Skip to main content

WORC2024 Conference Whitepaper: Rethinking Overflight Risk

Page 1

Rethinking Overflight Risk: A Whitepaper for the Aviation Industry Equipping Aviation Leaders with the Tools to Navigate Emerging Airspace Risk

PUBLISHED 05 JANUARY 2026

™ © WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com 1 DISCLAIMER: This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting do they necessarily endorse its conclusions. This whitepaper solely reflectsthis thedocument, views of thenor co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither

EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .


Contents Executive Summary .............................................................................................................................. 3 Introduction ........................................................................................................................................... 6 Methodology ......................................................................................................................................... 7 Authors .................................................................................................................................................. 8 Context .................................................................................................................................................. 9 Emerging Threats and the Changing Nature of Warfare ............................................................... 9 Barriers to Effective Information Sharing ....................................................................................... 9 The Shift from Reactive to Proactive ............................................................................................. 11 Primary Observations and Recommendations ................................................................................ 13 Fragmentation and a Lack of Standardisation in Overflight Risk Assessment. ......................... 13 Over-dependence on State-provided Intelligence ....................................................................... 16 The Limitations of State Regulator-Provided Intelligence and Notices. ................................. 16 Open-Source Intelligence ........................................................................................................... 19 Inefficient Manual Processes Hinder Effective Risk Monitoring.................................................. 21 Failure of the Risk Management Process .................................................................................. 21 Reactive, undocumented Decision-Making Increases Legal Vulnerability ................................. 23 The Risk of Unlimited Liability Under the Montreal Convention ............................................. 23 Conclusion ........................................................................................................................................... 25 Annex A. Definitions related to risk management ........................................................................... 26 Annex B. Risk Management Guidance – Definitions and Framework ............................................ 28 1.

Risk Management Definitions................................................................................................ 29 Other Commonly Used Terms ................................................................................................... 31

2. Risk Management Framework ................................................................................................... 32 2.1. Risk Management Process................................................................................................... 32 2.2. Risk Identification ................................................................................................................. 33 2.3. Risk Analysis.......................................................................................................................... 34 2.4. Risk Treatment ..................................................................................................................... 34 References........................................................................................................................................... 36

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

2


Executive Summary The World Overflight Risk Conference 2024 (WORC2024)—organised by Osprey Flight Solutions, the European Union Aviation Safety Agency, and the University of Southampton— brought together 249 key stakeholders from 45 countries. In a closed-door setting, aircraft operators, regulators, and insurers gathered to address the growing challenge of overflight risk near and over conflict zones, sharing new perspectives on this critical issue. At a particularly poignant time, the aviation industry faces an increasing number of disruptions due to geopolitical instability. This paper provides decision-makers with key insights into the skills and actions necessary to safeguard operations and ensure legal protection in an increasingly complex global risk environment. It also highlights the importance of equipping teams and adapting processes to effectively manage these growing challenges. WORC2024 was an immense success, with 96% of survey respondents reporting very high satisfaction and 100% expressing a desire for a future event. WORC2024 identified the following primary observations leading to a commensurate set of strategic recommendations:

Fragmentation and Lack of Standardisation in Overflight Risk Fragmentation and Lack of Standardisation in Overflight Risk Assessment Assessment

1

The current landscape of overflight risk management is marked by a lack of standardised terminology, inconsistent methodologies, and fragmented initiatives. This disjointed environment hampers efforts to develop a coherent and effective global strategy for mitigating airspace risks. The absence of a universally accepted lexicon and analytical framework undermines interoperability across national, regional, and organisational boundaries, impeding collective situational awareness and collaborative decision-making. Recommendation: A multilateral and cross-sectoral initiative should be established with the explicit goal of developing and adopting a standardised lexicon, shared methodological principles, and unified risk assessment protocols. Such an initiative should be hosted within or supported by relevant international regulatory bodies, with broad stakeholder participation from both state and non-state actors. Further Consideration: Efforts should also prioritise coordination among existing overflight risk platforms and working groups. Without deliberate integration, parallel initiatives risk duplicating efforts and producing conflicting outputs, thereby perpetuating ambiguity and inefficiency.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

3


2

Overdependence OverdependenceononState-Provided State-ProvidedIntelligence Intelligence

There is a prevailing over-reliance within the aviation sector on intelligence and threat assessments issued by state authorities. While governmental sources offer valuable insights, exclusive dependence on such channels may constrain the scope of risk analysis and lead to incomplete or delayed responses to emergent threats. Moreover, this reliance risks inhibiting the development of independent intelligence, analysis, and risk management competencies within the private sector, such as aircraft operators and insurers. Recommendation: The regulatory environment should support and encourage the professionalisation of overflight risk assessment by setting baseline competency, training, and experience requirements for practitioners. Rather than prescribing operational outcomes, regulatory frameworks should foster the development of robust, multi-source analysis processes that integrate state intelligence with commercial, academic, and open-source inputs.

3

Inefficiency InefficiencyofofManual ManualRisk RiskMonitoring MonitoringPractices Practices

Manual approaches to data collection, analysis, and dissemination remain prevalent in assessing overflight risk. These methods are inherently limited in their capacity to capture, process, and respond to large-scale and rapidly evolving datasets. As a result, risk detection and mitigation often occur only after hazardous conditions have materialised, reducing the effectiveness of protective measures. Recommendation: The aviation sector should explore scalable and efficient data management frameworks that support real-time or near-real-time threat detection and response. Emphasis should be placed on developing interoperable systems that can synthesise data from diverse sources, flag anomalies, and support dynamic risk modelling. While technology adoption is central to this transformation, institutional and procedural readiness are equally important components of successful implementation.

4

Reactive, undocumented Undermines Decision-Making Legal Vulnerability Lack of Documentation LegalIncreases and Regulatory Defensibility

In the current operational environment, decisions regarding overflight risk are frequently made in an ad hoc or undocumented manner. This lack of traceability can expose operators to legal liability, particularly under international frameworks such as the Montreal Convention. In the absence of verifiable records detailing the rationale behind overflight decisions, operators may be judged negligent in the aftermath of an incident.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

4


Recommendation: Policy frameworks should be developed to incentivise the formal documentation of risk assessment and decision-making processes. These frameworks should offer regulatory and legal protections to operators who demonstrate due diligence through transparent, evidence-based procedures. The goal is to foster a culture of accountability while enabling proactive and independently informed risk management.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

5


Introduction The World Overflight Risk Conference 2024 (WORC2024) organised by Osprey Flight Solutions, the European Union Aviation Safety Agency, and the University of Southampton, took place in Warsaw from 2 to 4 July 2024. This inaugural educational event provided a platform for the global aviation community to collectively address and navigate the dynamic challenges posed by overflight risk. Regulators, aircraft operators, and insurers gathered to discuss overflight risk, to gain greater mutual understanding and break down silos across and within sectors. The event attracted 249 attendees from 45 countries – including 75 Operators, 37 Governments, and 11 Insurers – who were educated on current risk management approaches, existing gaps, and informed about emerging threats and available technological solutions. The poignant timing and criticality of the conference, being so close to the 10th anniversary of the tragic misidentification and shootdown of Malaysian Airlines Flight MH17 and just a matter of days after the judgment in a civil lawsuit relating to the tragedy of Ukrainian International Airlines flight PS752, have since been further demonstrated with the events of the last few months. In December 2024, Azerbaijan Airlines flight J2-8243 crashed whilst attempting to land at Aktau airport in Kazakhstan. All indications point to a misidentification and shootdown by military air defence forces. This accident occurred just two months after a major global air traffic disruption on 1 October 2024, caused by a missile attack by Iran on Israel. According to FlightRadar24, more than 80 flights were diverted away from the affected airspace for refuelling and rerouting through non-involved countries, to avoid the risk of misidentification or being shot down over or near the conflict zone. When Israel launched a strike on Iran during the night between 12 and 13 June 2025, resulting in the closure of airspace over Iran, Iraq, Jordan, Syria, and Israel, approximately 3,000 flights were affected each day through cancellations or rerouting. In the context of another likely misidentification and shootdown event, as well as the significant disruption caused by severe overflight risk, the relevance of WORC2024 and the need for continued discussions on the risks faced by aircraft operating in airspace where an air defence threat exists are clear. WORC2024 was an immense success, with 96% of survey respondents reporting very high satisfaction and 100% expressing a desire for a future event. Feedback showed that the content was highly relevant to delegates’ roles, and the quality of the speakers was extremely high. The event was considered a significant step forward for industry efforts, providing knowledge and tools that participants have already begun to utilise.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

