Key takeaways
- In aviation, ransomware is a safety and airworthiness problem before it is an IT problem: if the maintenance records are encrypted, the aircraft may not be dispatchable, and if they are silently altered, it may not be airworthy.
- Four preparations do most of the work: backups you have restored, multi-factor authentication, a written "manual mode" for flight and maintenance operations, and a contact list that is not stored on the systems that just went down.
- Decide in advance who can isolate systems, who talks to whom, and who decides about a ransom demand. Those decisions are slow and wrong at 3 a.m.
- Reporting obligations differ by regime: EASA Part-IS, national occurrence reporting, privacy law and your insurer all have clocks. Know them before the clock starts.
- A tabletop exercise costs ninety minutes and finds the gaps a policy never will.
What ransomware does to an aviation business
Generic advice treats ransomware as data loss. In aviation the damage is more specific. Ground handler Swissport reported a ransomware attack in February 2022 that delayed flights. Jeppesen, whose flight-planning and NOTAM services are used by operators worldwide, reported a cyber incident in November 2022 that disrupted those services. Boeing confirmed in November 2023 that a criminal group had stolen data from its parts and distribution business and published it when no ransom was paid. None of these organizations is small, and all of them had security teams. The lesson for a company that does not is not that attacks are unstoppable but that recovery is what separates a bad week from a bad year.
For a small operator or MRO, three kinds of system matter most:
- Maintenance records and the technical log. If they are unavailable, aircraft may not be dispatchable. If they have been altered, the airworthiness of the aircraft is in question until every entry is verified, which can take longer than the outage.
- Flight operations systems: scheduling, dispatch, crew records, weight and balance, EFB content servers. Loss stops flying; corruption can be worse than loss.
- The business: email, invoicing, customer data, parts inventory. Loss costs money and reputation, and privacy law may require notifications.
Plan the recovery order in that sequence: what keeps aircraft safe first, what keeps them flying second, what keeps the business running third.
The preparations that matter
1. Backups you have actually restored
Keep three copies of critical data, on two kinds of media, with one copy offline or immutable so that the credentials an attacker steals cannot delete it. Then restore something from the offline copy once a quarter and time it. A backup that has never been restored is a hope, not a control. For maintenance records, keep the restore point short: a week of lost entries is a week of aircraft on the ground while paper is reconciled.
2. Multi-factor authentication and patched endpoints
Most ransomware enters through a stolen password, a phishing email or an unpatched remote-access service. MFA on every email, cloud and remote-access account, endpoint protection on every laptop, and a patching rhythm you can name close the doors that criminals use.
3. A written "manual mode"
Decide now how you would release an aircraft, plan a flight and record maintenance if the systems were unavailable for a week: which paper forms, which spreadsheets kept offline, who signs. Regulators accept manual processes; they do not accept improvisation without records. Print the forms and keep them where the incident will find them.
4. A contact list that survives the incident
Your IT provider, insurer, lawyer, national cyber authority, aviation authority contact, key customers and your own staff's personal phone numbers, on paper and on a phone that does not depend on the company network. If the list lives only in the encrypted mailbox, it does not exist.
5. Segmentation and least privilege
Separate the maintenance and operations systems from general office use, remove administrator rights from daily accounts, and keep vendors' remote access limited and logged. Ransomware spreads along the paths you leave open.
6. Malware basics that still matter
Reputable endpoint protection kept current; software installed only from official sources; digital signatures and file hashes checked on tools that touch aircraft data loaders; USB devices controlled in the hangar; mobile devices managed, since crews' tablets are part of the operation. None of this is novel, and all of it is on the path of the last several aviation incidents.
The incident response plan on one page
A small organization needs a plan people will read during the incident, which means one page. This is the structure I use; fill it in with your names and numbers.
| Section | Content |
|---|---|
| Roles | Incident lead (decides), technical lead (contains and recovers), communications lead (staff, customers, regulator, media), records keeper (timeline and evidence). Names, deputies, phone numbers. |
| Severity | Three levels: nuisance (one device, no spread), serious (a business system down), critical (safety-related systems, aircraft records or customer data affected). Who gets called at each level. |
| First hour | Isolate affected devices (unplug, don't power off); preserve evidence; change passwords on critical accounts from a clean device; open the timeline; call the IT provider and the insurer; decide whether aircraft can be released under manual mode. |
| Decisions reserved for the incident lead | Shutting down shared systems; notifying regulators and customers; engaging with any ransom demand (the default answer is no, and the insurer and lawyer are consulted first); public statements. |
| Recovery order | 1. Systems needed to establish airworthiness and release aircraft. 2. Systems needed to plan and operate flights. 3. Everything else. Rebuild from clean images; restore data from the offline copy; verify records before trusting them. |
| Reporting | The list of who must be told, by when (see below), with the wording pre-drafted. |
| After | A review within two weeks: what happened, what worked, what to change. Update the plan and the risk register. |
Reporting obligations to know in advance
The obligations depend on where you are and what approvals you hold, and they have deadlines that start when you become aware of the incident, not when you have finished dealing with it.
