
AVIATION CYBERSECURITY & EASA PART-IS
Legal advice on EASA Part-IS, NIS2 and information security governance for airlines.
I help airlines and aviation organisations translate regulatory requirements into clear responsibilities, workable procedures and coordinated incident response. My approach combines Czech and EU legal analysis with practical experience in airline cybersecurity governance.
01 - EASA Part-IS: Scope & Aviation Safety
Part-IS addresses information security risks with a potential impact on aviation safety. The relevant assessment therefore needs to consider safety consequences, not only commercial loss or the protection of personal data.
I assess which requirements apply to your organisation, taking account of its activities, approvals and regulatory status. Working with your information security and safety specialists, I help identify the relevant processes, systems and organisational interfaces.
The starting point is the airline's actual operating environment. The objective is to establish a legally sound scope and identify the measures and documentation requiring attention.
02 - Information Security Governance & ISMS
I help translate regulatory obligations into a workable information security management system, or ISMS. My support focuses on responsibilities, decision-making, documentation and the evidence needed to demonstrate implementation.
Roles & Accountability
I help define management responsibilities, reporting lines and escalation procedures, including the relationship between legal, information security, safety and compliance functions.
Risk Assessment & Documentation
Working with your technical and safety specialists, I review risk-assessment procedures, information security policies and management documentation against the applicable legal requirements.
Implementation & Oversight
I support the documentation of controls, change-management decisions and corrective measures. I also assist with regulatory enquiries and the legal aspects of audit findings.
03 - NIS2 & Czech Cybersecurity Requirements
Part-IS and NIS2 have different scopes. Compliance with one does not automatically establish compliance with the other.
I advise on Czech cybersecurity requirements implementing NIS2 and their interaction with aviation-specific obligations. This includes assessing regulatory status, management responsibilities and the requirements relevant to the agreed scope.
I compare existing policies and controls to identify what can be reused and what requires additional work. An ISO/IEC 27001-based ISMS may provide a foundation, but certification alone does not demonstrate Part-IS compliance.
04 - Incident Response & Regulatory Reporting
I support the legal side of incident preparation and response, working alongside your technical responders and operational decision-makers. The scope can include incident procedures, escalation arrangements and legal support during an actual event.
Reporting Assessment
I assess whether an event triggers aviation, cybersecurity or personal-data breach reporting. I identify the relevant recipients and deadlines and help coordinate the required submissions.
Legal Coordination & Evidence
I advise on internal escalation, evidence preservation, communications and contractual notifications. The aim is to maintain a consistent factual record while the technical team investigates and contains the incident.
Regulatory Follow-Up
I assist with follow-up reports, responses to authority requests and corrective-action documentation. Where an incident leads to regulatory proceedings, I advise on the organisation's legal position and response.
05 - Supplier Risk, Business Continuity & Recovery
I review cybersecurity provisions in agreements with technology providers, cloud services and operational partners. Key issues include security responsibilities, incident-notification timing, access to relevant evidence, subcontracting and continuity arrangements.
I also support the legal and governance aspects of business impact analysis, continuity and recovery planning. I review how internal plans and supplier commitments address recovery priorities, decision-making responsibilities and escalation procedures.
The objective is to identify gaps between what the airline expects, what its contracts require and what its operational arrangements support.
06 - Airline Experience & External Legal Support
My experience includes senior-level involvement in airline cybersecurity governance, information security management, business impact analysis, continuity and recovery planning, and incident-management processes. My work in the sector includes data protection and cybersecurity governance at Smartwings and Czech Airlines.
I work alongside your in-house legal, information security and compliance teams. Where you prefer outsourced legal support, I can assemble and lead a dedicated external legal team, coordinating with technical specialists while remaining your primary point of contact.
The scope, responsibilities and reporting arrangements are agreed at the outset, whether you need a focused compliance review, support with a specific incident or ongoing legal advice.
