When ransomware hit Collins Aerospace's MUSE passenger-processing platform on 19 September 2025, BER was the most severely impacted airport in Europe. Check-in and baggage reverted to manual for days; flights were cancelled; recovery took roughly two weeks. ENISA confirmed ransomware. This is fresh, public, and board-defining — the perfect, non-confrontational reason to open a conversation about resilience.
BER's self-service kiosks and Fast-Bag-Drop ran on redundant infrastructure and remained available — a concrete proof point that designed-in redundancy works, and a natural lead-in to a broader resilience-by-design discussion.
BER is a relatively young hub still maturing operationally (and the cautionary tale rivals like PPL explicitly cite). Security and resilience maturity is an active, ongoing agenda.
Public-sector ownership and a capital-city flagship status raise both scrutiny and the bar for trusted, sovereign partners.
BER experienced the third-party supply-chain ransomware scenario first-hand — and NIS2UmsuCG (in force 6 Dec 2025, no transition) now makes §30 supply-chain risk management a legal duty, with §38 personal board liability and §32 24h/72h reporting. The lesson and the law have converged.
Two weeks of disruption underlines what a retained, rehearsed incident-response capability and business-continuity plan are worth. The next incident's cost is set by how ready BER is before it happens.
The attack made supplier dependency and segmentation a leadership topic, not an IT footnote. Vendor-security baselines and IT/OT segmentation are exactly what's under review.
BER lived two weeks of manual operations. Resilience-by-design is the most credible possible opening.
Recovery was slow because response wasn't pre-arranged. Fix that before the next incident.
The attack came through a supplier; NIS2 now makes managing that a legal duty.
Segmentation between airport operations and vendor systems is the structural lesson of the attack.
Earlier detection shortens the next incident.
Part-IS applies to BER as an operator; resilience and governance reinforce each other.
No prospect has a clearer reason to act. Airbus Protect converts a public, painful incident into resilience-by-design, supply-chain assurance and a rehearsed response — the precise capabilities the attack proved BER needed.
Airbus Protect designs business continuity and crisis response for aviation specifically — with the systems-engineering rigour of an Airbus company.
The attack came through a third party. Third-party risk governance and vendor baselines are core Airbus Protect offerings — and now a NIS2 obligation.
A European Airbus subsidiary suits a publicly-owned, capital-city airport where trust and sovereignty matter.