- EASA-approved organizations (operators, Part-145, CAMO, design and production organizations) fall under Part-IS, which requires reporting of information security incidents with a potential impact on aviation safety to the competent authority, alongside existing occurrence reporting.
- Occurrence reporting in your national system applies whenever the incident affected, or could have affected, the safety of an aircraft, regardless of cyber-specific rules.
- Privacy law (PIPEDA in Canada, GDPR in the EU and UK, state laws in the US) requires notifying regulators and affected individuals when personal data is compromised, generally with short deadlines.
- Your insurer will have a notification clause; late notice can void cover. Your customers may have contractual notification clauses too.
- National cyber authorities (the Canadian Centre for Cyber Security, CISA in the US, national CSIRTs in Europe) accept and encourage reports, and can help.
Write the list for your organization, with the contact details and the time limits, and put it in the plan.
A 90-minute tabletop exercise
Gather the people in the plan, a facilitator who is not one of them, and a whiteboard. Read each stage aloud, give the team ten minutes to decide what they would do, and write down every gap. This scenario is written for a small operator; adapt the systems to yours.
- 06:10 Monday. The duty engineer cannot open the maintenance-tracking system. A text file on the desktop says the data is encrypted and gives a contact address. Two aircraft are due out at 08:00. What happens in the first fifteen minutes? Who is called? Can the 08:00 flights go?
- 06:40. The office file server and the shared mailbox are also unavailable. The IT provider's number is in the mailbox. Who has the contact list? How do you reach staff?
- 08:30. The IT provider reports the most recent backup that was not connected to the network is nine days old. What does nine days of missing maintenance entries mean for the fleet? How do you reconstruct them?
- 11:00. A customer calls asking whether their data is affected. A journalist emails. Who answers, and with what words?
- 14:00. The insurer says do not engage with the attackers; the attackers post a sample of your files online. Which regulators and individuals must now be notified, and by when?
- Day 3. Systems are rebuilt from clean images. How do you verify that restored maintenance records are complete and unaltered before releasing aircraft on them?
- Day 14. The review. What three changes would have made this a bad day instead of a bad fortnight?
Most teams find at least one gap in the first stage, usually the contact list or the manual-mode forms. That is the point of the exercise.
Questions I get asked
What should a small operator do in the first hour of a ransomware incident?
Isolate the affected systems, switch flight and maintenance operations to the written manual mode, call the people on the offline contact list, and start a log of what was done and when. Decisions about ransom, disclosure and restoration come after the situation is contained.
Should we pay the ransom?
Decide the policy before an incident, with your insurer and lawyer, and write it into the plan. Payment does not guarantee recovery, may be unlawful depending on who the attacker is, and does nothing to restore trust in records that may have been altered. Tested backups make the question much smaller.
Who do we have to report a cyber incident to?
It depends on your approvals and jurisdiction: EASA Part-IS organizations have reporting duties, national occurrence-reporting rules may apply when safety is affected, privacy law has its own deadlines if personal data is involved, and your insurer has notification terms. List the obligations and their clocks in the plan before you need them.
How often should we run a tabletop exercise?
Once a year at minimum, and after any major change to systems or people. Ninety minutes with the decision-makers in the room finds the gaps a written plan never will.
How I can help
My incident response and ransomware readiness engagement delivers a one-page incident response plan written for your organization, playbooks for ransomware and data loss, and a tabletop exercise I run with your team, so the first time you use the plan isn't the real thing.
Ask about incident readinessReferences
- NIST SP 800-61 Rev. 3 (2025), Incident Response Recommendations and Considerations for Cybersecurity Risk Management.
- Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203 (EASA Part-IS); Regulation (EU) 376/2014 on occurrence reporting.
- RTCA DO-392 / EUROCAE ED-206, Guidance on Security Event Management.
- Canadian Centre for Cyber Security, Ransomware playbook (ITSM.00.099).
- Public company statements on the Swissport (February 2022), Jeppesen (November 2022) and Boeing (November 2023) incidents.