6


Methodology Ahead of the conference, detailed research and planning sessions were conducted with aviation industry leaders—specifically in overflight risk—as well as with defence and risk management experts. These discussions focused on identifying key gaps in overflight risk management and emerging threats. This preparatory stage was critical in shaping the panel topics and ensuring the relevance of the issues addressed during the conference. During the conference, qualitative data was gathered through a series of presentations, panel discussions, and interactive Q&A sessions. Speakers, distinguished experts in aviation safety and security, risk management and defence, provided valuable insights. At the same time, audience engagement through real-time discussions and feedback further enriched the depth of the data. The participants represented a broad and diverse group, all of whom play key roles in overflight risk decision-making within their respective organisations, ensuring that the discussions were both highly relevant and practically applicable. WORC2024 was conducted as a closed-door event to provide an optimal environment for open and honest dialogue among participants. Recognising that the sources of overflight risk are often tied to conflict and geopolitical events, which are typically highly political and emotionally charged, discussions needed to remain strictly non-political. The conference focused only on operational and technical challenges and solutions relevant to the aviation industry. To ensure neutrality and avoid conflicts of interest, regulators and operators from the same country were not included in the same panels. This approach was designed to facilitate objective and solution-focused discussions. This combination of pre-conference research and real-time, honest, and objective discussions at the conference enabled a well-rounded collection of expert opinions and qualitative insights, which form the foundation of the whitepaper’s findings and recommendations.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

7


Authors Andrew Nicholson Andrew is CEO and co-founder of Osprey Flight Solutions. A former UK Royal Navy officer, he served six years with Special Forces, with deployments across global conflict zones. After leaving the military, he led security operations in the maritime and energy sectors, helping to shape international standards for human rights in security risk management. He founded Osprey to transform aviation security through data-led, technology-driven solutions.

Matthew Borie Matthew is Chief Intelligence Officer and co-founder of Osprey Flight Solutions. He brings over 15 years of experience in aviation intelligence, including roles with MedAire and Control Risks. A former US Air Force Operations Intelligence Craftsman, he supported global combat missions and deployments. Matt holds advanced degrees in Intelligence and National Security Studies, specialising in aviation threat analysis.

Stanislav Bukhman Stanislav is Head of Risk at Osprey Flight Solutions, responsible for designing and delivering risk management methodology and guidance to support Osprey’s clients across commercial aviation, business aviation, and government sectors. Prior to joining Osprey, Stanislav served as the Group Head of Safety, Security, and Compliance at one of Europe’s largest airlines. He is also engaged in PhD research at the University of Southampton, focusing on overflight risk management.

Tatevik Revazian Tatevik Revazian is Senior Vice President at Osprey Flight Solutions and the lead author of this whitepaper. She played a pivotal role in shaping and delivering the World Overflight Risk Conference. Previously, she served as Director General of Armenia’s Civil Aviation Committee, where she led the country’s civil aviation response during the 44-day war between Nagorno-Karabakh and Azerbaijan. The Integrated EU Aviation Risk Assessment Group concluded that Armenian authorities were actively and effectively managing regional risks to civil aviation.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

8


Context Overflight Risk and its management is a complex and dynamic subject. In the last 10 years, since the MH-17 tragedy, the environment has changed immeasurably. New and emerging threats such as the dramatic increase in autonomy and the use of Remotely Piloted Air Systems (RPAS), commonly known as drones or UAVs, the democratisation of more powerful and capable weapon systems that can target aircraft at cruising altitude, historically the purview of state actors alone, and the dramatic increase in the use of regulatory mechanisms designed to ensure safety of flight as a political tool comprise the context within which operators have to make operational decisions that have significant implications commercially, operationally and for the protection of life.

Emerging Threats and the Changing Nature of Warfare The challenge facing operators that operate in higher risk environments is becoming even more difficult as the aviation industry must consider dynamically evolving emerging threats such as GNSS jamming and spoofing, UAVs/drones, Military-Grade Weaponised Drones, Loitering Air-Defence Weapons (which combine the portability of a MANPADS with the capability of a conventional SAM system), and continuing MANPADS proliferation, particularly of more advanced variants. At WORC2024, it was discussed that in the coming years, the accessibility to low-cost, weaponised drones will increase exponentially, and the capabilities of weapon systems in general will improve, allowing them to operate larger weapons at longer ranges and at higher altitudes. These advancements will significantly enhance their operational effectiveness, making it exceedingly difficult to defend against such threats while maintaining proper civil-military deconfliction and posing new challenges to managing overflight risk. Furthermore, at WORC2024, the wider aviation industry was encouraged to consider the implications of a potential detonation of a small tactical nuclear device. The likelihood of such an event has never been greater in the current geopolitical climate. If a nuclear device were detonated, all aviation insurance policies would be subject to automatic termination, effectively and immediately grounding global aviation. This dynamic is not well understood and requires work by the insurance industry, in collaboration with aircraft operators and regulators, to resolve. Significant progress has been made, for example, through the Gallagher Insurance initiative for replacement cover; however, a wider understanding and implementation are still needed. It is crucial to monitor these dynamic developments as they can significantly alter the risk environment in which civilian aircraft operate.

Barriers to Effective Information Sharing Over the past decade, since the downing of MH17, overflight risk management has undergone significant improvements. Before the MH17 incident, there was no consensus on how to handle overflight risks and sharing information on conflict zones was not a standard practice among operators and states. However, today, sharing such information has become a fundamental practice in airline operations and in how states collaborate. ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

9


Led by Transport Canada, the Safer Skies Consultative Committee has introduced baseline information calls to facilitate the exchange of information between states, international organisations, and the aviation industry during crises, ensuring a coordinated and informed response to emerging threats. At the EU level, significant progress has been made in establishing the fully operational EU Conflict Zone Alerting System, led by the European Commission. This system, shared with member states and European aircraft operators, has significantly enhanced the safety and security of aviation operations over and near conflict zones. Despite significant improvements in information sharing, WORC2024 highlighted persistent gaps that still exist today. For instance, there remains a need to better understand why some aircraft operators choose to fly to certain destinations while others do not. This includes examining the specific mitigation measures that some operators employ, which others do not, acknowledging that these measures are highly operation-specific and may be effective for one but not for another. Understanding the factors influencing decision-making can help identify the reasons behind these differences. While no airline is obligated to share its risk assessments and mitigation measures, some choose to do so, especially within their alliances. However, limitations exist on what information can be shared, making it crucial to distinguish between data that impacts commercial interests and information related purely to overflight risks. Greater clarity is needed to understand which types of information are typically withheld and how this might affect overflight risk management. Additionally, information sharing is often reciprocal, and certain operators within an alliance may hesitate to share if the other party is state-owned or does not reciprocate by providing their own information. A similar situation exists among EU Member States. If one state withholds information, it is unlikely to receive all available data in return. Also, aviation authorities often do not receive overflight risk details from their own intelligence services due to classification restrictions. Finally, intelligence sharing between the military, national security agencies, and aviation authorities frequently faces approval challenges. As a result, even when Member States are willing to share, the issue may stem from their lack of access to critical information. At WORC2024, it was also discussed whether there are liability issues in sharing information between aircraft operators. Although no lawyers responded to this question, the aircraft operators, states, and insurance providers did not see any major obstacles in sharing information. They noted that information is often shared through informal channels, facilitating communication and collaboration without significant legal concerns. During one of the Q&A sessions at WORC2024, a topic emerged that had not been part of the original agenda. One group of attendees emphasised the importance of transparent and timely sharing of intelligence with the pilot in command, who holds ultimate responsibility for the flight and the safety of passengers. Another group questioned whether informing the crew about risk assessments that fall outside their expertise was necessary, as it might lead to reluctance to operate certain flights. A growing concern is that crew members are often

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

10


exposed to news reports without a complete understanding of global risk levels. There have been instances where crew members were willing to fly to higher-risk zones but hesitant to operate flights in lower-risk areas. It is crucial to reference ICAO Annex 6, which clearly states the requirement to inform the pilot in command, who is responsible for the safe conduct of the flight: “During the preparation of flights with a high degree of risk, before departure, aviation security service personnel must inform the flight crew about the specifics of the flight and point out issues that require increased attention from the crew. This includes the presence of military equipment directly at the airport or nearby territory, and any information on military activities in the flight region”. This highlights another key finding from WORC2024: the need to train the aviation industry in understanding relevant ICAO annexes, specifically those covering overflight risk, as well as Doc 10084, the Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones. One key takeaway from the discussion was the need to rebuild trust between pilots and the management teams responsible for conducting risk assessments, particularly in light of past incidents. Moving forward, future WORC conferences or overflight risk-related events may need to explore how internal silos within airlines can be broken down to better involve pilots in overflight risk management decisions. This should include transparent, timely intelligence sharing to foster trust and informed decision-making. However, no matter how laudable industry efforts to share information are, or how collegiate and collaborative they are, a key foundation is missing, which undermines their effectiveness. The industry lacks a consistent, standardised language or framework for understanding the information being shared. A consistent and standardised lexicon is essential for effective information sharing across the aviation sector, particularly when assessing and communicating the risks associated with operating flights over or near conflict zones. Currently, variations in terminology—such as differing interpretations of terms like “threat” or “risk”, as well as “LOW”, “HIGH” or “EXTREME” – can lead to ambiguity, miscommunication, and inconsistent decisionmaking among airlines, regulators, and insurers. Establishing a common language would ensure that all stakeholders uniformly interpret risk-related information, enabling clearer assessments, more timely responses, and aligned expectations across jurisdictions. It would also enhance data comparability, support collaborative risk evaluations, and reduce the potential of legal and operational disputes. For insurers, a standardised lexicon would provide greater clarity in policy interpretation and risk categorisation, while for operators and regulators, it would underpin transparent, coordinated actions. Ultimately, a shared vocabulary forms the foundation for building trust, improving safety outcomes, and strengthening resilience across the global aviation ecosystem.

