Safety is not an option, Part-IS - Ben Nagel

Ben Nagel

Disobey 2026 · Main Stage

Overview

Ben Nagel's talk, "Safety is not an option, Part-IS," delves into the critical and often overlooked intersection of information security and aviation safety, focusing specifically on the new European Union regulation, Part-IS (Part Information Security). Nagel, known as "Cyberben," guides the audience through the complexities of this regulation, which aims to prevent information security failures from escalating into catastrophic safety events within the aviation industry. The talk highlights the unique challenges faced by aviation organizations, from major manufacturers and airlines to smaller operators, in integrating cybersecurity practices into their deeply entrenched safety management systems.

Watch on YouTube

Visual summary for Safety is not an option, Part-IS - Ben Nagel by Ben Nagel
Visual summary for Safety is not an option, Part-IS - Ben Nagel by Ben Nagel

Key moments

  1. 0:00 Introduction: Futuristic scenario of grounded flights
  2. 2:00 Speaker's background and role as Part-IS auditor
  3. 4:00 What is Part-IS? Definition as a safety regulation
  4. 5:30 Information security failures leading to unacceptable safety impacts
  5. 6:30 Real-world incident: Airport luggage system outage
  6. 7:45 Real-world incident: Widespread GPS spoofing affecting aviation

Safety is not an option, Part-IS - Ben Nagel

Speakers: Ben Nagel, Independent Consultant

Conference: Disobey

YouTube: https://www.youtube.com/watch?v=bs66u1RO038

Overview

Ben Nagel's talk, "Safety is not an option, Part-IS," delves into the critical and often overlooked intersection of information security and aviation safety, focusing specifically on the new European Union regulation, Part-IS (Part Information Security). Nagel, known as "Cyberben," guides the audience through the complexities of this regulation, which aims to prevent information security failures from escalating into catastrophic safety events within the aviation industry. The talk highlights the unique challenges faced by aviation organizations, from major manufacturers and airlines to smaller operators, in integrating cybersecurity practices into their deeply entrenched safety management systems.

The core message underscores that for the aviation sector, information security is not merely a compliance checkbox but a fundamental component of operational safety. Nagel illustrates this by presenting a future scenario where flights are grounded due to a Part-IS non-compliance, emphasizing the real-world consequences of neglecting these new mandates. He breaks down the regulation's key elements, its global implications, and the rigorous auditing processes designed to ensure its effective implementation, ultimately aiming to maintain and enhance the resilience and trustworthiness of air travel.

This presentation is particularly significant as it sheds light on a relatively unknown but profoundly impactful regulation. Part-IS represents a pivotal shift, formally recognizing information security as a safety-critical discipline within aviation. Nagel's insights are crucial for anyone involved in aviation, cybersecurity, or regulatory compliance, offering a clear roadmap for understanding and navigating this complex landscape to safeguard the future of air travel.

Background

▶ Watch: Introduction: Futuristic scenario of grounded flights (0:00)

The aviation industry operates under a stringent regulatory framework primarily driven by safety. Historically, these regulations, such as Part 25 for large aircraft (e.g., Airbus A350, Boeing 737), Part 23 for smaller private aircraft, and Part 27 for helicopters, have focused on the physical integrity and operational safety of aircraft and associated systems. However, with increasing digitalization and interconnectedness, the potential for information security failures to directly impact safety has become a significant concern. This is the genesis of Part-IS (Part Information Security).

Part-IS is a new horizontal regulation introduced by the European Union Aviation Safety Agency (EASA). Unlike previous regulations that might have touched upon security as a separate domain, Part-IS explicitly defines information security as a safety regulation. This fundamental principle means that any information security failure that could lead to an "unacceptable safety" outcome, particularly a catastrophic hazardous event (defined as a crash, accident, or loss of human life/aircraft), falls under its purview. Nagel quotes his late friend John Paul Moreau, a key driver of Part-IS globally, emphasizing that "safety-related requirements in particular for catastrophic hazardous events continue to be applicable to prevent a single information security failure from leading to unacceptable safety."

