Munich operates a “Center of Excellence against Cyber Crime” with a full Cyber Defense Centre, OT training room and IT labs — and even sells cyber training via its AirportAcademy. This is a mature, self-aware buyer. The pitch is specialist depth and surge capacity, never “you need security.”
New T1 Pier for non-Schengen long-haul opened April 2026 (+6M capacity). Growth and new infrastructure expand the attack surface faster than internal teams can scale.
Repeated drone incursions delayed operations — a vivid, recent, board-level reminder that airspace and operational resilience is not just a cyber-screen problem. A crisis-management and resilience opening.
Shared infrastructure and governance across operator and anchor carrier multiplies third-party and identity complexity.
The German NIS2UmsuCG entered into force on 6 December 2025. As KRITIS, Munich is automatically a “besonders wichtige Einrichtung”: management-board personal liability (§38), 24h/72h incident reporting (§32), mandatory supply-chain risk management (§30), fines to €10M / 2% turnover (§65). The BSI registration deadline (6 March 2026) has already passed.
Munich runs different passenger systems and was unaffected in September 2025. As a sophisticated buyer, FMG understands this was vendor architecture, not invulnerability — and that NIS2 now makes supply-chain assurance a legal duty, not a best practice.
EASA Part-IS reaches FMG as an operator whose information systems touch aviation safety. A mature SOC is necessary but not sufficient for the aviation-safety governance Part-IS demands.
Contract starting via Haumberger. Even a strong in-house SOC needs an external, aviation-grade IR partner for major-incident surge and forensics.
A world-class SOC doesn't equal Part-IS governance maturity.
ISH has an OT training room — proof OT is on their radar. New pier, baggage, energy and apron systems need live OT defence, not just training.
The fastest way to add value to a mature SOC: test it adversarially and tune detection together.
October 2025 drone disruption is fresh. Operational resilience and crisis playbooks are top of mind.
A premium hub is a high-value target for credential leakage and industrial espionage.
Munich runs one of Europe's most respected airport SOCs. Airbus Protect engages as a technical equal — surge capacity, adversarial testing and aviation-safety governance the ISH doesn't replicate.
The IR contract validates the fit. Airbus's CSIRT brings forensics and 24/7 response with aviation context no generic MSSP matches.
Bridges the gap between an excellent SOC and the aviation-safety security governance Part-IS requires.
Post-drone, the Airbus pedigree across counter-UAS, airspace and ground operations is a differentiator no pure-play cyber firm can claim.