The threat is real. The solution is proven.
CHARTER & FRACTIONAL AVIATION
The questions your auditors are
already preparing.
IS-BAO, ARGUS, EASA, and your insurers are asking questions that now require documented answers.
Verbal assurance is not an auditable answer.
The gap between taking cyber security seriously and demonstrating it, is almost always a documentation gap.
What your auditors will ask for. Every IS-BAO Stage Two assessment and every ARGUS visit now includes a structured review of your cyber security documentation. Auditors are asking for specific documents: a current cyber security policy that reflects your live operational infrastructure, data protection impact assessments for the high-risk processing activities your operation conducts, penetration test records with evidence of formal remediation, and a compliance calendar that demonstrates your team is actively managing the audit cycle rather than reacting to it.
What the regulatory trajectory means. Aviation is at the same point maritime was in 2019. The IMO cyber risk management framework had been advisory for years before the mandatory requirement arrived in January 2021. The operators without documentation faced flag state audits and class society surveys with no grace period. All of them spent significantly more resolving the gap under pressure than they would have spent building the posture in advance. The aviation parallel is not a prediction. It is a pattern already in motion.
CHARTER & FRACTIONAL
REGULATORY LANDSCAPE
CHARTER & FRACTIONAL
DOCUMENTATION GAP
CHARTER & FRACTIONAL
MARITIME PARALLEL
Trusted by industry leaders

What Is Coming and When
The aviation cyber mandate is not a future risk. It is an active obligation.
Your accountable manager has a copy of the IS-BAO Stage Two requirements on their desk. Your ARGUS auditor last visited fourteen months ago and the next visit is scheduled for the spring. Your insurance renewal is in six weeks and the underwriter's questionnaire this year includes seventeen questions about cyber readiness that were not on last year's form. Somewhere in your compliance director's inbox is an EASA advisory circular about cyber security in aviation operations that has been flagged for review since it arrived in February. None of these obligations have been addressed. All of them are live.
The regulatory environment around aviation cyber security has shifted from advisory to mandatory in a period of three years. IS-BAO, ARGUS, EASA, FAA, and the GCAA are all now asking questions that require documented answers. CyberPlus provides those answers and the documentation behind them.
IS-BAO and IS-BAH Cyber Requirements
The International Standard for Business Aircraft Operations now includes specific cyber security requirements at Stage Two and above. We assess your current compliance position against the IS-BAO cyber framework, identify the gaps between your current posture and the standard's requirements, and implement the controls and documentation that close those gaps before your next audit cycle.
ARGUS and Wyvern Audit Readiness
ARGUS GOLD and Platinum ratings and the Wyvern WINGMAN and PASS programmes are the safety credentials your clients and brokers use to verify your operation. Both programmes are increasing their cyber security scrutiny in response to industry-wide incidents. We ensure your operation can answer every cyber-related question your auditor asks with documented evidence rather than verbal assurance.
EASA and National Aviation Authority Obligations
EASA's evolving framework for cyber security in aviation operations, and the national authority obligations derived from it across your operating jurisdictions, create a compliance requirement that most charter operators have not yet translated into documented controls. We map your obligations across every jurisdiction in which you hold an approval, identify the documentation requirements that apply, and implement the compliance framework that satisfies each authority.
Insurance Cyber Questionnaire Preparation
Aviation insurers are increasingly making cyber security posture a material factor in both premium calculation and coverage terms. An operation that cannot demonstrate adequate cyber controls faces premium increases, coverage restrictions, or both. We prepare your operation to answer the insurers' cyber questionnaires with documented evidence of your controls so that your renewal conversation is a commercial one rather than a remediation one.
What Your Auditors Will Ask For
If it isn’t documented, did it really happen?
Your IS-BAO auditor arrives on a Tuesday morning and asks to see your cyber security policy. Your compliance director produces a document that was last reviewed in 2021. The auditor asks whether it covers your current scheduling platforms and crew applications. It does not. The auditor asks for your data protection impact assessment for high-risk processing activities. It has never been produced. The auditor asks for the record of your last penetration test. It happened eighteen months ago and the findings were never formally remediated. The audit does not go well. The renewal conversation with your insurer, which takes place three weeks later, goes worse.
The gap between an operator who takes cyber security seriously and an operator who can demonstrate it to an auditor's satisfaction is almost always a documentation gap. CyberPlus closes it systematically and keeps it closed.