The regulation builds upon established information security frameworks like ISO 27001, incorporating many of its elements but with a crucial "safety twist." While ISO 27001 focuses on protecting information assets, Part-IS prioritizes the protection of systems and data whose compromise could directly lead to physical harm or loss of life. This distinction is vital, as it shifts the focus from purely data confidentiality, integrity, and availability to the direct safety impact of these attributes. Furthermore, Part-IS interacts with other regulatory landscapes, such as NIS 2 (Network and Information Security Directive 2) and FSec (physical aviation security), creating a complex compliance environment, particularly for operators who may need to adhere to multiple frameworks. The industry's existing Safety Management Systems (SMS) and Quality Management Systems (QMS), which have long driven continuous improvement based on lessons learned from events, are now expected to integrate information security as a new, critical domain.

Key Findings

▶ Watch: What is Part-IS? Definition as a safety regulation (4:00)

The talk meticulously outlines the key elements of Part-IS, drawing parallels with ISO 27001 but always emphasizing the aviation safety context:

  1. Responsibilities: Approved organizations within Europe, certified by EASA or national authorities, must clearly define information security responsibilities. A specific "Part-IS common responsible person" is required, akin to a CISO, to take accountability for information security within the organization, with clear delegation structures. This is particularly challenging for smaller organizations that may lack dedicated resources.
  1. Policies and Procedures: Comprehensive documentation is mandatory. This includes developing an Information Security Management Manual (ISMM), incident response plans, and robust risk management planning. The emphasis is on formalizing all information security activities to ensure consistency and accountability.
  1. Inventory of Safety-Critical Assets: A crucial divergence from standard information security practices is the requirement to identify and inventory assets that, if compromised, could have a direct safety impact. This extends beyond the aircraft itself (which is certified under regulations like AMC 20-42) to include ground systems and suppliers whose functions are integral to flight safety. An example cited is the luggage management system that calculates aircraft weight and balance. A malicious alteration to this system could lead to incorrect takeoff calculations, potentially causing an accident. The challenge lies in scoping correctly, especially for suppliers or training organizations whose impact on safety might be indirect.
  1. Risk Register and Assessment: Organizations must conduct thorough risk assessments, linking information security threats directly to potential safety failures using methodologies like the bow-tie diagram. This approach helps visualize how information security vulnerabilities could lead to system failures and ultimately, aviation safety incidents. The focus is on understanding the impact of a threat on the safety of the system or aircraft.
  1. Incident Response and Reporting: Part-IS mandates specific procedures for communicating and reporting information security incidents. Organizations must report to relevant authorities within defined timeframes (e.g., 24/72 hours for initial notifications, with longer periods for full remediation). This ensures timely awareness and coordinated response across the industry, although the speaker notes that three months is often too quick for certified system changes.
  1. Safety Management and Planning Integration: Information security is not to be treated as a standalone function but must be integrated into existing safety and quality management systems. This requires bridging the traditional gap between safety (focused on unintentional events) and security (focused on intentional unauthorized electronic interaction and malicious attempts). Organizations need to establish clear communication channels between security and safety teams.
  1. Continuous Improvement: Mirroring the aviation industry's strong emphasis on learning from events, Part-IS requires a continuous improvement cycle for information security. This involves regularly reviewing and enhancing security measures based on incidents, audits, and evolving threat landscapes.

Applicability and Global Reach: Part-IS is not a distant future concept; its applicability dates have already begun. For manufacturers and Air Traffic Management (ATM)/Air Navigation Service Provider (ANSP) domains, initial compliance was required by October 16, 2025. For airlines and operators, the next critical deadline is February 22, 2026, for having an ISMM and risk register present. While originating in the EU under EASA, Part-IS extends beyond. Organizations certified in Europe but operating elsewhere (e.g., airlines from the Middle East or US) must comply. The UK, post-Brexit, is developing its own rule to adopt similar principles, and seeds have been planted at the ICAO (International Civil Aviation Organization) level, indicating a potential global harmonization that could eventually impact entities like the FAA in the US.

