CONFIDENTIAL · Airbus Protect internalBER / EDDB · pre-meeting briefing
BER
EDDB
Pre-Meeting Dossier · ACI EUROPE 2026 · Prague

Berlin Brandenburg Airport

🇩🇪Flughafen Berlin Brandenburg GmbH (FBB) · Germany
Approach vector — Greenfield with the single sharpest door-opener in the entire field. BER was the worst-hit airport in the September 2025 Collins ransomware attack — days of manual operations. The conversation writes itself: “We help you ensure September never repeats.”
Sept 2025 impact
Worst-hit in Europe
Recovery
≈ 2 weeks to normal
Owners
Berlin · Brandenburg · Federal
Opened
2020 (after delay)
Status
Greenfield
01

Who we're meeting

named targets · relationship status
FBB Management Board
CEO / COO / CIO
Identify and confirm on-site via the app
Head of IT / CISO
Information security lead
Primary technical entry point
Relationship · GreenfieldNo existing contact — but the strongest natural opening of any prospect. Lead with resilience and supply-chain assurance.
02

Situation board

what's happening · why now
The defining event
Worst-affected airport in the September 2025 Collins attack

When ransomware hit Collins Aerospace's MUSE passenger-processing platform on 19 September 2025, BER was the most severely impacted airport in Europe. Check-in and baggage reverted to manual for days; flights were cancelled; recovery took roughly two weeks. ENISA confirmed ransomware. This is fresh, public, and board-defining — the perfect, non-confrontational reason to open a conversation about resilience.

What survived
Redundant self-service kiosks stayed up

BER's self-service kiosks and Fast-Bag-Drop ran on redundant infrastructure and remained available — a concrete proof point that designed-in redundancy works, and a natural lead-in to a broader resilience-by-design discussion.

Operating context
Opened 2020 after a notorious delay; still maturing

BER is a relatively young hub still maturing operationally (and the cautionary tale rivals like PPL explicitly cite). Security and resilience maturity is an active, ongoing agenda.

Ownership
Berlin, Brandenburg and the Federal Republic

Public-sector ownership and a capital-city flagship status raise both scrutiny and the bar for trusted, sovereign partners.

03

Risk & regulatory exposure

the pressure they're under

Lived the exact risk NIS2 now legislates

BER experienced the third-party supply-chain ransomware scenario first-hand — and NIS2UmsuCG (in force 6 Dec 2025, no transition) now makes §30 supply-chain risk management a legal duty, with §38 personal board liability and §32 24h/72h reporting. The lesson and the law have converged.

Recovery proved the case for a pre-arranged IR partner

Two weeks of disruption underlines what a retained, rehearsed incident-response capability and business-continuity plan are worth. The next incident's cost is set by how ready BER is before it happens.

Vendor architecture is now a board question

The attack made supplier dependency and segmentation a leadership topic, not an IT footnote. Vendor-security baselines and IT/OT segmentation are exactly what's under review.

04

Opportunity map

their need → our offer · P1 = lead
CyberP1

Business resilience & continuity (lead offer)

BER lived two weeks of manual operations. Resilience-by-design is the most credible possible opening.

Airbus ProtectBespoke Business Continuity Plans, resilience exercises and crisis coaching — turning September's lesson into designed-in resilience.
CyberP1

Incident Response retainer + 24/7 hotline

Recovery was slow because response wasn't pre-arranged. Fix that before the next incident.

Airbus ProtectAirbus CSIRT on retainer with a 24/7 hotline and digital forensics — rehearsed, fast, aviation-grade.
CyberP1

Supply-chain & third-party risk + NIS2

The attack came through a supplier; NIS2 now makes managing that a legal duty.

Airbus ProtectFENCE-based GRC for vendor-security baselines and NIS2 evidence — directly addressing the September failure mode.
CyberP2

IT/OT segmentation & security architecture

Segmentation between airport operations and vendor systems is the structural lesson of the attack.

Airbus ProtectArchitecture review and segmentation to contain the next third-party compromise.
CyberP2

Managed SOC / MDR

Earlier detection shortens the next incident.

Airbus Protect24/7 SOC/MDR to detect and contain before disruption spreads.
CyberP3

Part-IS audit & governance

Part-IS applies to BER as an operator; resilience and governance reinforce each other.

Airbus ProtectEASA-accredited Qualified Entity support for Part-IS governance.
05

Why Airbus Protect — for them

the unfair advantages
USP 01

We turn September into a strategy

No prospect has a clearer reason to act. Airbus Protect converts a public, painful incident into resilience-by-design, supply-chain assurance and a rehearsed response — the precise capabilities the attack proved BER needed.

USP 02

Aviation-grade resilience, not generic BCP

Airbus Protect designs business continuity and crisis response for aviation specifically — with the systems-engineering rigour of an Airbus company.

USP 03

Supply-chain assurance is our answer to the actual failure

The attack came through a third party. Third-party risk governance and vendor baselines are core Airbus Protect offerings — and now a NIS2 obligation.

USP 04

Sovereign, trusted, fit for a public flagship

A European Airbus subsidiary suits a publicly-owned, capital-city airport where trust and sovereignty matter.

06

Talking points

tap to open · tailored openers
“September was the hardest two weeks in your operation's recent history — and it came through a supplier you didn't control. We help airports ensure that never repeats: rehearsed incident response, designed-in resilience, and supplier assurance that's now also a NIS2 duty. And we build it for aviation, as an Airbus company.”
“Your redundant kiosks stayed up while everything else went manual — proof that designed-in resilience works. The opportunity is to extend that principle across the operation before the next incident.”
“The risk you lived through is now the risk NIS2 makes you legally accountable for — with personal board liability. We close that gap with supply-chain governance and a rehearsed response, both aviation-native.”