Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal

Operationalising Trust in the Sky: An Institutional Analysis of EASA Part-IS Implementation

Edouard van den Heuvel

Amsterdam Business School, University of Amsterdam, the Netherlands.

edouard.vandenheuvel@uva.nl

Riana Steen

Department of Safety, Economics and Planning University of Stavanger, Norway.

riana.steen@uis.no

Maria Papanikou

Faculty of Technology,, Amsterdam University of Applied Sciences, the Netherlands.

m.papanikou@hva.nl

ABSTRACT

The European Aviation Safety Agency (EASA) Part-IS regulation requires EU airlines to integrate information security into existing aviation safety frameworks, aiming to improve regulatory consistency, organisational resilience, and overall aviation safety. Despite its significance, limited empirical insight exists into the preparedness of airlines to implement and demonstrate compliance with Part-IS. This study examines implementation readiness using publicly available information, reflecting the perspective of external stakeholders. A systematic document review and regulatory gap analysis are applied to six purposively selected European airlines representing variation in business models, governance structures, and geographic coverage within the EASA jurisdiction. The analysis focuses on six high-priority clauses according to IS.I.OR regulation and assesses the alignment between publicly disclosed governance arrangements, security risk management practices, and procedural measures and regulatory requirements. The findings indicate that all sampled airlines have established basic information security structures and initiated preparatory activities. From an institutional perspective, organisational responses largely reflect compliance with formal regulatory demands and partial alignment with industry norms, while information security remains unevenly embedded in organisational practices. However, publicly available information rarely addresses aviation-specific security risk assessments, the integration of information security into occurrence reporting systems, or the existence of formal Information Security Management Manuals. This lack of transparency constrains external evaluation of regulatory readiness and may affect stakeholder confidence. The study contributes a transparent and replicable approach for assessing implementation readiness in security-sensitive and highly regulated domains and highlights the need for structured procedural development and clearer public disclosure to demonstrate compliance and strengthen trust in aviation safety and security.

Keywords: Aviation safety, EASA Part-IS, Cybersecurity, Regulatory readiness, Information Security Management, Resilience.



Download PDF