Search

Cybersecurity in civil aviation and its legal framework

Cybersecurity in civil aviation and its legal framework

cybersecurity in civil aviation

The security of computer and information systems is currently a major topic, especially considering that the development of modern technologies is rapidly increasing every year. This trend is also shown by the adoption of the new Act 264/2025 Coll., on cybersecurity, which will enter into force on 1 November 11. The emphasis on higher cybersecurity can also be found in the field of civil aviation, which can be an easy and vulnerable target for cyberattacks. Our article aims to provide an overview of the basic specifics of cybersecurity legislation in civil aviation, including the possible consequences resulting from insufficient protection of the security of computer and information systems.

Specifics of cybersecurity in civil aviation

Modern technologies and their development have brought many challenges to the present day, including in protecting the functionality of these technologies. Increased emphasis on protecting these technologies is also placed in the field of civil aviation, which is characterized by an increased level of vulnerability, which can result in unpleasant consequences for those working in this sector, both legally and economically.

About topicality cybersecurity in civil aviation is evidenced not only by growing dependence on digital technologies, but also increasing number of security incidentsIn recent years, we have seen attacks on airport and airline systems that have led to operational outages (e.g. the hacker attack on Warsaw Chopin Airport in 2015), leaks of sensitive data (e.g. the leak of British Airways customer data in 2018) or disruptions to communication or navigation systems (most often occurring in the Middle East or Eastern Europe).[1]). These events show that civil aviation is becoming an attractive target for cyber attacks and it is essential to strengthen its resilience.

Legal framework for cybersecurity (safety) in civil aviation

The increased need to protect technologies in civil aviation is also being responded to by a significant amount of legal regulation, which seeks to mitigate this vulnerability in order to ensure the greatest possible aviation safety.

The aforementioned legal framework, which deals with cybersecurity issues, can be found as at the national level, but at the international level, including European Union law. For the sake of clarity, this article will focus on the basic legal regulations governing aviation cybersecurity.

National adjustment

The basic legal regulations addressing cybersecurity issues at the national level include, in particular:

  • Act No. 181/2014 Coll., Act on Cybersecurity and on the amendment of related laws[2] (hereinafter "ZKB"), whose rules may also affect persons working in air transport, which the National Cybersecurity Office (hereinafter referred to as "theOffice") decides that they are providers of the so-called essential services pursuant to Section 2, letter i), point 2. in the field of transport in accordance with the criteria set out Decree No. 437/2017 Coll., on criteria for determining the operator of the basic service point 2.1. of the annex to the decree,
  • "new" Act 264/2025 Coll., on cybersecurity (hereinafter "NZKB"), effective from 1.11.2025, which implements the so-called NIS 2 directive and significantly expands the circle of persons[4], which will be obliged to register under this Act and will be obliged to implement necessary and appropriate security measures, including in the field of aviation and air transport (Section 4, paragraph 1, letter a) point no. 8 of the NZKB)[5], or
  • Act No. 49/1997 Coll., on civil aviation (hereinafter "ZCL"), which is a basic legal regulation in the field of aviation, which regulates, among other things, aspects of general aviation security, also partially with regard to cybersecurity (e.g. Section 85m of the Civil Aviation Act, which stipulates the obligation to have an approved security program at the airport by the Civil Aviation Authority).

International adaptation

In addition to the above-mentioned national regulations, security issues (including cybersecurity) in aviation are also addressed by international regulations, where among the most important legal regulations are[6], in addition to the already mentioned NIS 2 directive, these include:

Aviation safety precautions

The common denominator of the above-mentioned legal regulations (and other related legal regulations) is that the aim of this regulation is striving to achieve the best possible defense, both against external and internal dangers that could threaten aviation safety in any way.

From a cybersecurity perspective, those working in aviation have obligations to ensure the protection of information and communication systems against hacker attacks is as guaranteed as possible.

Individual measures in the field of cybersecurity can be defined in the sense of the NZKB[8] divided into two basic types of measures, namely organizational and technical measures (Section 14 of the NZKB). These measures include, in accordance with Section 14 of the NZKB, for example: risk management, human resource security, access control, detection and recording of cyber security events or the use of cryptographic algorithms.[9][10].

