CONFIDENTIAL · Airbus Protect internalSTR / EDDS · pre-meeting briefing
STR
EDDS
Pre-Meeting Dossier · ACI EUROPE 2026 · Prague

Stuttgart Airport

🇩🇪Flughafen Stuttgart GmbH (FSG) · Germany · Booth 358
Approach vector — The ideal managed-services account. A lean ~1,200-person hub taking over its own security screening from November 2026, under a now-in-force NIS2 regime — exactly the profile that buys an outsourced SOC, vCISO and IR retainer rather than building in-house.
Passengers / yr
≈ 8.4M
Cargo / yr
40,000 t
Employees
≈ 1,200
Screening handover
Nov 2026
Status
Warm
01

Who we're meeting

named targets · relationship status
Ulrich Heppe
CEO & Spokesman of the Management Board
Booth 358 · owns Operations, Security, Safety
Florian Frech
Head of IT
Existing Airbus Protect contact
Carsten Poralla
Managing Director — Non-Aviation (incl. IT)
Owns IT, Infrastructure
Relationship · WarmEntry via Florian Frech (Head of IT). CEO Heppe owns Security & Safety personally.
02

Situation board

what's happening · why now
Security transition
Taking over its own passenger screening from Nov 2026

Stuttgart signed a transfer-of-responsibility contract with the Federal Interior Ministry in January 2026 — the first medium-sized German hub to run its own security lanes. It now owns technology selection, the provider tender and, critically, the cyber and operational security of those new systems.

Scale & team
≈ 8.4M pax, ~1,200 staff — a lean operator

Smaller than Munich or Frankfurt and without a large in-house cyber function. This is the sweet spot for managed/outsourced security: an SOC, vCISO and IR retainer deliver enterprise-grade protection without enterprise headcount.

Leadership signal
CEO Heppe is ex-Fraport; owns Security & Safety

Heppe ran Fraport Bulgaria and Fraport Sénégal and led transition at Adani's Ahmedabad. He personally holds the Operations, Security and Safety brief — a CEO who understands aviation security and is hiring heavily in IT.

Mission
“Among Europe's most efficient and sustainable airports”

A decade-long efficiency-and-sustainability mission opens both a security-efficiency story and a sustainability-consulting angle.

03

Risk & regulatory exposure

the pressure they're under

NIS2 in force, deadlines already passed — and the team is lean

NIS2UmsuCG took effect 6 December 2025 with no transition period; as KRITIS, Stuttgart is a “besonders wichtige Einrichtung” with §38 board liability, §32 24h/72h reporting and §30 supply-chain duties. The BSI registration deadline (6 March 2026) has passed. For a lean team, the fastest route to compliance is a partner, not a hiring spree.

New screening = new attack surface, new accountability

Owning screening from November 2026 means new networked CT/scanner systems, new vendor relationships, and direct accountability for their security and continuity — landing precisely as NIS2 supply-chain obligations bite.

September 2025 set the bar for resilience

The Collins attack showed a mid-sized airport can be stopped by a supplier it doesn't control. Business continuity and IR for Stuttgart's growing digital estate is now a board expectation.

04

Opportunity map

their need → our offer · P1 = lead
CyberP1

Managed SOC / MDR (24/7)

A lean team can't staff 24/7 detection. Outsource it and get enterprise-grade coverage immediately.

Airbus ProtectAirbus Protect 24/7 SOC/MDR — full monitoring without building a Cyber Defence Centre.
CyberP1

NIS2 compliance programme + FENCE

Law in force, deadlines passed, personal board liability. Heppe needs a defensible compliance position fast.

Airbus ProtectEnd-to-end NIS2 readiness on the FENCE GRC platform — §30 risk management, §32 reporting workflow, §38 governance, evidence on demand.
CyberP2

vCISO / strategic cyber consulting

No need to hire a full CISO office — buy the capability as a service.

Airbus ProtectFractional CISO leadership and strategic roadmap, scaled to a 1,200-person operator.
CyberP2

Security for the new screening estate

The November 2026 handover brings systems Stuttgart has never had to secure.

Airbus ProtectArchitecture review, OT security and supplier-security baselines for the new screening systems.
CyberP2

Incident Response retainer

Without a big internal team, a retained responder is the resilience plan.

Airbus ProtectCSIRT retainer with 24/7 hotline and forensics — rehearsed, not improvised.
SustainabilityP3

Decarbonisation & compliance consulting

A stated sustainability mission plus EU reporting pressure.

Airbus ProtectDecarbonisation roadmaps, energy strategy and ESG-regulation support.
05

Why Airbus Protect — for them

the unfair advantages
USP 01

Built for the lean operator

Stuttgart needs enterprise security without enterprise headcount. Airbus Protect's managed model — SOC, vCISO, IR — delivers exactly that, with aviation context built in.

USP 02

Speaks Heppe's language

An ex-Fraport CEO who owns security personally will value a partner that is aviation-native and German-domiciled — not a generic IT outsourcer.

USP 03

Compliance that's actually defensible

NIS2 is live with personal liability. FENCE plus Airbus Protect's GRC practice produces audit-ready evidence, fast.

USP 04

German, EU-sovereign, aviation-grade

A German Airbus subsidiary — sovereignty, proximity and aviation pedigree in one partner.

06

Talking points

tap to open · tailored openers
“You're about to own the security of screening systems you've never had to run — right as NIS2 lands with personal board liability and the registration deadline already behind us. We can stand up managed SOC, NIS2 evidence and IR without you hiring a department.”
“You ran Fraport operations abroad — you know aviation security isn't a generic IT problem. We give a lean team enterprise-grade protection: 24/7 SOC, a defensible NIS2 position, and IR on retainer, all aviation-native and German.”
“November's handover is an opportunity to get the security architecture of the new screening estate right from the start. We'll review the design and set supplier-security baselines before the systems go live.”