Technical Deep Dive

▶ Watch: Information security failures leading to unacceptable safety impacts (5:30)

The technical underpinnings of Part-IS represent a significant evolution in aviation regulation. While it leverages the structural familiarity of ISO 27001, its application is fundamentally reoriented by the imperative of aviation safety. This means the scope of information security management is tightly coupled to potential catastrophic outcomes, rather than just data breaches or system downtime.

One of the most technically challenging aspects is the precise scoping of safety-critical assets. Unlike a typical enterprise environment where all IT systems might be in scope, Part-IS demands a rigorous identification process focusing on systems whose compromise could directly or indirectly lead to a safety incident. This includes:

  • Ground Systems: Any system used on the ground that generates or processes data critical for flight operations. An example given is the calculation of weight and balance for an aircraft. If the ground system providing this data is compromised, leading to incorrect load calculations, the aircraft's takeoff performance could be severely impacted, potentially causing an accident.
  • Satellite Data Units (SDUs): The talk references a simulator scenario where a "cyber threat" message in the cockpit prompts a pilot to "turn off and on the SDU." This highlights how on-board systems, even those with simple troubleshooting steps, can be targets or indicators of security issues. The SDU manages satellite communications, crucial for navigation and other critical functions.
  • Navigation Systems: The widespread GPS spoofing incidents in areas like the Middle East and around Talin demonstrate how external information security threats directly impact navigational integrity, forcing pilots to rely on alternative procedures. This is a real-time, daily operational challenge directly tied to safety.

The regulation requires a sophisticated risk assessment methodology that explicitly links information security threats to aviation safety failures. This often involves a "bow-tie" diagram approach, where information security vulnerabilities and threats are analyzed for their potential to trigger system malfunctions or operational errors that lead to safety incidents. The definition of a security incident under Part-IS is distinct: "intentional unauthorized electronic interaction," which contrasts with the traditional safety domain's focus on unintentional events. This necessitates a cultural and procedural shift, as safety teams accustomed to analyzing human error or mechanical failure must now integrate the concept of malicious intent.

Integration with existing Safety Management Systems (SMS) and Quality Management Systems (QMS) is central. Aviation has mature processes for managing safety and quality, including incident reporting, root cause analysis, and continuous improvement loops. Part-IS mandates embedding information security into these established frameworks. This requires:

  • Communication Bridges: Establishing effective communication channels between cybersecurity professionals and safety engineers, ensuring that security threats are understood in the context of their potential safety impact.
  • Process Adaptation: Modifying existing safety processes to include information security risk identification, mitigation, and incident response.
  • Training and Awareness: Educating personnel across all levels about the safety implications of information security.

The auditing process itself is technically demanding. Auditors must possess a blend of ISO 27001 experience, general auditing skills, in-depth knowledge of Part-IS, and a deep understanding of aviation safety principles. They must evaluate not just the existence of policies but their suitability and effectiveness in safeguarding safety-critical functions. The speaker mentions that the initial phase (until Feb 22, 2026) focuses on the presence of an ISMM and risk register, while subsequent phases will assess their operational effectiveness and maturity. This staged approach acknowledges the complexity and investment required for organizations to fully comply.

Demo / Proof of Concept

▶ Watch: Real-world incident: Airport luggage system outage (6:30)

While Ben Nagel's talk did not feature a live, interactive technical demonstration of an attack or defense, he provided compelling examples and referenced a specific simulator-based proof of concept from a university. This involved simulating a cyber security attack on an aircraft, with the results being displayed in the cockpit.

Nagel described a scenario where a "cyber threat" message appeared in the cockpit, accompanied by a checklist item instructing the pilot to "turn off and on the SDU." The SDU (Satellite Data Unit) is a critical component responsible for satellite communications on an aircraft. Nagel recounted his personal experience with this simulator exercise, finding it "funny when you're like trying to fly in the plane and at the same time trying to like kind of find the fuse or the right system to turn off and on." He noted that during the exercise, he inadvertently flew to the side while attempting to locate the control.

