An integrated operating model for risk management, operational resilience, crisis management, business continuity and cyber resilience across the European aerodrome, powered by the 7A Risk Management Framework and proven by exercise. Published in three editions: commercial, air freight and business aviation.
DAEDALUS is Resilience Guard's proprietary Airport Resilience Framework: an integrated operating model that treats the aerodrome as a single system of systems, binds five resilience domains, risk management, operational resilience, crisis management, business continuity and cyber resilience, into one architecture, drives that architecture with the 7A Risk Management Framework, anchors it in board level governance, and proves it through a graduated, multi agency exercise programme.
Where most airport assurance is organised around compliance checklists and after the fact incident reviews, DAEDALUS is organised around defensible executive decisions made before, during and after disruption, and around the justified confidence that leadership can actually manage the exposures it carries. Nothing critical is allowed to sit unmapped or unowned, from the runway and the control tower interface through ground handling, baggage, fuelling, the terminal and passenger data core, the perimeter and airspace, to the enabling utilities and the extended enterprise of handlers, navigation providers and vendors, because the unmapped node is exactly where the recent disruptions originated.
The name is deliberate. Daedalus was the master craftsman of flight in Greek myth, the engineer whose wings worked because they were designed with discipline and respect for the conditions, in contrast to the reckless ambition that undid Icarus. Resilience is engineered, not improvised, and it is built by people who understand the system they are protecting.
European airports have spent three years learning the same lesson in public. In August 2023 a single malformed flight plan disabled the United Kingdom's air traffic system, disrupting more than seven hundred thousand passengers. In July 2024 a faulty update from a cybersecurity vendor cascaded into roughly seventeen thousand flight cancellations worldwide in three days. In March 2025 a substation fire outside the perimeter closed Europe's busiest airport for some eighteen hours and more than thirteen hundred flights. In September 2025 a ransomware attack on a single common use check in supplier forced four major airports back to pen and paper. And from September into November 2025 a wave of drone incursions, treated by national authorities as probable hybrid activity, repeatedly suspended operations at one capital airport after another.
None of these was a failure of aviation safety in the classical sense; every one was a failure of resilience, and they share a single anatomy. A concentrated dependency failed. The failure crossed an organisational boundary that no single party owned. The response was slowed by arrangements that had never been tested at the necessary scale. And the recovery was governed by improvisation rather than rehearsal. None of that is visible to a compliance checklist; it is visible only to an integrated, exercised operating model, which is what DAEDALUS provides.
The obligation now arrives on a fixed timetable. The EU's aviation information security regime, Part-IS, became applicable to aerodrome operators on 16 October 2025 and extends across the wider aviation population from 22 February 2026, with applicability the start of the obligation rather than its discharge. The Critical Entities Resilience Directive names transport among its supervised sectors, NIS2 raises cybersecurity and reporting duties, and Swiss critical infrastructure operators have been bound since 1 April 2025 to report cyberattacks to the national authority within twenty four hours. Resilience has become a board level legal responsibility rather than an operational courtesy.
DAEDALUS is driven by the 7A Risk Management Framework, which decomposes every material risk into two independent indices: the Risk Exposure Index, capturing impact severity, stressed likelihood, velocity and cascade potential, and the Confidence Index, capturing the justified belief that leadership can actually manage that exposure. Their combination places each risk into one of four governance states, and the dangerous quadrant is not high likelihood and high impact; it is high exposure with low confidence, the quadrant a conventional heatmap collapses into a single ambiguous colour. Every marquee disruption of 2023 to 2025 sat in that quadrant before it happened, each one rated managed on paper but untested in practice.
The Confidence Index is computed from evidence, not opinion. Every score is referenced to fixed evidence pillars, the recency and result of the last realistic test, independent assurance status, the completeness of the dependency map, whether recovery time objectives have been demonstrated rather than assumed, and the closure of incident actions, and three rules keep it honest: a score cannot exceed its weakest pillar, it decays if the control is not retested within its window, and it is validated by the independent third line rather than self assessed. Untested means unmanaged, not merely unproven.