The Shift from Reactive to Proactive The persistent volatility of the geopolitical landscape presents a critical challenge to the safety and stability of international civil aviation. In particular, the management of overflight risk has become increasingly complex due to the emergence of unpredictable conflict zones and shifting state-level security dynamics. Historically, the aviation industry has adopted a reactive posture, ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

11


adjusting airspace use only after threats have materialised. However, the limitations of this approach have become increasingly evident, necessitating a transition toward a more proactive model of risk management. Proactive risk management involves the systematic identification and anticipation of potential threats, enabling informed decision-making before operational disruptions occur. In the context of overflight, this means continuously monitoring political developments, assessing potential airspace volatility, and integrating these assessments into dynamic route planning. The benefits of such an approach extend beyond enhanced safety; it also supports operational efficiency and continuity, reduces exposure to legal liabilities, and improves confidence among both operators and passengers. Modern technology enables near real-time and even predictive risk assessments, improving both the accuracy and timeliness of decision-making. Importantly, however, the shift to proactive risk management is not solely dependent on technological advancements, though such tools can and must play an integral role. Instead, the foundation of proactive risk management lies in organisational and institutional change. Events such as WORC2024 have highlighted growing recognition within the industry of the need for this transition. Yet for proactive risk management to be fully realised, there must be a sustained commitment to collaborative frameworks, open data sharing practices, and the integration of strategic foresight into regulatory and operational processes. Only through such systemic change can the aviation sector build resilience in the face of an increasingly uncertain global environment.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

12


Primary Observations and Recommendations Fragmentation and a Lack of Standardisation in Overflight Risk Fragmentation and Lack of Standardisation in Overflight Risk Assessment Assessment.

1

 The current landscape of overflight risk management is marked by a lack of standardised terminology, inconsistent methodologies, and fragmented initiatives. This disjointed environment hampers efforts to develop a coherent and effective global strategy for mitigating airspace risks. The absence of a universally accepted lexicon and analytic framework undermines interoperability across national, regional, and organisational boundaries, impeding collective situational awareness and collaborative decision-making.  Standardisation and consistency of terminology, methodologies and data exchange would improve understanding between operators, regulators and insurers, and the effectiveness of training and information sharing efforts globally.  ICAO Doc10084 represents a valuable starting point; however, effective global implementation and ongoing refinement through further iterations are essential to ensure the improvement.  Multiple initiatives have been developed, sometimes in complete isolation, that are laudably intended to further the discussion on overflight risk management. However, a lack of coordination between these initiatives injects further inconsistency and ambiguity for the operators that need cohesive advice and support. While risk management frameworks are widely adopted across the aviation sector, they still have a notable lack of consistency in how key concepts – such as risk, threat and vulnerability – are defined by key stakeholder organisations, including ICAO and IATA. Across ICAO and IATA documents, the term 'risk' is frequently used in various contexts; however, a formal definition is generally absent – except in the case of 'safety risk,' which is defined as: The projected severity and likelihood of any adverse consequence(s) or outcome(s) from or

associated with an existing hazard. A projected outcome could be an accident, but an intermediate unsafe event or consequence might be identified as the most credible outcome [IATA Reference Manual for Audit Programs]. the predicted probability and severity of the consequences or outcomes of a hazard [ICAO

Doc 9859, Safety Management Manual] Sources from industry, business, and academic literature provide additional perspectives on risk.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

13


the effect of uncertainty on objectives [ISO 31000:2018 Risk management — Guidelines]

the potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organisation [ISO/IEC 27005:2022 – Information Security Risk Management] a function of the likelihood of a given threat-source’s exercising a particular potential

vulnerability and the resulting impact of that adverse event on the organisation [NIST SP 80030 Rev. 1 – Guide for Conducting Risk Assessments] the possibility that events will occur and affect the achievement of strategy and business

objectives [COSO ERM – Enterprise Risk Management] combination of the probability of an event and its consequence. Consequences can range

from positive to negative [Institute of Risk Management] the uncertainty of an event occurring that could have an impact on the achievement of the

objectives. Risk is measured in terms of consequences and likelihood [Institute of Internal Auditors] the effect of uncertainty on objectives. Risk is usually expressed in terms of causes, potential

events, and their consequences [HM Government: The Orange Book. Management of Risk – Principles and Concepts 20201] the probability and magnitude of a loss, disaster, or other undesirable event [Douglas

Hubbard, The Failure of Risk Management] The above comparison reveals common elements across the various definitions, including concepts such as Uncertainty (Risk arises from unknown or unpredictable events), Likelihood (probability of an event), Impact (consequence or severity of the outcome), Objectives (organisational goals), Threats and Vulnerabilities. Each industry tends to define risk in relation to the specific events and contexts relevant to its domain. The difference and inconsistency in the definition and communication of risk can become a contributing factor in aviation incidents involving the misidentification and downing of civil aircraft. The disaster of Azal Airlines flight 8243 illustrates this point: the airspace over Grozny was not officially designated as high-risk by either Russian authorities (who controlled the airspace) or by Azerbaijan (the state of the operator). While several international regulators issued warnings regarding the broader region, these advisories were generally vague – some prohibited their carriers from flying over areas adjacent to the conflict zone, such as the Rostov FIR, which did not cover the location where the incident occurred, while others offered nonbinding recommendations. At the same time, several airlines had already ceased operations in Russian airspace due to sanctions or insurance constraints. This created a fragmented operational picture in which those carriers that continued to operate may have become desensitised to generic and geographically imprecise warnings. Meanwhile, commercially available threat intelligence had issued a clear and specific warning seven days before the incident. This advisory precisely identified the affected airspace as high risk, specified misidentification as the likely threat scenario, assessed the overall likelihood, and even highlighted the time of day when the likelihood was exceptionally high.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

14


To support greater clarity and consistency in risk management practices across the aviation sector, international agencies and industry associations should consider revising and harmonising the definitions of key terms such as risk, hazard, threat, vulnerability, and risk tolerance. A comprehensive review of commonly used definitions is provided in Annex A. The following information was gathered from discussions and presentations at WORC2024, as well as an extensive review of all industry guidance and best-practice documentation. A proposition for a more standardised lexicon and risk management framework is presented in Annex B. Despite significant efforts by industry bodies, states, and international organisations to improve the understanding and application of risk management for flights over or near conflict zones, the landscape remains fragmented. Numerous commendable initiatives have emerged, each contributing valuable perspectives, tools, and frameworks. These include: •

The Safer Skies Consultative Committee (SSCC)

The Safer Skies Forum (SSF)

EASA European Information Sharing and Cooperation Platform on Conflict Zones

ICAO Doc 10084: Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones

ICAO Regional Workshops on Conflict Zone Risk Management

IATA Airspace Risk Management Training

IATA AVSEC Insights

European Group on Risk of Conflict Zones (EGRICZ)

The World Overflight Risk Conference (WORCTM)

While these efforts reflect a shared commitment to improving aviation safety, the lack of formal coordination between them can inadvertently lead to increased inconsistency, overlapping scopes, differing methodologies, and varying terminologies, which risk creating confusion rather than clarity. This fractured environment may hinder operators, regulators, and insurers from effectively aligning risk assessments and operational decisions, potentially exacerbating misunderstandings during crises. Greater coordination between these initiatives—through shared platforms, harmonised guidance, and structured collaboration—would not only reduce duplication but also foster a more coherent global strategy. Such integration would accelerate the collective objective of safer skies by enhancing interoperability, information exchange, and mutual understanding across the aviation risk management ecosystem. Recommendation: Led by ICAO and IATA, a multilateral and cross-sectoral initiative should be established with the explicit goal of developing and adopting a standardised lexicon, shared methodological principles, and unified risk assessment protocols. Such an initiative should be hosted within or supported by relevant international regulatory bodies, with broad stakeholder participation from all sub-sectors, including operators, regulators, and subject-matter experts.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

15


Further Consideration: Efforts should also prioritise coordination among existing overflight risk platforms and working groups. Without deliberate integration, parallel initiatives risk duplicating efforts and producing conflicting outputs, thereby perpetuating ambiguity and inefficiency. In support of this, the organisers of WORCTM have engaged with ICAO, EASA, SSCC, EGRICZ and others prior to the presentation of future conferences to ensure coordination and harmonisation.