This "demo" highlights several critical points:

  • Real-world Impact: It visualizes how a cyber attack could manifest in the cockpit, presenting pilots with unfamiliar, safety-critical challenges.
  • Human Factors: Nagel's personal anecdote underscores the significant human factors challenge. Presenting a "cyber threat" message directly to a pilot could induce panic or distract from primary flight duties. He suggests that it should ideally be presented as a standard checklist item ("turn off and on the system") rather than explicitly labeling it as a "cyber threat" to avoid undue stress or misinterpretation.
  • Operational Procedures: The need for specific, clear operational procedures for pilots to follow in the event of a cyber-induced system malfunction is evident. These procedures must be integrated into existing flight manuals and training.
  • System Resiliency: The ability to "turn off and on" a system like an SDU suggests a design intended for recovery from certain types of failures, which could include cyber-related incidents. However, the ease and safety of performing such actions during flight are paramount.

Beyond this simulated attack, Nagel also referenced the ongoing GPS spoofing incidents observed in areas like the Middle East and around Talin. He presented a screenshot illustrating how aircraft are being "positioned in a different place on the map" due to spoofing. This is a daily "proof of concept" of information security impacting aviation safety, forcing pilots to adapt and rely on other navigation methods. This demonstrates that the threats Part-IS aims to mitigate are not theoretical but are active and pervasive in the operational environment.

Defensive Implications

▶ Watch: Real-world incident: Widespread GPS spoofing affecting aviation (7:45)

The introduction of Part-IS fundamentally reshapes the defensive posture required across the entire aviation ecosystem. Organizations must move beyond traditional IT security and integrate information security into their core safety management frameworks. Here are the key defensive implications:

  1. Establish a Safety-Centric ISMS: Organizations must develop or adapt an Information Security Management System (ISMS) that explicitly aligns with Part-IS requirements. This ISMS must prioritize safety impacts, with all policies and procedures geared towards preventing information security failures from leading to catastrophic events. It’s not just about securing data, but securing operations that ensure human life.
  1. Appoint a "Common Responsible Person": A dedicated individual or role, often termed the Part-IS common responsible person, must be designated to oversee information security with a clear mandate and accountability. This person is responsible for ensuring compliance, managing risks, and integrating security into the organization's broader safety culture. For smaller organizations, this might involve shared resources or external consultants.
  1. Comprehensive Asset Inventory and Scoping: A rigorous process is needed to identify all safety-critical assets, including ground systems (e.g., weight and balance calculation systems, air traffic control systems), operational technology (OT), and IT systems that directly or indirectly influence flight safety. This requires deep collaboration between IT, OT, and safety engineering teams to accurately scope the environment and understand potential attack vectors. Suppliers also fall under this, requiring robust supply chain security management.
  1. Integrated Risk Management: Defensive strategies must be built upon a robust, integrated risk management framework. This involves:
  • Bow-tie Analysis: Using methodologies like bow-tie diagrams to clearly link information security threats (e.g., malware, insider threat, spoofing) to potential system failures and their ultimate safety consequences (e.g., loss of control, mid-air collision).
  • Threat Intelligence: Continuously monitoring for aviation-specific cyber threats, including GPS spoofing, supply chain attacks, and vulnerabilities in critical aviation systems (AMC 20-42 for aircraft development).
  • Proactive Mitigation: Implementing controls (technical, administrative, physical) that specifically address identified safety-critical risks, moving beyond generic cybersecurity controls.
  1. Robust Incident Response and Reporting: Organizations must develop and regularly test incident response plans tailored to aviation safety impacts. This includes:
  • Clear Communication Protocols: Establishing rapid communication channels with EASA or national authorities (like Traficom in Finland) within specified timeframes (e.g., 24/72 hours for initial reports).
  • Cross-Functional Teams: Forming incident response teams that include cybersecurity, operations, and safety personnel to effectively assess and manage incidents with potential safety implications.
  • Post-Incident Learning: Integrating lessons learned from information security incidents into the continuous improvement cycles of both security and safety management systems.
  1. Continuous Improvement and Maturity: Part-IS mandates a journey of continuous improvement. Organizations should aim to mature their information security posture beyond initial compliance, regularly auditing their ISMS, refining processes, and investing in training and technology. The auditing process itself is designed to drive this maturity, with external auditors providing feedback to authorities.
  1. Addressing Regulatory Overlap: Organizations, especially operators, need to navigate the complexities of complying with Part-IS alongside other regulations like NIS 2 and FSec. This requires a strategic approach to documentation and control implementation to avoid duplication and ensure consistency across frameworks.
  1. Auditor Engagement: Understanding the audit process is critical. Organizations will be audited by qualified entities (currently only three accredited across Europe, with nine auditors) or internal EASA auditors. These auditors will review the ISMM, risk registers, and conduct on-site interviews to challenge the organization's understanding and implementation. Defensive efforts should anticipate this scrutiny, ensuring documentation is not only present but suitable and reflective of operational realities. A Level 1 finding in an audit can lead to grounding aircraft or halting development, underscoring the severity of non-compliance.

