AERO Vodochody: Developing a Cybersecurity Strategy
Customer: AERO Vodochody AEROSPACE a.s.
Project period: 2019–2023
Developing and implementing an IT security strategy
Customer
Aero Vodochody is the largest aircraft manufacturer in the Czech Republic and a major manufacturer of jet training aircraft. It develops, manufactures, sells and services military aircraft and civil aviation technology. Its supplier network includes more than 400 companies in the Czech Republic. Aero is one of the world’s oldest aircraft manufacturers: the company was registered with the Commercial Court in Prague on 25 February 1919.
Customer needs
The customer faced significant cybersecurity challenges. Its IT environment relied on ageing technology, and some systems had been introduced as rapid, reactive responses to immediate needs. As international tensions increased, attempts to compromise its infrastructure became more frequent, predominantly originating from eastern countries. These attempts threatened both the company’s know-how and its commercial activities.
The company decided to take a systematic approach to network protection and began looking for a new partner.
Main challenges
- No overarching cybersecurity strategy.
- Limited expertise in security architecture and no established methodology for managing risks and controls.
- Underused security tools, including Check Point firewalls, and fragmented infrastructure investment.
- Unsatisfactory outsourced LAN management and limited documentation.
- Missing preventive maintenance, particularly for security infrastructure.
Why ComSource
Aero Vodochody selected ComSource following repeated practical experience of working together on security incidents during the early years of the relationship. ComSource provided services described in the project as RED team support, actively participated in incident investigations and helped introduce both immediate responses and systematic measures. ComSource specialists joined the customer’s crisis management team during incidents.
Our work
ComSource assessed the network infrastructure and the wider cybersecurity environment, identifying a range of potential risks. Penetration testing highlighted the most urgent weaknesses. Based on these findings, the customer commissioned a cybersecurity strategy defining the target state.
The strategy initiated changes to technology and processes. Work included network and firewall segmentation, replacement of selected security and access technologies, and investment in communications monitoring. The customer also introduced an outsourced cybersecurity management role and Security Operations Center as a Service (SOCaaS).
The strategy addressed potential adoption of cloud services. ComSource also provided operational support for selected infrastructure from vendors including Juniper, Flowmon, Cisco, Check Point and Fortinet. Work extended to documenting passive network infrastructure and improving records both in network cabinets and in electronic documentation, with future technology renewal in mind.
Key elements of the collaboration
- CISOaaS: outsourced cybersecurity management, strategy development and mentoring of operational teams.
- SOCaaS: a security monitoring service integrating selected technologies, including domains, firewalls, authentication and authorization tools, and other key systems.
- NOCaaS: network monitoring and operational support, including regular preventive maintenance of active network equipment.
- Consulting on IT infrastructure investment strategy and ROI analysis for strategic decisions.
- Financial services.
- Documentation services.
- RED team services and perimeter penetration testing.
Results
The strategy helped Aero move from a reactive cybersecurity model to a proactive approach. The customer gained a clearer understanding of its data, IT resources and risks, with corrective measures in place. It was better prepared for technology renewal and the introduction of modern services such as cloud computing.
The collaboration significantly improved cybersecurity at Aero Vodochody and helped integrate security into the management of its IT resources.