2

Over-dependence State-provided Intelligence Overdependence onon State-Provided Intelligence

 There is a prevailing over-reliance within the aviation sector on intelligence and threat assessments issued by state authorities. While governmental sources offer valuable insights, exclusive dependence on such channels may constrain the scope of risk analysis and lead to incomplete or delayed responses to emergent threats. Moreover, this reliance can hinder the development of independent analytical competencies within the private sector, such as among aircraft operators and insurers.  It was agreed that, because of its nature and intrinsic limitations, including timely availability, State information, intelligence or formal notices should not be used as the sole source of overflight risk information to inform overflight risk analysis and risk management. Open airspace does not mean safe airspace.  Highly effective information, once accessible only to a selected few due to classification, is now more widely available. Adoption of open-source Intelligence, enhanced where possible with classified information, is essential to maximise accuracy and timeliness of information received on overflight risk.

The Limitations of State Regulator-Provided Intelligence and Notices. As discussed, states publish notices that may include advisories and prohibitions for specific areas of airspace, based on the state’s assessment of the overflight risk in that airspace. During WORC2024, a concerning situation was highlighted based on the following question: ‘If a state does not publish a prohibition or advisory for a specific area of airspace, does that mean there is no risk within that airspace?’ Of course, the answer to that question is no, but examples of operational decision-making suggest that many operators do not understand this premise. The shootdown of Azerbaijan Airlines Flight 8243 is one tragic example. Additionally, during the recent escalation between India and Pakistan, only one regulator issued an advisory recommending the complete avoidance of Pakistani airspace at all altitudes – two days after the conflict had already begun. Two additional regulators advised their operators to avoid flying below FL260, although both sides employed conventional surface-to-air missiles capable of endangering aircraft at all altitudes. No other regulators issued any guidance, and several airlines continued operating near the conflict zones throughout the escalation. ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

16


The ability of a state to have a comprehensive worldview on overflight risk and to publish that view through advisories and prohibitions is limited for several reasons. Firstly, there is the simple matter of exposure. A state regulator’s responsibility is limited to the operators it regulates, including any codeshares carried by operators in other states. If none of those operators conduct flights in a particular region of the world or a particular piece of airspace, then there is no exposure for that state, and therefore, there is no reason for the regulator to publish a prohibition or advisory. This does not mean there is no overflight risk in that airspace. Secondly, it is the regulator’s role to publish notices relating to overflight risk, which therefore relies on the regulator's access to intelligence to inform that process. Much government- and military-produced overflight risk-related intelligence has traditionally been classified by states, and ICAO guidelines have been largely restricted. Classified information is data deemed sensitive enough by a government or organisation to require protection against unauthorised disclosure. Access to such information is restricted to individuals who have the necessary security clearance and a legitimate need-to-know basis to perform their duties. At WORC2024, it became clear that aviation authorities worldwide face significant challenges in accessing overflight risk-related information from their national security and military intelligence agencies. This issue arises due to two main factors: either aviation authorities lack the necessary security clearance to access such data, or the agencies themselves are unaware of which information is relevant to share with aviation officials. In cases where information is shared, it is often not specific to aviation and requires further assessment. Even after this assessment, the information may still lack the operational specifics needed by aircraft operators. As a result, aviation authorities are unable to provide a comprehensive picture that addresses the specific operational needs of aircraft operators. Thirdly, the conflict of interest of ‘host’ states. At WORC2024, it was highlighted that countries in conflict facing overflight risks rarely restrict their own airspace, despite clear ICAO requirements to report such risks through the NOTAM system. ICAO Doc 10084 outlines states' responsibility to assess threats to civil aviation within their territory and airspace, take appropriate action, and inform relevant stakeholders in a timely manner if restrictions are necessary. Governments may hesitate to disclose information about threats in their airspace due to logistical, political, or commercial interests. In some cases, the state itself may be responsible for activities such as Global Navigation Satellite System (GNSS) interference, drone usage, or the deployment of ballistic missiles, which pose risks to civil aviation. This creates a conflict of interest, as states have different priorities and perspectives. These pressures can limit transparency from a safety and security standpoint, especially when aviation authorities lack the mandate to publish information without approval from other state bodies. As a result, warnings may be delayed or absent, and the state’s risk appetite may be affected.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

17


Finally, there is the inherent political nature of governments and, therefore, state organisations such as aviation authorities. The industry should neither dismiss nor hesitate to accept this; it is the necessary function of all governments to further their country's political objectives. This is exactly what citizens of a country need their government organisations to be and do. Diplomatic relationships with other countries are a crucial component of this, and they must be considered when drafting notices that may affect operators' decision-making regarding airspace operations. An airspace prohibition can have significant political and economic implications for any country and will inevitably affect diplomatic relationships with a state imposing such a prohibition. Whilst this is an important function of a government, it is not conducive to objective, apolitical or timely risk analysis. The above dynamics can cause a state authority to refrain from publishing an advisory or prohibition, even when a significant overflight risk exists, leading to the dangerous misconception that airspace is safe if no government warnings or restrictions are issued. A key takeaway from the presentation by Joe Fiorante of CFM lawyers on the downing of Ukraine International Airlines Flight 752 in Iran was the importance of recognising that the absence of state-issued information or prohibitions does not necessarily mean the airspace is safe. Instead, it often indicates that information is incomplete or unavailable. Even in the best-case scenario, when globally recognised authorities are involved, the process of collecting classified information is often slow and lacks agility, making it difficult for aircraft operators to receive timely data. This was already the case with the downing of PS752 over Iran: at the time of the incident, only one state-issued warning had been published – approximately 2 hours and 40 minutes before the incident. Four additional regulators issued airspace prohibitions over Iran only three days after the shootdown. Additionally, aircraft operators frequently report confusion when leading Western authorities disagree on the global risk landscape. At WORC2024, it was clarified that while aviation authorities primarily assess safety and security, their final reports may be influenced by the political and commercial interests of their respective states. While governments can offer critical insights and context, their inherent limitations make overreliance on them risky, leaving aircraft operators, regulators, and insurers with significant gaps in their risk identification and response. This can result in reacting to risks rather than proactively managing them. Aircraft operators should avoid using state-provided information as the sole basis for their intelligence gathering and overflight risk management. Instead, integrating classified data and state-provided information with near real-time open-source intelligence can significantly improve the timeliness and accuracy of overflight risk assessments, offering a more comprehensive and proactive approach to managing threats. The industry-wide gap in the aviation sector, characterised by a predominantly reactive approach, became particularly evident during WORC2024 discussions on reopening previously restricted airspace. Unsafe airspace can be misperceived as safe. Conversely, outdated airspace restrictions issued by states, operators, or insurers outside of a conflict territory can lead to misperceptions, resulting in safe airspace being mistakenly considered unsafe. ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

18


Throughout multiple sessions, it was observed that states and aircraft operators find it relatively easy to issue airspace restrictions when a conflict occurs outside their own territory. However, when the conflict is within their country, there is often a reluctance to impose similar restrictions—largely because foreign operators and states rarely lift prohibitions dynamically. This creates a disincentive for conflict-affected states to issue formal NOTAMs, as doing so could result in prolonged closures and limited traffic recovery, even after the immediate threat has subsided. The absence of dynamic, data-driven de-escalation mechanisms has far-reaching consequences. Even when the immediate threat has passed, restoring pre-conflict traffic volumes and rebuilding trust with foreign aircraft operators and governments can be a lengthy process. The resulting impact can be significant: •

For ANSPs/Governments affected by conflict: operational disruptions, logistical challenges, economic impact, and long-term reputational damage.

For foreign operators: operational disruptions, increased fuel burn, unnecessary CO₂ emissions, and delays in resuming profitable routes.

Due to the system's lack of dynamism, affected states may choose to avoid issuing a formal NOTAM and instead temporarily restrict certain segments of airspace in coordination with neighbouring Air Navigation Service Providers (ANSPs), redirecting traffic to maintain safety. However, this approach is far from optimal, as its effectiveness depends heavily on the political context and the strength of human relationships between regional actors. At WORC2024, several underlying factors were identified to explain the lack of dynamism. Foreign authorities publishing advisories outside their own territory may lack awareness of improvements in airspace conditions or overlook changes because the impact of their advisory is not a priority. Since issuing the advisory carries no direct cost, and the state may not have significant commercial or political interests in the region, there is little incentive to reassess the situation. Additionally, if their aircraft operators have little presence in the area, regulators may face minimal pushback, especially compared to situations with higher commercial stakes.