In essence, Part-IS demands a holistic, safety-first approach to information security, moving it from a supporting IT function to an integral part of aviation's core mission: ensuring safe flight.

Key Takeaways

  • Part-IS is a Safety Regulation: Information security is no longer an optional add-on but a fundamental safety requirement in aviation, designed to prevent cyber failures from causing catastrophic accidents.
  • Focus on Safety-Critical Assets: Organizations must identify and protect ground systems, operational technology, and data that directly impact flight safety, such as weight and balance calculation systems, rather than just general IT infrastructure.
  • Integration with Existing Safety Systems: Information security must be seamlessly woven into established aviation Safety Management Systems (SMS) and Quality Management Systems (QMS), requiring cross-functional collaboration and a shift in mindset from unintentional to intentional threats.
  • Comprehensive Risk Management: A rigorous risk assessment process, often using bow-tie diagrams, is essential to link information security threats directly to potential aviation safety impacts and implement targeted mitigations.
  • Global Applicability and Staged Compliance: Part-IS, while originating in EASA, has global implications (e.g., ICAO, UK, US) and phased compliance deadlines, with initial requirements for documentation (ISMM) by February 2026 for airlines and operators.
  • Rigorous Auditing and Accountability: Compliance is enforced through audits by qualified entities and EASA, emphasizing the need for clear responsibilities (e.g., Part-IS common responsible person) and a demonstrable, mature information security posture.

About the Speaker(s)

Ben Nagel, also known as "Cyberben," is an independent consultant and a prominent voice in aviation cybersecurity. With a self-proclaimed title of "cyber safety ninja," Nagel is deeply involved in the standardization of cybersecurity practices within the aviation industry. He is a board member of a STICKER committee (as visibly represented by numerous stickers on his laptop and in his presentation) and actively works on engineering solutions for aviation and cyber security.

Nagel has a strong background in securing aircraft and products, having previously spoken at conferences three years prior on these topics. He travels extensively, both training and being trained, accumulating significant flight time. More recently, he has taken on a professional role as an officially certified Part-IS auditor, which requires him to maintain independence, adhere to checklists, and operate with a higher degree of formality ("proper pants, not shorts and flip-flops"). His work embodies the spirit of "disobeying" in challenging norms while simultaneously "obeying" the structured requirements of standardization and auditing within a critical industry.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Nagel delivers a competent regulatory briefing on Part-IS that will genuinely inform aviation-adjacent practitioners who haven't tracked EASA's cybersecurity mandates. The talk is honest about scope, timelines, and organizational pain points, but it stays in explainer territory — there's no novel research, no original threat modeling, and the 'demo' is a secondhand simulator anecdote.

Heather Calloway (CISO) — SOLID

Nagel delivers a competent walkthrough of a consequential but poorly understood regulation, and the governance framing — IS as a safety discipline, not a compliance checkbox — is the right one. The talk earns its place, but it's fundamentally an orientation briefing, not an analysis that changes how security leaders operate.

→ Top-rated talks at Disobey 2026

All talks from Disobey 2026