Skip to main content
CHARTER & FRACTIONAL

REGULATORY LANDSCAPE

IS-BAO, ARGUS, EASA, and your insurers are all asking questions that now require documented answers.
CHARTER & FRACTIONAL REGULATORY LANDSCAPE
CHARTER & FRACTIONAL

DOCUMENTATION GAP

A structured review of your cyber security policy, DPIA records, penetration test history, and compliance calendar.
CHARTER & FRACTIONAL DOCUMENTATION GAP
CHARTER & FRACTIONAL

MARITIME PARALLEL

The IMO 2021 parallel and what it means for aviation operators still in the advisory window.
CHARTER & FRACTIONAL MARITIME PARALLEL

Trusted by industry leaders

TeamViewer logo RealWear logo RINA logo Fortinet logo ZeroFox logo

What Is Coming and When

The aviation cyber mandate is not a future risk. It is an active obligation.

Your accountable manager has a copy of the IS-BAO Stage Two requirements on their desk. Your ARGUS auditor last visited fourteen months ago and the next visit is scheduled for the spring. Your insurance renewal is in six weeks and the underwriter's questionnaire this year includes seventeen questions about cyber readiness that were not on last year's form. Somewhere in your compliance director's inbox is an EASA advisory circular about cyber security in aviation operations that has been flagged for review since it arrived in February. None of these obligations have been addressed. All of them are live.

The regulatory environment around aviation cyber security has shifted from advisory to mandatory in a period of three years. IS-BAO, ARGUS, EASA, FAA, and the GCAA are all now asking questions that require documented answers. CyberPlus provides those answers and the documentation behind them.


IS-BAO and IS-BAH Cyber Requirements

The International Standard for Business Aircraft Operations now includes specific cyber security requirements at Stage Two and above. We assess your current compliance position against the IS-BAO cyber framework, identify the gaps between your current posture and the standard's requirements, and implement the controls and documentation that close those gaps before your next audit cycle.

ARGUS and Wyvern Audit Readiness

ARGUS GOLD and Platinum ratings and the Wyvern WINGMAN and PASS programmes are the safety credentials your clients and brokers use to verify your operation. Both programmes are increasing their cyber security scrutiny in response to industry-wide incidents. We ensure your operation can answer every cyber-related question your auditor asks with documented evidence rather than verbal assurance.

EASA and National Aviation Authority Obligations

EASA's evolving framework for cyber security in aviation operations, and the national authority obligations derived from it across your operating jurisdictions, create a compliance requirement that most charter operators have not yet translated into documented controls. We map your obligations across every jurisdiction in which you hold an approval, identify the documentation requirements that apply, and implement the compliance framework that satisfies each authority.

Insurance Cyber Questionnaire Preparation

Aviation insurers are increasingly making cyber security posture a material factor in both premium calculation and coverage terms. An operation that cannot demonstrate adequate cyber controls faces premium increases, coverage restrictions, or both. We prepare your operation to answer the insurers' cyber questionnaires with documented evidence of your controls so that your renewal conversation is a commercial one rather than a remediation one.

What Your Auditors Will Ask For

If it isn’t documented, did it really happen?

Your IS-BAO auditor arrives on a Tuesday morning and asks to see your cyber security policy. Your compliance director produces a document that was last reviewed in 2021. The auditor asks whether it covers your current scheduling platforms and crew applications. It does not. The auditor asks for your data protection impact assessment for high-risk processing activities. It has never been produced. The auditor asks for the record of your last penetration test. It happened eighteen months ago and the findings were never formally remediated. The audit does not go well. The renewal conversation with your insurer, which takes place three weeks later, goes worse.

The gap between an operator who takes cyber security seriously and an operator who can demonstrate it to an auditor's satisfaction is almost always a documentation gap. CyberPlus closes it systematically and keeps it closed.


Cyber Security Policy Development and Maintenance

A cyber security policy that reflects your current operational infrastructure, your current regulatory obligations, and your current threat environment is the foundation of every audit conversation. We develop and maintain your cyber security policy as a live document that is updated when your infrastructure changes, when regulatory requirements evolve, and when your threat environment shifts, so that it is current when your auditor asks for it.

