PPL is now the strategic investor in Poland's Centralny Port Komunikacyjny, investing ≈ PLN 4.6B by 2032 (potentially up to 100% control). Construction starts 2026; certification 2031; first passengers 2032. This is the largest airport build in post-war Poland — and a once-in-a-generation security-by-design engagement.
The CPK procurement pipeline is opening now: airport facilities, aeronautical lighting, energy and digital infrastructure. Security architecture and OT assurance should be specified into these builds, not retrofitted.
PPL operates Chopin (≈ 23M pax, near capacity) plus Radom, Zielona Góra and stakes in Kraków, Katowice, Gdańsk, Poznań, Wrocław, Rzeszów. A separate PLN 1B Chopin upgrade runs 2027–2029 — an immediate, parallel cyber/OT need.
PPL explicitly plans to validate procedures at Chopin first to avoid the start-up failures “experienced at other new airports in Europe — for example, Berlin Brandenburg.” De-risking a complex programme is precisely Airbus's track record.
Poland borders Ukraine, Belarus and Kaliningrad. Polish critical infrastructure faces sustained hybrid pressure: GPS jamming, sabotage, state-aligned cyber operations. A national flagship airport programme is a strategic target from the first foundation pour.
Retrofitting security into a built airport is the most expensive lesson in the industry. Architecting OT segmentation, identity, and resilience into Port Polska from the design phase is dramatically cheaper and stronger — and the design phase is now.
Poland's transposition of NIS2 via the National Cybersecurity System (KSC) and EASA Part-IS both apply. The CISO's high maturity and active Part-IS dialogue mean this is a sophisticated, ready buyer — not an education exercise.
The greenfield prize: bake OT/IT segmentation, zero-trust identity and resilience into the design before a cable is pulled.
Bjorum is already exchanging on Part-IS at high maturity. Convert dialogue into a mandate.
Aeronautical lighting, BHS, energy and building systems are all in the tender pipeline — specify their security now.
A 2031 certification milestone for a brand-new hub is a vast safety-assurance undertaking.
100 tenders means 100+ suppliers — each a potential weak link, as September 2025 proved.
Chopin needs live defence now, through the modernisation and the run-up to CPK.
PPL explicitly wants to avoid Berlin Brandenburg's start-up problems. Airbus delivers the world's most complex aerospace programmes on schedule — that delivery discipline is the differentiator for CPK.
An Airbus subsidiary understands sovereignty, frontline threat and defence-grade assurance — and Airbus has a substantial industrial presence in Poland. A trusted European, not a hyperscaler or a non-aligned vendor.
Almost no prospect can architect a hub's security from a blank sheet. PPL can — and Airbus Protect is built to do exactly that.
Matches the CISO's maturity with the one credential that formally backs Part-IS implementation, for both Chopin and CPK.