Cyber Security Policy Development and Maintenance
A cyber security policy that reflects your current operational infrastructure, your current regulatory obligations, and your current threat environment is the foundation of every audit conversation. We develop and maintain your cyber security policy as a live document that is updated when your infrastructure changes, when regulatory requirements evolve, and when your threat environment shifts, so that it is current when your auditor asks for it.
Data Protection Impact Assessments
GDPR and its national equivalents require documented data protection impact assessments for high-risk processing activities. Passenger data in a charter operation qualifies. We produce and maintain the DPIAs that your regulatory obligations require, in a form that satisfies both data protection authorities and aviation safety regulators, so that the question is answered before it is asked.
Penetration Testing and Remediation Records
Regular penetration testing of your operational infrastructure is increasingly required by IS-BAO, ARGUS, and aviation insurers. The test itself is not sufficient. The documented remediation of findings is what auditors and insurers look for. We manage the penetration testing cycle and produce the remediation documentation that demonstrates your organisation's response to findings, not just the findings themselves.
Compliance Calendar and Audit Preparation
The audit calendar for a charter operator holding IS-BAO, ARGUS, and national aviation authority approvals simultaneously is a continuous cycle rather than a series of discrete events. We maintain your compliance calendar, track the documentation requirements for each audit cycle, and ensure that every piece of evidence your auditors will request exists, is current, and is retrievable in the time your auditor allows.
What Maritime Learned and Aviation Is Learning Now
The operators who moved early will not remember the mandate. The ones who did not will not forget it.
In January 2021, the International Maritime Organization's cyber risk management requirements became mandatory for all vessels subject to the ISM Code. Operators who had treated the advisory period as a grace period found themselves facing flag state audits, port state control inspections, and class society surveys for which their documentation was inadequate. Some lost their certificates of compliance. Most faced significant remediation costs under time pressure. The operators who had built their cyber posture into their safety management systems before the deadline faced the same audits with complete documentation and no surprises.
Aviation is at the same point maritime was in 2019. The frameworks are advisory and the enforcement is inconsistent. The operators who are moving now are building a compliance posture that will meet the mandatory requirements when they arrive, improving their insurance position in the interim, and differentiating themselves to the brokers and principals who are already asking the questions. The operators who are waiting are accumulating a debt that will become significantly more expensive to repay under pressure.
Positioning
Early Adoption Positioning
Charter and fractional operators who build documented cyber security postures now, ahead of mandatory enforcement, will hold a demonstrable competitive advantage when their peers begin the same process under regulatory pressure. We position your operation as a cyber-ready operator in the documentation and representations your brokers, insurers, and principals receive from you.
Commercial
Broker and Principal Communication
The brokers and advisors who recommend charter operators to UHNW principals are beginning to ask cyber security questions as part of their due diligence process. An operator who can provide documented evidence of their cyber posture in response to those questions wins the relationship. One who cannot is beginning to lose it without knowing why. We develop the cyber security summary documentation that positions your operation correctly in every broker and principal conversation.
Financial
Insurance Premium Optimisation
Aviation insurers are pricing cyber risk into premiums for operators who cannot demonstrate adequate controls and beginning to offer preferential terms to operators who can. The return on a documented cyber security posture is not just risk reduction. It is a measurable reduction in the cost of the insurance programme that funds the cyber security investment. We work with your brokers to ensure your compliance posture is accurately represented in your insurance placement.
Ongoing
Regulatory Monitoring
The aviation cyber regulatory environment is changing continuously across EASA, FAA, GCAA, and the national authorities relevant to your operating jurisdictions. We monitor the regulatory environment on your behalf, identify the changes that affect your compliance obligations, and update your documentation and controls before the new requirements take effect rather than after.
A discreet
conversation.
This compliance gap audit is a structured review of your current position against IS-BAO, ARGUS, EASA, and your insurers' requirements: the documentation that exists, and the operational gaps that would be exposed if an auditor arrived tomorrow. Strictly confidential, with all findings entirely yours to keep. No marketing follow-up. No automated sequences. No obligation beyond the hour.
The advisory window is still open. The operators using it now will not remember it closing. The ones who are not will not forget it.SEND US A MESSAGE
We don’t share your details. We don’t do follow-up campaigns.