Open-Source Intelligence In proactive risk management and, indeed, in all intelligence collection capabilities, OpenSource Intelligence (OSINT) has become the dominant source of information for situational awareness. OSINT refers to the process of collecting, analysing, and interpreting publicly available and legally accessible information. Publicly available information can be either free of charge or accessed for a fee and is derived from a variety of sources, including traditional media, social media, ADS-B data, satellite imagery, and much more. At WORC2024, Air Marshal Johnny Stringer, Deputy Commander, NATO Allied Air Command, shared that “sensitive information, previously limited to a select few, is now widely available”. This marks a significant shift in managing overflight risk, as data on topics such as weapon types, which were once accessible to only a few individuals, is now widely available. Today, ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

19


detailed photographs of weapons and related data are available online, and images play a crucial role as source material. This enables risk managers to assess the capabilities and geolocation of various weapons, thereby improving their evaluation of potential threats to aviation. OSINT has significantly increased the speed of information collection. By accessing and overlaying multiple sources, the validation process is greatly enhanced, improving accuracy. According to Matt Schroeder, Senior Researcher at Small Arms Survey, "any claims not supported by imagery (video or photo) are excluded from the Small Arms Survey's database on illicit MANPADS, as verifying key details such as make, model, or type of a weapon is often impossible without imagery”. That said, it is important to note that human capabilities are significantly limited when collecting, processing, analysing, and validating OSINT. The sheer volume of data generated daily from various sources, combined with the complexity of analysing diverse data types— ranging from text and images to videos and geospatial information—requires advanced analytical skills, technological development, and substantial time for proper validation. Manual collection, processing, and analysis are not only resource- and time-consuming but also prone to errors and human biases. Recommendation: Establish a regulatory framework that enables the professionalisation of overflight risk assessment. States should define baseline requirements for personnel competency, training, and experience for those conducting risk assessments for flights near and over conflict zones. The aviation industry must address a critical and often overlooked issue: the misalignment between political imperatives and operational decision-making. State authorities should not prescribe operational outcomes in airspace risk management, given the inherent limitations and potential biases in such approaches. Instead, States The National Civil Aviation Authority (CAA) — or the designated competent authority with responsibility for overflight risk — must develop the capability to perform adequate oversight over operator risk assessment processes. This includes, but is not limited to, assessing the quality and implementation of operators’ risk assessments, procedures, and risk mitigation strategies. Currently, a global gap exists in which many States lack clarity about which organisational entity holds functional responsibility for overseeing airspace risk related to operations over or near conflict zones. ICAO guidance remains ambiguous on this point, leading to inconsistent implementation and limited accountability. Clear designation of responsibility within the State framework is urgently needed. Once designated, the responsible authority must ensure that appropriately qualified personnel are trained and that policies and oversight mechanisms are developed to support continuous ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

20


monitoring, compliance, and improvement in airspace risk assessment practices.

3

Inefficient Manual Processes HinderPractices Effective Risk Monitoring Inefficiency of Manual Risk Monitoring

 Manual approaches to data collection, analysis, and dissemination remain prevalent in the assessment of overflight risk. These methods are inherently limited in their ability to capture, process, and respond to large-scale, fast-evolving datasets. As a result, risk detection and mitigation often occur only after hazardous conditions have materialised, reducing the effectiveness of protective measures.  The use of technology to manage the volume, speed and breadth of open-source intelligence is essential to ensure efficiency, scalability and accuracy.

Failure of the Risk Management Process While the importance of adopting OSINT has become more widely recognised within the aviation industry, current modes of data collection and processing remain largely manual, inhibiting near real-time monitoring, dynamic risk analysis and predictive intelligence. This situation persists despite the evident lack of capacity and resources within aviation security and operations teams to monitor the landscape continuously, 24/7, without implementing supporting technology. Previous sections of this paper have explored significant gaps in the timely and accurate gathering of intelligence, as well as the lack of proactive risk assessments in overflight risk management. However, the most significant risk may reside within the risk management process itself. Keynotes by Douglas Hubbard, inventor of the Applied Information Economics (AIE) method; Dr. Ahmad Altarawneh, now Partner at Crowe in the Pioneering & Excellence Sector; Mario Brito, Head of Decision Analytics & Risk at the University of Southampton, and their PhD researcher Stanislav Bukhman, highlighted the need to reassess the traditional risk assessment methods currently used in the aviation industry. According to Mr Hubbard, commonly used approaches, such as risk matrices, while widely adopted, lack a robust mathematical or scientific foundation. Although regulatory compliance remains a key component of risk management, its true effectiveness should be assessed by the extent to which it reduces or mitigates actual risk. Dr Altarawneh proposed expanding the traditional two-dimensional approach to risk assessments – based on likelihood and impact – by introducing a third dimension, so-called “risk velocity”, defined as the speed at which a risk event materialises. Stanislav Bukhman noted that the aviation industry’s use of risk matrices relies too heavily on expert opinion rather than on data-driven approaches, which can lead to potential bias and subjectivity. Despite access to large volumes of data, industry manuals provide limited guidance on effectively incorporating this data into the risk management process. Addressing the shortcomings of traditional methods, especially those based on human judgment, is crucial. Mr Hubbard noted that if a decision-maker were modelled as a computer, the model would consistently outperform the human, solely due to its consistency, a quality that human decision-makers inherently lack.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

21


The integration of advanced risk management methodologies with large datasets and nextgeneration technology enables analysts to provide near real-time intelligence, detect patterns and trends, and make accurate predictions. This allows aircraft operators to anticipate and respond to threats before they manifest. Recommendation: The aviation sector should explore scalable and efficient data management frameworks that support real-time or near-real-time threat detection and response. Emphasis should be placed on developing interoperable systems that can synthesise data from diverse sources, flag anomalies, and support dynamic risk modelling. While technology adoption is central to this transformation, institutional and procedural readiness are equally important components of successful implementation. Further Consideration: While ICAO’s Safety Management Manual (Doc 9859) has begun promoting the collection and processing of safety data to enable predictive modelling and support data-driven decisionmaking, this remains a recommended rather than mandatory approach. Traditionally, risk management processes, particularly in aviation security and conflict zone operations, have lacked systematic integration with data analytics. Yet, vast amounts of safety and security data are routinely collected by aircraft operators, regulatory authorities, and the private sector. If properly aggregated, processed, and analysed, this data can inform the selection of relevant variables for machine learning algorithms. These models can then be used to forecast security improvements or deteriorations, identify escalation and de-escalation patterns, and monitor shifts in overall risk levels in areas of operation. It is recommended that ICAO and national civil aviation authorities incorporate data-driven methodologies – particularly predictive analytics – into aviation security risk assessment frameworks and conflict zone guidance, which should include: •

Establishing basic requirements for safety and security data collection and processing;

Defining a common set of relevant variables for predictive modelling;

Promoting the use of machine learning to identify trends and anticipate changes in the threat environment; Encouraging collaboration between operators, regulators, third-party providers and

data science experts to ensure methodological robustness and operational relevance. Integrating predictive modelling into security decision-making will enhance the proactive management of emerging threats and support timely and evidence-based interventions.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

22


4

Reactive, undocumented Vulnerability

Decision-Making

Increases

Legal

Reactive, undocumented Decision-Making Increases Legal Vulnerability

 In the current operational environment, decisions regarding overflight risk are frequently made in an ad hoc or undocumented manner. This lack of traceability can expose operators to legal liability, particularly under international frameworks such as the Montreal Convention. In the absence of verifiable records detailing the rationale behind overflight decisions, operators may be judged negligent in the aftermath of an incident.  Failure by aircraft operators to independently and proactively assess risks, as well as to thoroughly document the entire risk assessment process and decision-making, may constitute negligence under the Montreal Convention and hinder learning from past experiences.  Outdated airspace restrictions published by States, aircraft operators, and insurance providers can cause safe airspace to be incorrectly perceived as unsafe.  Traditional risk assessment methods need to be reevaluated: in some cases, they can be a source of risk themselves, as they might not measure the effectiveness of risk management efforts.

