Stefan Schwindt

Stefan Schwindt

  • Senior Principal – Aerospace Cyber Security
  • GE Aerospace

Stefan Schwindt is a Senior Principal for Aviation Cybersecurity within GE Aerospace. He holds the role of Chair of AIA’s Civil Aviation Cybersecurity Subcommittee, ICCAIA member representative to ICAO’s Cybersecurity Panel, participation in other global industry groups and leads or participates in most cybersecurity standards committees. In these roles, he works with global stakeholders on establishing a regulatory framework and associated standards suitable and appropriate for the aviation industry. He is also involved in a variety of industry research programs. Within GE, he supports the organizational and product security strategy and helps to ensure that the GE Aerospace businesses and their product lines are secure and resilient.

In addition to managing cybersecurity risks, Stefan is involved in EASA’s Rulemaking Task 0742 for ensuring safe integration of Artificial Intelligence and Machine Learning in aviation. In order to further this topic, he initiated a new subcommittee at AIA with other member companies.

In over 15 years of industry experience, Stefan Schwindt has worked in multiple functions. This includes reliability and safety engineering, environmental engineering, system engineering and certification before his current function in production security. He has worked at multiple tiers from hardware and software suppliers to type certificate holders. The products include civil and military aerospace and additionally ground and sea military assets.

Stefan’s academic background begins with a Masters in Aerospace Engineering followed by a doctorate in impact engineering researching resilience against birdstrike. He has concluded his studies with an Executive MBA. Stefan has also been recognized as a Fellow of the Royal Aeronautical Society.

Sessions

  • Cybersecurity in the Testing Environment

    Aeronautical Systems Security

    Cybersecurity requirements are now integral to the verification and validation (V&V) process for avionics and embedded systems, driven by mandatory compliance with DO-326A / ED-202A series under EASA Part 21 and FAA Special Conditions for connected systems. With increased network exposure (e.g., ACARS, ADS-B, SWIM, onboard Wi-Fi), system-level cybersecurity testing is prioritized alongside traditional safety assessments. Key activities such as threat modeling, penetration testing, secure boot validation, and verification of isolation in mixed-criticality environments provide unique challenges. How does the industry focus on tooling and methodologies that support combined safety and security certification—positioning cybersecurity as a top priority?