Stuttgart signed a transfer-of-responsibility contract with the Federal Interior Ministry in January 2026 — the first medium-sized German hub to run its own security lanes. It now owns technology selection, the provider tender and, critically, the cyber and operational security of those new systems.
Smaller than Munich or Frankfurt and without a large in-house cyber function. This is the sweet spot for managed/outsourced security: an SOC, vCISO and IR retainer deliver enterprise-grade protection without enterprise headcount.
Heppe ran Fraport Bulgaria and Fraport Sénégal and led transition at Adani's Ahmedabad. He personally holds the Operations, Security and Safety brief — a CEO who understands aviation security and is hiring heavily in IT.
A decade-long efficiency-and-sustainability mission opens both a security-efficiency story and a sustainability-consulting angle.
NIS2UmsuCG took effect 6 December 2025 with no transition period; as KRITIS, Stuttgart is a “besonders wichtige Einrichtung” with §38 board liability, §32 24h/72h reporting and §30 supply-chain duties. The BSI registration deadline (6 March 2026) has passed. For a lean team, the fastest route to compliance is a partner, not a hiring spree.
Owning screening from November 2026 means new networked CT/scanner systems, new vendor relationships, and direct accountability for their security and continuity — landing precisely as NIS2 supply-chain obligations bite.
The Collins attack showed a mid-sized airport can be stopped by a supplier it doesn't control. Business continuity and IR for Stuttgart's growing digital estate is now a board expectation.
A lean team can't staff 24/7 detection. Outsource it and get enterprise-grade coverage immediately.
Law in force, deadlines passed, personal board liability. Heppe needs a defensible compliance position fast.
No need to hire a full CISO office — buy the capability as a service.
The November 2026 handover brings systems Stuttgart has never had to secure.
Without a big internal team, a retained responder is the resilience plan.
A stated sustainability mission plus EU reporting pressure.
Stuttgart needs enterprise security without enterprise headcount. Airbus Protect's managed model — SOC, vCISO, IR — delivers exactly that, with aviation context built in.
An ex-Fraport CEO who owns security personally will value a partner that is aviation-native and German-domiciled — not a generic IT outsourcer.
NIS2 is live with personal liability. FENCE plus Airbus Protect's GRC practice produces audit-ready evidence, fast.
A German Airbus subsidiary — sovereignty, proximity and aviation pedigree in one partner.