The Risk of Unlimited Liability Under the Montreal Convention WORC2024 aimed to support the aviation industry in advancing overflight risk management by identifying gaps in current processes and exploring potential solutions to address them. In his keynote address, William Sandover, Aviation Security Adviser, illustrated the essence of risk management with a vivid analogy: being in a pub where bottles are either being thrown or could be thrown. The point, he argued, is not just reacting to risk but recognising early signs, assessing whether to stay, and ensuring mitigation is in place if you must. In risk management, the goal is simple: don’t get hit by the bottle. According to Annex 6, aircraft operators are required to ensure that flights over or near conflict zones do not commence unless risk assessments have been carried out by aircraft operators and appropriate mitigation measures are taken to guarantee the safety and security of the aircraft along the intended route. Traditionally, and still quite common today, aircraft operators rely heavily on guidance from regulators and governments to assess overflight risks, or, in other words, to determine whether there are 'bottles in the pub”. However, during the conference, Sylvain Lefoyer, Deputy Director of Aviation Security and Facilitation at the Air Transport Bureau of ICAO, highlighted that a "very limited number of states have the capability to conduct threat and risk assessments". This further underscores the critical importance of aircraft operators conducting independent risk assessments. In the "Open airspace does not mean safe airspace” section, it was highlighted that intelligence gathering from states is often insufficient, delayed, or influenced by political and commercial biases. Additionally, both the data collection and risk assessment processes are often manual and prone to errors. As a result, when risk assessments rely on flawed data and inefficient ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

23


manual processes, even with the best efforts, it becomes unrealistic for aircraft operators to conduct truly proactive risk assessments or make fully informed decisions. This presents a significant challenge, as aircraft operators may fail to meet the requirements of the Montreal Convention, leaving them vulnerable to negligence claims, as demonstrated in the case of PS752, which was shot down in Iran. Ukraine International Airlines was unable to prove that it was not negligent in allowing PS752 to depart Tehran on 8 January 2020, resulting in unlimited liability under the Montreal Convention. It is important to recognise that this is not an isolated incident affecting a single airline, but a broader issue facing the entire industry. The outcome of the PS752 court case highlights the increasing risks and liabilities for aircraft operators, underscoring the urgent need for the aviation industry to shift from reactive risk management to a more proactive approach. Another key takeaway was the importance of comprehensive documentation at every stage of the risk assessment process and decision-making in overflight risk. This is crucial for several reasons. Firstly, in the case of litigation, specific evidence of decisions made is indispensable. This documentation can demonstrate that decision-makers have a reasonable approach to understanding and managing risks. Additionally, as highlighted by WORC2024 speaker and leading risk management expert Doug Hubbard, learning from past experiences requires feedback, which is only possible when decisions and the decision-making processes are recorded. Without such documentation, there is a risk of retrospective bias, in which memories are adjusted to fit the conclusions already reached rather than objectively evaluating and learning from past actions. It is important to remember that in a rapidly escalating situation, documentation may not be top of mind for a decision-maker – yet it remains essential for legal protection and demonstrating that actions were justified, traceable, and accountable. Recommendation: Policy frameworks should be developed to incentivise the formal documentation of risk assessment and decision-making processes. These frameworks should offer regulatory and legal protections to operators who demonstrate due diligence through transparent, evidencebased procedures. The goal is to foster a culture of accountability while enabling proactive and independently informed risk management. For example, a requirement within the SeMS framework, IOSA and/or ICAO SARPs to demonstrate auditable records of decision-making in standardised formats would incentivise operators to implement such processes. It is unlikely that leaving this to national authorities would result in a consistent outcome.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

24


Conclusion The findings presented from WORC2024 underscore a fundamental truth: when the industry comes together in an open and collaborative forum, the potential for progress shifts from a mere possibility to an undeniable reality. By identifying the most critical gaps in overflight risk management and providing participants with actionable tools, the conference has sparked a wave of change that extends far beyond the event itself. While some challenges will require intervention from states, regulators, and international organisations, many urgent issues can—and should—be addressed directly by those responsible for the daily operations and safe transport of millions of passengers. Feedback from event participants clearly illustrates that the knowledge exchanged is not just theoretical; it is being actively applied in real-world situations. This ongoing dialogue promotes a culture of continuous improvement, and the momentum generated during the conference lays a strong foundation for more standardised, resilient, and proactive practices throughout the industry. We look forward to welcoming you to the next World Overflight Risk Conference in Malta on 20-22 April 2026!

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

25


Annex A. Definitions related to risk management Source / References

ICAO

IATA

ISO

Other

ICAO Doc 10084 Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones, 3 Ed., 2023 [10084]] ICAO Doc 9859 Safety Management Manual, Rev 4, 2018 [9859]

IATA Reference Manual for Audit Programs, Edition 13, 2023 [RM]

NIST* SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012 [NIST] COSO** ERM – Enterprise Risk Management, 2017 [COSO]

Risk

Safety risk: The predicted probability and severity of the consequences or outcomes of a hazard [9859]

Safety risk: The projected severity and likelihood of any adverse consequence(s) or outcome(s) from or associated with an existing hazard [RMт а]

ISO 31000:2018 – Risk Management – Guidelines [31000] ISO 31073:2022 Risk management — Vocabulary [31073] ISO/IEC 27005:2022 – Information Security Risk Management [27005] Effect of uncertainty on objectives [31000, 31073]

Uncertainty

Threat

Risk Tolerance

Risk Mitigation / Control

Security risk: identification of the level of exposure to a successful attack being carried out on a specific target, taking into account the assessed threat and consequences, as well as an assessment of the remaining vulnerabilities after evaluating the effectiveness of the aviation security measures currently in place [10084] N/D

The likelihood of a credible attack being attempted, based on the intentions and capabilities of perpetrators but not taking into account current security measures [10084] N/D

The process of incorporating defences, preventive controls or recovery measures to lower the severity and/or likelihood of a hazard’s projected consequence [9859]

The potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organization [27005]

A function of the likelihood of a given threat-source’s exercising a particular potential vulnerability and the resulting impact of that adverse event on the organization [NIST]

The possibility that events will occur and affect the achievement of strategy and business objectives [COSO]

N/D

A measure of the probability of an act of unlawful interference being committed against civil aviation [RM]

Tolerability - the level of safety risk that is acceptable (or unacceptable) to an organization based on the risk acceptance criteria of that organization [RM] The development and implementation of action(s) or measures designed to reduce a safety risk to, and maintain such risk at or below, an acceptable level in accordance with an organization's safety risk tolerability [RM]

State, even partial, of deficiency of information related to understanding or knowledge [31073] Potential source of danger, harm, or other undesirable outcome [31073]

N/D

Organization’s … readiness to bear the residual risk in order to achieve its objectives [31073]

The acceptable levels of variation in performance related to business objectives [COSO]

Risk control - measure that maintains and/or modifies risk [31000, 31073]

Prioritising, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process [NIST]

Any circumstance or event with the potential to adversely impact organizational operations [NIST]

The process of incorporating additional measures to lower the ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

26


vulnerability to a specific scenario [10084] N/D

N/D

Risk Evaluation

N/D

N/D

Risk Assessment

N/D

Safety Risk Assessment - a formal process used to determine safety risk by assessing the potential severity and likelihood of occurrence of an adverse consequence or outcome from an existing hazard [RM]

Risk Management

Safety Risk Management (SRM) is a key component of safety management and includes hazard identification, safety risk assessment, safety risk mitigation and risk acceptance [9859]

Safety Risk Management (SRM) - the component of a safety management system that includes the organization-wide implementation of hazard identification and safety risk assessment processes to ensure safety risks are mitigated or controlled to an acceptable level [RM]

Risk Criteria

Terms of reference against which the significance of a risk is evaluated [31073] Process of comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable or tolerable [31073] Overall process of risk identification, risk analysis and risk evaluation [31000, 31073]

Coordinated activities to direct and control an organization with regard to risk [31000, 31073]

N/D

N/D

The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system [NIST] Enterprise Risk Management - the culture, capabilities, and practices that organizations integrate with strategysetting and apply when they carry out that strategy, with a purpose of managing risk in creating, preserving, and realizing value [COSO] The program and supporting processes to manage information security risk to organizational operations (…) and includes: (i) establishing the context for risk-related activities; (ii) assessing risk; (iii) responding to risk once determined; and (iv) monitoring risk over time

N/D – not defined * NIST – National Institute of Standards and Technology, US Department of Commerce ** COSO - Committee of Sponsoring Organizations of the Treadway Commission