Data Protection Impact Assessments

GDPR and its national equivalents require documented data protection impact assessments for high-risk processing activities. Passenger data in a charter operation qualifies. We produce and maintain the DPIAs that your regulatory obligations require, in a form that satisfies both data protection authorities and aviation safety regulators, so that the question is answered before it is asked.

Penetration Testing and Remediation Records

Regular penetration testing of your operational infrastructure is increasingly required by IS-BAO, ARGUS, and aviation insurers. The test itself is not sufficient. The documented remediation of findings is what auditors and insurers look for. We manage the penetration testing cycle and produce the remediation documentation that demonstrates your organisation's response to findings, not just the findings themselves.

Compliance Calendar and Audit Preparation

The audit calendar for a charter operator holding IS-BAO, ARGUS, and national aviation authority approvals simultaneously is a continuous cycle rather than a series of discrete events. We maintain your compliance calendar, track the documentation requirements for each audit cycle, and ensure that every piece of evidence your auditors will request exists, is current, and is retrievable in the time your auditor allows.

What Maritime Learned and Aviation Is Learning Now

The operators who moved early will not remember the mandate. The ones who did not will not forget it.

In January 2021, the International Maritime Organization's cyber risk management requirements became mandatory for all vessels subject to the ISM Code. Operators who had treated the advisory period as a grace period found themselves facing flag state audits, port state control inspections, and class society surveys for which their documentation was inadequate. Some lost their certificates of compliance. Most faced significant remediation costs under time pressure. The operators who had built their cyber posture into their safety management systems before the deadline faced the same audits with complete documentation and no surprises.

Aviation is at the same point maritime was in 2019. The frameworks are advisory and the enforcement is inconsistent. The operators who are moving now are building a compliance posture that will meet the mandatory requirements when they arrive, improving their insurance position in the interim, and differentiating themselves to the brokers and principals who are already asking the questions. The operators who are waiting are accumulating a debt that will become significantly more expensive to repay under pressure.


Positioning

Early Adoption Positioning

Charter and fractional operators who build documented cyber security postures now, ahead of mandatory enforcement, will hold a demonstrable competitive advantage when their peers begin the same process under regulatory pressure. We position your operation as a cyber-ready operator in the documentation and representations your brokers, insurers, and principals receive from you.

Commercial

Broker and Principal Communication

The brokers and advisors who recommend charter operators to UHNW principals are beginning to ask cyber security questions as part of their due diligence process. An operator who can provide documented evidence of their cyber posture in response to those questions wins the relationship. One who cannot is beginning to lose it without knowing why. We develop the cyber security summary documentation that positions your operation correctly in every broker and principal conversation.

Financial

Insurance Premium Optimisation

Aviation insurers are pricing cyber risk into premiums for operators who cannot demonstrate adequate controls and beginning to offer preferential terms to operators who can. The return on a documented cyber security posture is not just risk reduction. It is a measurable reduction in the cost of the insurance programme that funds the cyber security investment. We work with your brokers to ensure your compliance posture is accurately represented in your insurance placement.

Ongoing

Regulatory Monitoring

The aviation cyber regulatory environment is changing continuously across EASA, FAA, GCAA, and the national authorities relevant to your operating jurisdictions. We monitor the regulatory environment on your behalf, identify the changes that affect your compliance obligations, and update your documentation and controls before the new requirements take effect rather than after.

Compliance Gap Audit

A discreet
conversation.

This compliance gap audit is a structured review of your current position against IS-BAO, ARGUS, EASA, and your insurers' requirements: the documentation that exists, and the operational gaps that would be exposed if an auditor arrived tomorrow. Strictly confidential, with all findings entirely yours to keep. No marketing follow-up. No automated sequences. No obligation beyond the hour. The advisory window is still open. The operators using it now will not remember it closing. The ones who are not will not forget it.


Prefer to speak directly? +44 (0)20 4572 6250 Monday to Friday  ·  09:00 – 18:00

    The threat is real. The solution is proven.

    Let's Talk