Service · For everyone in the company

Security training for aviation staff

Most security training is a generic video that everyone clicks through. Aviation people respond to something else: examples from their own world, delivered by someone who understands it, in the time they actually have. These sessions are built for the roles in a small aviation company and measured with a phishing simulation before and after, so you can show an authority, an insurer or a customer that awareness improved rather than that a box was ticked.

Is this for you?

  • You need awareness training that satisfies EASA Part-IS, ISO/IEC 27001 or an insurer's requirement, and you want it to be worth the hour.
  • Your pilots, technicians and engineers switch off at generic security content.
  • You have had phishing or invoice-fraud attempts and want the whole company to recognize the next one.
  • You want a measurement, not just attendance.

What you get

  • Role-based sessions. Four tracks of 45 to 60 minutes, live over video or on site: flight crew (EFB, connectivity, GNSS and ADS-B awareness), maintenance and technicians (records integrity, portable devices, supplier tools), engineers (design data, source and update pipelines), and office and management (email, payments, social engineering). Recorded for later hires.
  • Phishing simulations. A baseline campaign before the sessions and a follow-up after, with realistic aviation-themed lures, run with your consent and without shaming anyone.
  • Before-and-after report. Click and report rates by group, what changed, and what to reinforce, in a form you can show an authority, an insurer or a customer.
  • Reference cards. One page per role with the five things that matter most, for the crew room and the workshop wall.
  • Annual refresh. Optional: a shorter session and a new simulation each year, with the trend.

How it runs

  • Week 1BaselineA short call to agree the roles and the scenarios, then the baseline phishing simulation.
  • Weeks 2–3SessionsDelivered by role, live, at times that fit rosters; each recorded.
  • Week 4Follow-up simulation and reportThe second campaign, the report, and reference cards.

What I need from you

A list of staff by role and email address, agreement from management on the simulation (I provide the wording to announce it), and 45 to 60 minutes per person.

Questions I get asked

Live or recorded?

Live, because the questions are where the learning happens, with the recording kept for people who join later.

Does this satisfy Part-IS or ISO/IEC 27001 awareness requirements?

Yes. Attendance is recorded, the content is documented, and the before-and-after report is the kind of evidence an auditor looks for.

How large a group?

Any size, but sessions work best under 25 people so that they stay a conversation.

Will staff be embarrassed by the phishing test?

No. Results are reported by group, not by name, the announcement makes clear that it is training, and the point of the second run is to show the group how far it has come.

Start with a 45-minute readiness call

Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.

Ask about training
Eugene Pik

Eugene Pik

Founder of Mevocopter Aerospace. M.Sc. in Aviation and Aerospace Sustainability with a specialization in Aviation Cybersecurity from Embry-Riddle; Ph.D. researcher in Data Science at the University of Essex; earlier career in computer support and network security. Full biography · Publications