meaningful decision-making.


Understanding the current threat landscape is essential. Cyber attacks affecting aviation and other critical sectors continue to evolve in sophistication and frequency.


This is where elements like threat intelligence help organisations focus on realistic threats rather than hypothetical ones.


A good example of threat intelligence is ENISA’s Threat Landscape report which provides insight into current cyber threat trends affecting Europe and critical infrastructure sectors. Such reports highlight prevalent attack methods, threat actor behaviours, and evolving tactics. This information can inform realistic threat scenario development.


There are many threat intelligence sources out there, and it is important to find the right ones that give you information that is relevant to your organisational context and landscape.

 

Integrating with Existing Safety Risk Management


Part-IS does not mandate a specific risk assessment framework.


Organisations may apply recognised frameworks, such as ISO 31000 and NIST CSF, or adapt existing safety risk management processes.


Extending existing safety methodologies is often the most effective approach. It reinforces the message that information security is part of operational safety rather than a separate discipline.


It also ensures information security risks are expressed in a language already understood by safety personnel and regulators.


This integration improves internal acceptance and simplifies oversight.

 

Risk Assessment as a Living Process


Risk assessment is not a one-time exercise.


It must evolve as systems change, operational interfaces expand, new threats emerge, and incidents provide new insights.


Regular review ensures that the assessment reflects operational reality and emerging risks.


Lessons learned from incidents, vulnerability disclosures, or operational changes should inform updates to ensure that your risk assessment remains relevant and effective.

 

A Foundation for Risk-Based Protection


Risk assessment under Part-IS enables organisations to understand where safety could be compromised through digital means and to take proactive action.


It establishes a clear connection between information security and aviation safety, ensuring that cybersecurity efforts directly support safe operations.


With this foundation in place, the next step is understanding how to perform a practical assessment of a threat scenario and determine its likelihood and safety impact.


That is where the process becomes operational.

 

Want More Part-IS Guidance You Can Actually Use?


I regularly share clear, safety-focused insights to help aviation professionals implement the core elements of an ISMS under EASA Part-IS.


The focus is on aligning information security with existing safety and compliance systems, using real-world experience rather than theory.


Subscribe to the Aviation Cybersecurity Brief to receive these insights, along with my Free Part-IS Starter Checklist, designed to help you validate your approach and strengthen the foundations of your ISMS.


👉 Subscribe here to implement Part-IS with clarity.

Comments


bottom of page