Incident reporting

In addition to implementing specific measures, persons subject to the regulation of the NZKB (but ultimately also under other regulations, including the ZKB) also have other obligations, including the obligation to report cyber security incidents, either to the national team for coordination and management of cyber security incidents, events and threats (in the case of the regime of lower obligations – Section 15(2) of the NZKB) or to the Office (in the case of the regime of higher obligations – Section 15(1) of the NZKB) or an obligation towards suppliers (Section 24 et seq. of the NZKB).

Sanctions

The importance of implementing appropriate measures and fulfilling the aforementioned obligations also corresponds to potential sanctions for failure to comply with these obligations in accordance with the NZKB. These sanctions can reach up to
CZK 175.000.000 or 1,4% of global turnover in the case of a lower obligation regime or up to CZK 250.000.000 or 2% of global turnover, or suspension of certification or temporary ban on performing the function of a member of the statutory body.

Other legal and economic consequences

In addition to the above-mentioned sanctions associated with violations of cybersecurity obligations, the following may be considered: and other negative consequences resulting from a security incident,
and not only for persons subject to the above-mentioned regulation.

These consequences include, for example: imposition of a fine associated with a breach of personal data protection[11] whether claiming damages (in the case of air carriers, compensation for flight delays).

In addition to the legal consequences, these security incidents can have even in economic terms, because a possible security incident can affect both competitiveness (e.g. in the case of obtaining trade secrets or know-how from a competitor) and the very good reputation of a person working in aviation, which, given the limited circle of people working in aviation, can lead to fatal economic consequences.

záver

In light of the above, it is clear that the topic of cybersecurity is currently a very topical topic. For these reasons, it is advisable to have cybersecurity protection in aviation (and aviation security in general) set up to meet the highest security standards and minimize legal and economic risks.

Source: Epravo.cz

Are you interested in the issue of cybersecurity in civil aviation? Do you solve any questions related to aviation law? Contact experts in the field – we will advise you!

Jan Vych

JUDr. Ing. Jan Vych, attorney and partner

Mgr. David Šnajdr

Mgr. David Šnajdr, paralegal


[1] In response to these attacks, the European Union Aviation Safety Agency (EASA) and the International Air Transport Association (IATA) have adopted a plan that sets out a basic plan against this type of attack: https://www.easa.europa.eu/en/newsroom-and-events/press-releases/easa-and-iata-outline-comprehensive-plan-mitigate-gnss.

[2] It should be noted that the rules set out in this act will be valid until November 1, 11, when the new Cybersecurity Act will enter into force.

[4] These persons include persons providing a regulated service (Section 4(1)(a) of the NZKB) and persons who, pursuant to Section 4(1)(b) of the NZKB, are medium-sized or large enterprises within the meaning of Commission Recommendation 2003/361/EC of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises or are significant for the provision of important social or economic activities or for security in the Czech Republic.

[5] The specific list of services pursuant to Section 4, Paragraph 1, Letter a) of the NZKB and the definition of the conditions of significance of the provider of these services pursuant to Section 4, Paragraph 1, Letter b) of the NZKB will be determined by a decree issued by the Office (Section 4, Paragraph 2 of the NZKB).

[6] The list of legal regulations will include in particular legal regulations that establish certain specific rules in the field of aviation safety. The list will not include, for example, Agreement No. 147/1947 Coll., the Convention on International Civil Aviation (the so-called Chicago Convention).

[7] The State Safety Plan of the Czech Republic for 2023-2025 is available on the website of the Ministry of Transport: https://md.gov.cz/Dokumenty/Letecka-doprava/Pravni-predpisy/Statni-plan-bezpecnosti-2023-2025?returl=/Dokumenty/Letecka-doprava/Pravni-predpisy.

[8] Due to the approaching effectiveness of the NZKB, the authors consider it better to focus on the issue of security measures on the modification of the NZKB.

[9] The specific measures differ according to the so-called regime of obligations under the NZKB (Section 8 of the NZKB). The authors have selected measures that will be used in both of these regimes.

[10] The specific content of these measures will be supplemented by a decree issued by the Office.

[11] This occurred, for example, in the aforementioned case of British Airways, which was fined over £183 million for violating GDPR rules.

Have you read this far?

Subscribe to our newsletter

Enter your email here so you don't miss any news from our office.
More articles

Thank you for visiting our site.

If you would like to receive a selection of current legal news, we would like to offer you the opportunity to subscribe to our newsletter. Simply fill in your e-mail address.

Law firm Vych and partners