Heights Consulting Group

Aviation and Aerospace

Aviation and aerospace organizations now carry cybersecurity obligations from several directions at once: TSA security program requirements, FAA airworthiness rules, defense supply chain mandates and export controls on technical data. They need security leadership that can hold all of it in one program and speak the sector's safety language while doing it.

Obligations

What applies in this sector

Descriptions are of the published requirements, not claims about outcomes.

How we establish which obligations apply
Regimes that commonly apply to Aviation and Aerospace organizations, NIST Cybersecurity Framework, CMMC and NIST SP 800-171, ISO/IEC 27001, all resolving into one governed security program.

Regimes in play

  • NIST CSF Voluntary framework
  • CMMC Contractual requirement
  • ISO 27001 Certifiable standard

One control base

Mapped once, evidenced once, and maintained between assessments.

The environment

What shapes security decisions here

For most of aviation's history, security meant fences and badges while safety meant engineering. That separation is gone. Regulators now treat network compromise as an airworthiness and operational concern, and the sector's obligations have grown accordingly: TSA has written cybersecurity requirements into the security programs of regulated airport and aircraft operators, and the FAA has made protection against intentional electronic interference part of certifying transport category aircraft and engines.

The supply chain carries a second set of obligations. An aerospace machine shop or avionics supplier feeding defense primes inherits federal safeguarding requirements and certification expectations through its contracts, and export-controlled technical data adds handling rules that most general-purpose security programs were never designed around.

The operators in between, MROs, FBOs, charter and fractional operators, flight schools and airports, feel the same pressure commercially: primes, carriers, insurers and customers asking for evidence of a governed program, in a sector where downtime is measured in grounded aircraft and missed slots.

Exposure

Risks that behave differently in this sector

Not a general threat list. These are the exposures that need a different response here than they would elsewhere.

  • Operational disruption on the ground

    Scheduling, dispatch, maintenance records, fueling and crew systems are where aviation actually stops. Ransomware in ground systems grounds operations without touching an aircraft.

  • Export-controlled data in ordinary systems

    ITAR and EAR technical data routinely lives in email, shared drives and CAD systems. A security incident becomes an export control question the moment controlled data may have been accessed.

  • Flow-down obligations with certification attached

    Defense aerospace work brings NIST SP 800-171 safeguarding duties and CMMC certification expectations through prime contracts, with eligibility for the work riding on the answer.

  • Safety-critical suppliers and connected aircraft

    Maintenance software, parts data and aircraft connectivity link commercial IT to airworthiness. The FAA's airworthiness cybersecurity rules exist precisely because that boundary stopped being theoretical.

Requirements

Regulatory and contractual pressure

General descriptions of published requirements. Which of them apply to a particular organization is the first question an engagement answers.

TSA cybersecurity requirements
Amendments to the security programs of TSA-regulated airport and aircraft operators requiring, among other measures, network segmentation, access control, continuous monitoring and patching discipline for critical cyber systems.
FAA airworthiness cybersecurity
Certification requirements for protecting transport category airplanes, engines and propellers against intentional unauthorized electronic interference, reaching design approval holders and their supply chains.
NIST SP 800-171 and CMMC
Safeguarding requirements for controlled unclassified information in defense aerospace work, with certification obligations arriving through prime contractors.
ITAR and EAR
Export controls on defense and dual-use technical data, including access restrictions by person and defined conditions, such as end-to-end encryption, under which data may be transmitted and stored.
AS9100 and customer flow-downs
Aerospace quality expectations and prime-imposed security requirements that function as contractual obligations, with audit rights over the supplier.

How we establish which obligations apply

What we hear

What leadership raises with us

  • A TSA amendment, prime flow-down or FAA expectation arrived, and nobody can say which systems are in scope.
  • Export-controlled technical data has spread across email and shared drives, and access does not follow the license.
  • A CMMC deadline is attached to work the company cannot afford to lose.
  • Ground operations depend on systems nobody has assessed, run by vendors nobody has reviewed.
  • Safety has a management system and an accountable executive. Security has neither.

What prompts an engagement

  • A prime made cybersecurity certification a condition of remaining in the supply chain.
  • TSA requirements or an FAA expectation now apply to your operation and evidence is due.
  • An export control review, voluntary disclosure or audit raised questions about technical data handling.
  • A ransomware event at a peer operator made grounded-fleet scenarios a board question.
  • Aircraft connectivity, new maintenance platforms or an ERP change is linking systems that were never designed to meet.

Alignment

Frameworks that apply here

NIST Cybersecurity Framework
Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
CMMC and NIST SP 800-171
Defense contractors and their supply chain, where flow-down clauses make this an eligibility issue rather than a compliance preference.
ISO/IEC 27001
Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.

FAQ

Questions from aviation and Aerospace leaders

General questions about the vCISO role are answered on the vCISO page.

Do TSA cybersecurity requirements apply to our operation?

If TSA regulates your airport or aircraft operation through an approved security program, the cybersecurity amendments reach you through that program: identifying critical cyber systems, segmenting them from other networks, controlling access, monitoring for intrusion and keeping them patched, with an incident response capability behind it all.

Operations outside TSA's programs are not off the hook commercially. Carriers, primes and insurers increasingly expect the same discipline by contract, so the practical question is rarely whether the obligations apply but which route they arrive by.

We machine parts for aerospace primes. Do defense cybersecurity rules really reach a shop our size?

If controlled unclassified information touches your systems, yes. The safeguarding requirements of NIST SP 800-171 flow down through prime contracts regardless of company size, and CMMC certification expectations arrive the same way, attached to the work itself.

Size changes the how, not the whether. A shop of forty people does not need an enterprise security department; it needs the requirements scoped to the systems that actually hold controlled data, a plan of action for the gaps, and one accountable owner who can speak to the prime's assessors. That is a fractional leadership problem, which is why it fits a vCISO engagement.

Is our export-controlled technical data allowed in the cloud?

Under defined conditions, yes. The export control regulations permit properly secured transmission and storage of controlled technical data, including end-to-end encryption arrangements under which the data is not treated as exported, but the conditions are specific and the access controls around who can decrypt matter as much as the encryption itself.

The failures we see are rarely exotic: controlled drawings in ordinary email, shared drives where access outlived the project, and no record of who can reach what. Specific licensing questions belong with export control counsel; building the access, encryption and evidence discipline underneath their advice is security leadership work.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.