Cybersecurity Meets Safety: Discussion on the Risks of Networked Systems at the Cybersecurity Meetup Munich

27 April 2026

At the Cybersecurity Meetup Munich in February 2026, experts from industry and research discussed the growing importance of the intersection of safety and cybersecurity — particularly in complex and safety-critical systems such as aerospace. The discussion focused on differing understandings of risk, the challenges posed by networked systems, and the shift of cybersecurity from a “nice-to-have” to a fundamental prerequisite for modern technologies.

On February 24, 2026, Airbus and infodas hosted the Munich Cybersecurity Meetup, which focused on the growing integration of functional safety and cybersecurity. Following an introductory presentation by Prof. Dr. Chiara Manfletti (Head of the Department of Aerospace and Geodesy and Professor of Space Mobility and Propulsion) on space activities at the Technical University of Munich (TUM) and the specific challenges of safety-critical systems, a panel discussion took place with experts from industry and research.

 

A key topic was the insufficient integration of safety and cybersecurity approaches to date. Prof. Dr. Chiara Manfletti emphasized that, although greater integration is necessary, these two areas have largely been considered separately thus far. In particular, while data integrity is recognized as crucial, it has not yet been consistently addressed. Differences exist between the engineering perspective on systems and the requirements of end users.

Dr. Tobias Kiesling (Head of the Cyber Technical Office, Airbus Protect) also pointed out that modern systems are increasingly interconnected, but that the challenges posed by this interconnectivity have not yet been adequately addressed. He noted that a common understanding of risks has yet to be established. Regulation and standards could help create a uniform foundation in this area.

Andreas Krüger (Founder & CEO, Laokoon Security) highlighted the fundamental differences between the disciplines: While functional safety aims to protect the environment from potential system malfunctions, cybersecurity is designed to protect systems from a dynamic and potentially hostile environment.

 

During the discussion, it became clear that while both fields use the term “risk,” they attach different meanings to it. Andreas Krüger emphasized that threat modeling is becoming increasingly important for systematically identifying cyber risks. Manufacturers, in particular, are often still in the early stages in this regard and first need to develop an appropriate understanding.

The shift from cybersecurity being a “nice-to-have” to a mandatory requirement was also discussed. Prof. Dr. Chiara Manfletti described this shift as an ongoing process in which it is crucial to take security requirements into account as early as the initial stages of development. Kiesling added that this requires a fundamental shift in mindset, moving away from isolated risk assessments and toward integrated security analyses.

 

Another key focus was on the risks associated with complex system landscapes. According to Dr. Tobias Kiesling, this ultimately amounts to a classic engineering task: systems and their interactions must be modeled and analyzed step by step. Rather than attempting to grasp the entire complexity at once, he said, it makes sense to start with individual scenarios and points of vulnerability and draw conclusions from them.

Prof. Dr. Chiara Manfletti emphasized that increasing complexity and the growing convergence of technologies form a continuous cycle. Attackers are constantly evolving their tactics. This is a situation that requires constant vigilance.

 

Regulatory developments such as the NIS 2 Directive were also discussed. Andreas Krüger noted that many organizations continue to operate in a strongly compliance-driven manner. At the same time, however, a trend toward more proactively driven security measures is evident. Companies are increasingly coming to understand how important confidentiality, integrity, and availability are even at the architectural level. For certified systems, security is highly context-dependent. Andreas Krüger made it clear that, given enough time, any system could in principle be compromised. Often, the actual attack surface lies not in the certified core system itself, but in interfaces or network access points.

Following the discussion, representatives from academia, industry, and small and medium-sized enterprises took the opportunity to network. During the event, Prof. Dr. Corinna Schmitt presented the activities of the CODE Research Institute in the field of cybersecurity, as well as the work of her group, Secure Communication Systems (SeCoSys), in the areas of secure multi-domain operations, aeronautics, and secure decentralized data storage. She also promoted the initiatives launched by the National Coordination Center for Cybersecurity Germany (NKCS) to strengthen the German cybersecurity community and gathered valuable information about research areas in aeronautics.

The meetup clearly demonstrated that integrating safety and cybersecurity approaches is one of the key challenges facing modern technical systems. Especially in highly critical fields such as aerospace, a joint risk assessment is becoming increasingly indispensable.

 

 

Photos: © SeCoSys/Schmitt