An airport's resilience is only ever as strong as the providers that deliver its operation, and the recent disruptions propagated through exactly those providers: the handler whose system failed, the vendor whose update cascaded, the supplier whose platform was held to ransom. The DAEDALUS spine extends to the ground handlers, caterers, maintenance organisations, air navigation provider, fuel operators and cargo and logistics partners through six defined plug in points: the provider node mapped inside the airport's dependency register with cross boundary single points of failure owned jointly; provider controls mapped to the five domains; the provider's test and recovery evidence feeding the airport's Confidence Index; joint detection and notification wired to the reporting clock and the command structure; membership of the multi agency exercise programme; and resilience obligations written into the contract with the recognised assurance standard evidenced.
Every provider assured to the DAEDALUS standard is a seam closed in the airport's own dependency map, so the posture stops being an assertion about the airport's own controls and becomes an evidenced statement about the whole dependency, including the parts the airport does not own. See also our supply chain security practice, which applies the same discipline beyond aviation.
Every marquee disruption failed at a point a realistic exercise would have exposed beforehand: the remote recovery that broke under pressure, the manual fallback never rehearsed at volume, the notification chain with a silent telephone in it, the multi agency seam no one had tested. DAEDALUS therefore treats exercising as the mechanism by which the model is proven and the Confidence Index is earned, through a graduated programme aligned with the cadence ICAO already expects of aerodrome emergency planning, and extended deliberately beyond the classic accident scenario to the cyber, continuity and hybrid scenarios the recent disruptions proved decisive. The scenario library is evidence led: a common use platform ransomware attack forcing manual processing, a prolonged power loss requiring rehearsed recovery sequencing, a coordinated drone incursion requiring joint command, a deepfake enabled impersonation of a leader during a live incident, and the classic accident and security cases. Every exercise closes the loop: lessons captured, actions owned and dated, closure verified at the next exercise.
The programme is delivered through our exercise formats, from board tabletops to full scale simulation, with multi agency rehearsal treated as non negotiable because the seams between organisations are where real crises fail.
DAEDALUS is Resilience Guard's proprietary operating model for airport resilience: five domains, risk, operational resilience, crisis, continuity and cyber, bound into one architecture across the whole aerodrome system of systems, driven by the 7A Risk Management Framework, anchored in board governance and proven through a graduated multi agency exercise programme.
Because the disruption record of 2023 to 2025, air traffic collapse, vendor cascade, substation fire, common use ransomware and drone incursions, shows systemic failures that compliance checklists cannot see, and because Part-IS, the Critical Entities Resilience Directive, NIS2 and the Swiss 24 hour reporting duty have made demonstrable resilience a board level legal responsibility on fixed dates.
Commercial passenger, calibrated to passenger processing continuity and high consequence crisis response; air freight and cargo, calibrated to supply chain, cold chain and round the clock tempo; and business aviation, calibrated to discretion, privacy and physical security. Combined operations layer the relevant editions on one spine under one command chain.
Every material risk is measured on two independent axes, exposure under stress and evidence based confidence in the controls, placing it in one of four governance states with an explicit mandate. The Confidence Index is scored against fixed evidence pillars, capped by the weakest, decays if untested and is validated by the independent third line, so the board sees earned confidence rather than self assessment.
An organisational accreditation that lets an aerodrome evidence its resilience posture through an independent two stage assessment, with a three year certificate, annual surveillance and an explicit impartiality firewall separating certification from advisory and implementation.
With a bounded, senior led diagnostic, typically six to eight weeks: five domain maturity, cross boundary dependency register, business impact analysis and the 7A exposure and confidence baseline, closing with a prioritised, costed gap closure plan so the decision to proceed is evidence based.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Six to eight weeks, senior led, low disruption: your five domain maturity, your true dependencies and your 7A confidence baseline, with a prioritised plan to close the gaps that matter.
Book a consultation