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

27


Annex B. Risk Management Guidance – Definitions and Framework Risk Management is not an end in and of itself. It is a means and mechanism through which better decisions can be made. Whilst a defined process is critical for consistency and communication, it is the decision that matters more than the process to get there. This foundational principle informs the requirements for a Risk Management function. This function, critical in business decision-making, requires both the lexicon used to communicate the process and the outcome and the framework that defines the activities required to achieve risk-based decision-making. With a focus on outcome rather than process, it is most important to recognise that complexity in a Risk Management process adds nothing more than an ‘analysis placebo’ and should be studiously avoided to maximise understanding and efficiency. Consistency and standardisation are essential in risk management. This is well recognised in many areas of aviation where standardisation has been transformational in improving safety and operational effectiveness. Standard radio voice procedures and protocol are a perfect example of this. History is littered with the tragic outcomes that stem from a lack of or a breakdown in standardisation. When we, as an industry, discuss, share information and intelligence, and develop best practices and regulatory frameworks for risk management, particularly in security, this standardisation is essential for everyone to speak the same language and understand the information, intelligence, and best practices that are being shared. This guide is intended to support, promote and enable simplicity and standardisation by: 1. Proposing a standard set of language for the industry to act as a framework within which risk management processes can be conducted. This lexicon has been developed through extensive research of current standards and best practice guidance across all sectors, including those specific to aviation. 2. Providing readers with a high-level risk management framework, drawn from all current standards and best practice documents, that can be customised and adapted to their own organisation and operation. 3. Inform the development of other industry documents, guidance and regulatory frameworks to promote simplicity and standardisation.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

28


1. Risk Management Definitions (Definitions below are adopted from various sources listed in the section “References” below and adjusted for use in aviation safety/security) Through a thorough literary review of the dominant standards and best practice documents, along with current industry advice and support, we have developed a set of proposed standard terms and approaches that provide a simple and customisable framework for risk management for operators and other aviation sectors. These definitions include concepts and terms that we both recommend used in a risk management framework and those used regularly but that increase complexity and do not add consummate value to such frameworks. Risk: The adverse effect of Uncertainty on an organisation’s objectives. What does this mean? Risk is a concept used to conceptualise the future and the potential negative effects that different events and scenarios may have on an organisation and its ability to carry out its mission and objectives. In its most simplistic terms, ‘Something can go wrong’. For example, what is the chance of event X happening, and what is the impact on our organisation if it were to happen? Uncertainty: The lack of complete knowledge or predictability about future events or conditions that may affect the achievement of objectives. In simple terms, we do not know everything. Risk Statement: The articulation of a specific risk in a standard format to improve clarity, understanding and communication. Advice on drafting a Risk Statement is in section 2. Risk Identification: A stage in the risk management process during which all risks that the organisation faces across its entire operational network are identified and articulated with Risk Statements. Risk Analysis: Defining an identified risk through the assessment of impact and likelihood. This definition can be qualitative or quantitative using descriptors, scales, probabilities or other mechanisms to articulate the assessed impact and likelihood. At its most simple, it is giving a risk a number or a description to represent the assessed level of that risk. A note on Impact and Likelihood. In some situations Consequence and Probability are used instead of Impact and Likelihood, particularly when probabilistic methods are used to analyse risk. However, Impact and Likelihood are more intuitive terms that cover a broad range of methodologies and are therefore recommended. Level of Risk: An articulation of the Risk Analysis. This is often in the form of a scale, either numeric (e.g. 1-100) or descriptive (Insignificant, Low, Moderate, High, Extreme) but can also be expressed in fiscal units ($), particularly if probabilistic risk analysis methods are used. ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

29


Risk Evaluation: This is the first real decision point in the risk management process, deciding whether a risk can be accepted, tolerated or must be treated. It can be considered an inherent part of Risk Analysis (Risk Analysis is purely academic without Risk Evaluation and has no practical benefit on its own). Risk Tolerance: Risk tolerance is an organisation-specific, defined level of risk an organisation or individual is willing to accept in pursuit of its objectives. It represents the amount of uncertainty or potential loss an organisation is prepared to handle, either from a strategic, operational, or financial perspective, without significantly affecting its overall goals, values, or success. It is Risk Tolerance that determines the Risk Evaluation decision of acceptance, tolerance or treatment. Hazard (or Threat): A potential cause of an unwanted incident, which may result in harm to a system, organisation, or individual. In relevant circumstances, Hazard/Threat is the combination of capability and intent. A Hazard or Threat either exists or it does not and does not require an assessment of the ‘level’ of that hazard or threat. For example, a specific weapon system exists in a specific location that has the capability to target aviation assets at cruising altitude and the party that has control of that weapon system has both the capability to operate it and the intent to target aircraft in flight (even if not directly and deliberately targeting commercial aircraft) or it does not. Hazard/Threat is a fundamental component of Risk Identification (without a Hazard or Threat, a Risk does not exist as there is no cause). A note on the differences between Hazards and Threats. These are, in many ways, very similar. Hazard is traditionally used more frequently in the Safety sphere, often defined as being ‘untargeted’ i.e. no deliberate targeting of an organisation’s operations or objectives. This could include weather, accidents/safety incidents etc. As many potential causes of risk that may be traditionally considered Threats are equally untargeted (misidentification and shootdown, civil/military deconfliction issues, social unrest) they can also arguably be classified as Hazards. ICAO Doc 9859 (SMM - Safety management manual) defines a Hazard as: A condition or an object with the potential to cause or contribute to an aircraft incident or accident. This is broad enough to cover both Hazards and Threats so it is our recommendation that, for simplicity and consistency, Hazard is used as a term to cover both. Mitigation (or Control): The process of reducing, controlling, or eliminating the likelihood or impact of identified risks. It involves strategies and actions that aim to minimise potential negative outcomes, thus helping organisations reduce exposure to risks that could hinder achieving their objectives. The purpose of mitigation is to manage risk to an acceptable level within the organisation’s defined Risk Tolerance. Theme: A Theme is a concept used to group risks in order to make their analysis and management easier, quicker and more scalable. The Theme is usually the cause of that risk. For example, Social Unrest is the Theme, and within that Theme, there are a set of risks caused by social unrest that may cause damage, disruption, injury, loss of life or another impact on the ™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

30


organisation. By grouping risks in this way, the analysis of likelihood and/or impact may be done ‘in bulk’ for all the risks in that Theme.

Other Commonly Used Terms Risk Scenario: A term sometimes used to describe and articulate a particular scenario that can then be assessed and analysed (quantified). In reality, every Risk is a scenario – it is the chance of a particular event or scenario occurring and the impact of that event or scenario if it were to occur. Risk Scenario is a term that is therefore not needed if Risks are correctly identified and articulated. Vulnerability and Exposure: These terms are often used in risk management frameworks, but in practice add little value as they are inherent in any assessment of likelihood and impact. Risk Appetite: The corollary of Risk Tolerance, which is therefore duplicative.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

31


2. Risk Management Framework 2.1. Risk Management Process A simple and effective risk management process is defined below. All reference standards and documents articulate more complex processes, but in general, they cover the same functions. It is recommended that the simplest possible approach be adopted initially, which allows for an increase in resolution and complexity as experience, knowledge, and available data improve. At its most simple, a risk management process consists of a three-stage cycle, guidance for which is provided below. A risk management process must be continuously iterated, looking for new risks, analysing them and treating them as they appear and disappear, hence its cyclical nature:

Risk Identification • Identify the risks that exist in a specific location or context • Articulate the risks with formal risk statements

Risk Treatment

Risk Analysis

• Apply mitigation measures to impact and/or likelihood of each risk • Quantify the effect of each mitigation • Is the residual risk acceptable?

• Quantify/qualify the impact & likelihood of each risk • Is the result acceptable or does it need treating?

There are other terms or functions that are often defined as part of a risk management process, including monitoring and review, communication and consultation and recording and reporting. In reality, very few multi-stakeholder processes work without these functions, so we have considered these to be inherent for the sake of simplicity.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

32


2.2. Risk Identification Risk Statements A Risk Statement must include the following components: 1. Risk Event: o What might happen? This part describes the uncertainty or event that could pose a hazard. It clearly identifies what the potential risk is. o Example: "The airline’s operation may face significant disruption…” 2. Cause: o Why might it happen? This part explains the underlying cause or conditions that may lead to the risk event. Understanding the cause helps in addressing the root of the problem. o Example: "... due to social unrest leading to protests, blockades, or strikes at key airports or along essential transportation routes…" 3. Impact (Consequence): o What will be the effect? This part describes the potential consequences if the risk event occurs. o In the aviation operational context, for simplicity’s sake, the potential consequences could be limited to Injury/Loss of life, Damage (to aircraft or facilities) and Disruption (delay, diversion, re-routing). However, a broader view, which includes commercial, reputational, financial and legal impacts, can be taken if desired. o Example: "...resulting in widespread flight cancellations, delays, or rerouting, severely impacting the airline’s schedule and customer satisfaction.” 4. Context (Conditions): o Under what circumstances? This component sets the context for the risk, explaining under which specific conditions the risk could occur. o Example: "This disruption is particularly likely if unrest occurs in regions where the airline has major hubs or frequent flights." Example of a Complete Risk Statement "The airline’s aircraft or ground equipment might suffer damage (Risk Event) due to a collision or near-miss with private or military drones, particularly during take-off or landing (Cause), causing damage to the aircraft’s fuselage, engines, or other critical components, leading to costly repairs, grounded aircraft, and potential operational delays (Impact). The risk of damage is elevated if drones are operated recklessly or without proper authorisation near flight paths or airport perimeters. (Context)." This structure ensures that risks are communicated clearly, facilitating more informed decision™

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

33


making and effective risk management strategies.

