New BSI IT-Grundschutz profile strengthens the cyber resilience of drone systems

21 May 2026

With the publication of the new document „IT-Grundschutzprofil für den Betrieb von UAS Band 2: UAS-Betriebskategorie „Specific (Speziell)““ (engl. “IT-Grundschutz Profile for the Operation of UAS - Volume 2: UAS Operational Category ‘Specific’”), the Federal Office for Information Security (BSI) has set an important milestone for the safe use of unmanned aircraft systems (UAS). The profile specifically addresses security and resilience requirements for professional drone applications and supplements the previously published recommendations for the “Open” operational category.

The new baseline protection profile responds to the increasing digitalization and networking of modern drone systems. In addition to traditional flight safety issues, the focus is particularly on cyberattacks, manipulation of communication links, data protection, and the security of ground stations and control systems. Robust security architectures are becoming increasingly important, particularly in critical infrastructure operations, government applications, or autonomous UAS operations. Studies show that UAS systems are particularly vulnerable to GPS spoofing, radio manipulation, or attacks on communication interfaces. 

Prof. Dr. Corinna Schmitt contributed to the development of the document. She has been actively involved in the UAV DACH Competence Group “Safety & Security” for several years, where she contributes her research expertise in secure communication, aviation cybersecurity, and resilient UAS infrastructures. The work within the UAV DACH Competence Group “IT Safety & Security” aims to establish practical safety standards for industry, government agencies, and operators. The published profile serves as a concrete guide for organizations in implementing information security in UAS operations and simultaneously supports the harmonization of future European safety requirements.



Links:

IT-Grundschutzprofil für den Betrieb von UAS Band 2: UAS-Betriebskategorie „Specific (Speziell)“: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/Hilfsmittel/Profile/Profil_UAS_Band2.html (german only)

Further IT-Grundschutz Profiles: https://www.unibw.de/secosys/publikationen/standardisierung

UAV-DACH: https://uavdach.org/

 

 

 

Photo: © SeCoSys/Schmitt - generated with Chatgpt