Safety-critical, safety-regulated, and attacked through everything else
Nothing about an aircraft is casually changed. Certification, airworthiness and maintenance regimes make aerospace one of the most rigorously controlled engineering environments there is, and that rigour is real security value.
It is also not where the attacks land. Aviation compromises arrive through booking and operations platforms, ground handling systems, maintenance providers, cargo and logistics partners, and the ordinary corporate IT sitting alongside all of it. The consequence shows up as cancelled flights and grounded fleets without anyone touching a certified system.
The intelligence problem follows from that. Reporting on aviation incidents, avionics advisories, supplier breaches, satellite ground segment compromise and navigation interference lives in five different communities. Nobody aggregates them.
For defence programmes and the cleared supply chain, see /industries/defence.
Why the sector needs its own view
Operational disruption is both the objective and the pressure
Grounded aircraft, cancelled flights and stranded passengers are visible within hours and expensive immediately. Extortion groups understand this as well as they understand hospital downtime.
The maintenance and parts chain is deep and global
MRO providers, parts distributors, ground handlers and cargo operators hold operational data and system access across many carriers at once. One compromise reaches several airlines.
Certification slows patching by design
Avionics and aircraft systems run on software change processes measured against airworthiness rather than against exploit timelines. That is correct, and it means knowing which exposures are actually being exploited matters more here than almost anywhere.
Navigation interference is now routine
GNSS jamming and spoofing affecting civil aviation across several regions has moved from anomaly to operating condition, and it sits in a reporting stream most security tools ignore entirely.
The space segment has its own exposure
Satellite operators, ground stations and the terminals downstream of them have been targeted directly, including as an opening move in conflict. Ground segment and modem infrastructure is where it happens rather than in orbit.
Airports are cities with a fence
Retail, hospitality, border systems, baggage handling, fuel, parking and dozens of tenant organisations sharing infrastructure and blame.
What ThreatCluster does for an aerospace security team
Coverage across all five communities
Aviation incident reporting, avionics and ICS advisories, supplier and MRO breach reporting, satellite and ground segment compromise, and navigation interference, ingested and clustered together instead of tracked separately.
Supplier and partner monitoring
Track MRO providers, ground handlers, parts distributors, cargo partners and platform vendors as watched entities. Their incident is your operational disruption.
Exploitation status, not CVSS theatre
Confirmed in-the-wild exploitation separated from the rest of the queue, which is what justifies opening a change process in an environment where change is expensive.
One record per incident
Every source covering the same event in a single record with timeline, entities, IOCs and ATT&CK mapping.
Reporting your regulator will accept
Dated, sourced briefings ready to forward to a safety and security function, an auditor or a national authority.
Running in an afternoon
- Tell it what you run. Fleet platforms, operations systems, suppliers, sector.
- Pick how it reaches you. Digest, Slack, Teams, RSS or API.
- Wire the outputs in. IOC exports to the SIEM, reports to the safety and security function.
Hosted, outbound only, nothing deployed on operational or certified systems.
Evidence for the regimes you are assessed against
Aerospace and aviation organisations answer to safety and security regulators as well as the usual information-security frameworks, and most now expect documented awareness of current threats.
- EASA Part-IS, the information security requirements now applying across EU aviation organisations
- DO-326A / ED-202A airworthiness security process for aircraft systems
- ICAO Annex 17 and national aviation security programmes
- TSA security directives for US aviation operators
- NIS2, which covers air transport as an essential entity in the EU
- ISO 27001 Annex A 5.7 as a named control
ThreatCluster is the monitoring and evidence layer underneath these. It produces the dated, sourced record a regulator or auditor asks for.
Questions we get from aerospace buyers
“We already participate in A-ISAC.”
Keep it. Sector sharing is authoritative and narrow. It does not cover your named MRO providers, the platforms in your estate, or the CVE in the appliance carrying your third-party connectivity.
“Aircraft systems are certified and isolated.”
They largely are, and almost no aviation disruption we cluster involved touching one. It involved operations, ground handling or corporate IT. The question worth asking is what stops flights if those go dark.
“We are an MRO, not an airline.”
Then the supplier and parts chain sections are the relevant ones, and the airline-facing material is not. Filtering is set by you.
“Does this cover the space side or only aviation?”
Both. Ground segment and satellite operator reporting is tracked alongside aviation, because for operators running both the two pictures have converged.
What we are tracking in the sector right now
Every incident on the aerospace entity page is drawn from live clustering: active clusters, associated threat groups, and the most recent reporting, updated continuously.
Aerospace threat intelligence FAQ
What is threat intelligence for aerospace?
Monitoring of the threats specific to aviation and space organisations: ransomware and extortion against airlines and airports, compromise of MRO and ground handling providers, vulnerabilities in avionics and operational systems, satellite ground segment attacks, and navigation interference.
Do you cover GNSS jamming and spoofing?
Yes, reporting on navigation interference affecting civil aviation is tracked alongside the cyber reporting.
Do you cover satellite and ground segment security?
Yes. Satellite operators, ground stations and terminal infrastructure are tracked as entities.
What is the difference between this and the defence page?
This page covers commercial aviation, MRO, airports, avionics and the space segment. Defence programmes and the cleared supply chain are covered separately at /industries/defence.
Is there a free version?
Yes, with no card required.
Five reporting streams, one feed
Free account, no card. Set your suppliers and platforms and see a week of filtered reporting across all five.