2.3. Risk Analysis

Calculation of Risk Risk = impact x likelihood These two factors can be assessed in many different ways, from risk matrices to criteria-based to statistical and probabilistic methodologies. Each has its own benefits and disadvantages, and different resource and expertise requirements. The likelihood of an adverse event and the impact of that event if it were to happen can be expressed in a number of ways: 1. Qualitative (based on descriptive (high-medium-low) or ranking (Level 1, 2, 3) scales for impact and likelihood); 2. Semi-quantitative (one parameter (usually likelihood) is expressed quantitatively and the other is expressed on a rating scale) 3. Quantitative, where both impact and likelihood are calculated and expressed in a quantitative, usually probabilistic way. A clear and well-defined risk – whether expressed qualitatively or quantitatively – is a critical component of the risk management process. When combined with an organisation’s defined risk tolerance, it forms the basis for determining appropriate mitigation strategies and selecting specific control measures; that is, it is essential to be able to make a decision. While no universal standard or guideline exists for quantifying risk tolerance levels, having a precise internal definition – particularly regarding the threshold at which operations must cease – can significantly enhance the effectiveness and consistency of risk management decisions. Aviation traditionally uses a qualitative approach to risk management. While it has several benefits, such as easy implementation and risk communication, it also has several significant downsides. Notably, different individuals interpret qualitative classifications of likelihood or probability in varied ways. This variation can increase in complexity when such classifications are translated into other languages, leading to additional layers of ambiguity. Assessing risks quantitatively and communicating risks in numeric or probabilistic terms would enhance precision, reduce ambiguity, and remove biases. We, therefore, recommend using a quantitative approach.

2.4. Risk Treatment Types of Mitigation Strategies: Mitigation strategies may vary depending on the type of risk, but commonly include: Risk avoidance: Changing plans or processes to eliminate the risk.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

34


Risk reduction: Implementing measures to reduce the likelihood or impact of the risk (e.g., process improvements, preventive maintenance).

Risk transfer: Sharing the risk with a third party (e.g., insurance, outsourcing).

Risk acceptance: Acknowledging the risk and deciding to take no further action if it is within acceptable limits.

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

35


References RISK •

Security risk: identification of the level of exposure to a successful attack being carried out on a specific target, taking into account the assessed threat and consequences, as well as an assessment of the remaining vulnerabilities after evaluating the effectiveness of the aviation security measures currently in place (ICAO Doc 10084 Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones, 3 Ed., 2023). Safety risk: the predicted probability and severity of the consequences or outcomes of a hazard (ICAO Doc 9859 Safety Management Manual, Rev 4, 2018). Note: only “safety risk” is defined. Safety risk: the projected severity and likelihood of any adverse consequence(s) or outcome(s) from or associated with an existing hazard (IATA Reference Manual for Audit Programs, Edition 13, 2023). Note: only “safety risk” is defined. Effect of uncertainty on objectives (ISO 31000:2018 – Risk Management – Guidelines, ISO 31073:2022 Risk management — Vocabulary). The potential that a given threat will exploit vulnerabilities of an asset or group of assets and thereby cause harm to the organization (ISO/IEC 27005:2022 – Information Security Risk Management). A function of the likelihood of a given threat-source’s exercising a particular potential vulnerability and the resulting impact of that adverse event on the organization (NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012). The possibility that events will occur and affect the achievement of strategy and business objectives (COSO ERM – Enterprise Risk Management, 2017). The probability and magnitude of a loss, disaster, or other undesirable event. Shorter definition: something bad can happen (Douglas W. Hubbard. The failure of risk management. Why it is broken and how to fix it).

• •

• •

UNCERTAINTY • state, even partial, of deficiency of information related to understanding or knowledge (ISO 31073:2022 Risk management — Vocabulary). THREAT • The likelihood of a credible attack being attempted, based on the intentions and capabilities of perpetrators but not taking into account current security measures (ICAO Doc 10084 Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones, 3 Ed., 2023). • A measure of the probability of an act of unlawful interference being committed against civil aviation (IATA Reference Manual for Audit Programs, Edition 13, 2023). • Potential source of danger, harm, or other undesirable outcome (ISO 31073:2022 Risk management — Vocabulary).

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

36


Any circumstance or event with the potential to adversely impact organizational operations (NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012).

RISK TOLERANCE • Tolerability - the level of safety risk that is acceptable (or unacceptable) to an organization based on the risk acceptance criteria of that organization (IATA Reference Manual for Audit Programs, Edition 13, 2023). • Organization’s … readiness to bear the residual risk in order to achieve its objectives (ISO 31073:2022 Risk management — Vocabulary). • The acceptable levels of variation in performance related to business objectives (COSO ERM – Enterprise Risk Management, 2017). RISK MITIGATION/CONTROL • Risk mitigation - the process of incorporating defences, preventive controls or recovery measures to lower the severity and/or likelihood of a hazard’s projected consequence (ICAO Doc 9859 Safety Management Manual, Rev 4, 2018). • Risk mitigation - the process of incorporating additional measures to lower the vulnerability to a specific scenario (ICAO Doc 10084 Risk Assessment Manual for Civil Aircraft Operations Over or Near Conflict Zones, 3 Ed., 2023). • Safety Risk Mitigation - the development and implementation of action(s) or measures designed to reduce a safety risk to, and maintain such risk at or below, an acceptable level in accordance with an organization's safety risk tolerability (IATA Reference Manual for Audit Programs, Edition 13, 2023). • Risk control - measure that maintains and/or modifies risk (ISO 31000:2018 – Risk Management – Guidelines, ISO 31073:2022 Risk management — Vocabulary). • Risk mitigation - prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process (NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012). RISK CRITERIA • terms of reference against which the significance of a risk is evaluated (ISO 31073:2022 Risk management — Vocabulary). RISK EVALUATION • process of comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable or tolerable (ISO 31000:2018 – Risk Management – Guidelines, ISO 31073:2022 Risk management — Vocabulary). RISK ASSESSMENT

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

37


Safety Risk Assessment - a formal process used to determine safety risk by assessing the potential severity and likelihood of occurrence of an adverse consequence or outcome from an existing hazard (IATA Reference Manual for Audit Programs, Edition 13, 2023). Overall process of risk identification, risk analysis and risk evaluation (ISO 31000:2018 – Risk Management – Guidelines, ISO 31073:2022 Risk management — Vocabulary) The process of identifying, estimating, and prioritizing risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system (NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012).

• •

RISK MANAGEMENT • Safety Risk Management (SRM) is a key component of safety management and includes hazard identification, safety risk assessment, safety risk mitigation and risk acceptance (ICAO Doc 9859 Safety Management Manual, Rev 4, 2018). • Safety Risk Management (SRM) - the component of a safety management system that includes the organization-wide implementation of hazard identification and safety risk assessment processes to ensure safety risks are mitigated or controlled to an acceptable level (IATA Reference Manual for Audit Programs, Edition 13, 2023). • Coordinated activities to direct and control an organization with regard to risk (ISO 31000:2018 – Risk Management – Guidelines, ISO 31073:2022 Risk management — Vocabulary). • Enterprise Risk Management - the culture, capabilities, and practices that organizations integrate with strategy-setting and apply when they carry out that strategy, with a purpose of managing risk in creating, preserving, and realizing value (COSO ERM – Enterprise Risk Management, 2017). • The program and supporting processes to manage information security risk to organizational operations (…) and includes: (i) establishing the context for risk-related activities; (ii) assessing risk; (iii) responding to risk once determined; and (iv) monitoring risk over time (NIST SP 800-30 Rev. 1 – Guide for Conducting Risk Assessments, 2012).

© WORC copyright Sora Solutions T/A Osprey Flight Solutions World Overflight RiskRisk Conference | worconference.com | hello@worconference.com This whitepaper solely reflects the views of the co-organiser, Osprey Flight Solutions, and not those of the other parties involved. Neither EASA nor the University of Southampton participated in drafting this document, nor do they necessarily endorse its conclusions. .

38


END


JOIN US AT

20-22 APRIL 2026 | ST JULIAN’S, MALTA ORGANISED BY

GET YOUR TICKETS TODAY

worconference.com |

hello@worconference.com

@World Overflight Risk Conference

@WORConference


Turn static files into dynamic content formats.

Create a flipbook
WORC2024 Conference Whitepaper: Rethinking Overflight Risk by Osprey Flight Solutions - Issuu