Case Study: Simon Hegele Gesellschaft für Logistik und Service mbH

Tamper-proof session recording and traceable control of privileged access in the context of the Aviation Security Act (LuftSiG), including mapping to NIS2 and ISO 27001.

Our case studies provide insight into real client projects, for example audit-compliant session recording in aviation logistics, and show how our solutions perform in daily operations. We describe the initial situation, requirements and implementation, and make the added value visible through concrete results. In this way, you gain an authentic impression of how modern IT and security solutions are used in diverse organisations. We thank our clients for their trust and their willingness to share their experiences publicly.

With Simon Hegele Gesellschaft für Logistik und Service mbH, we show how an international logistics provider implements audit-compliant session recording in accordance with the Aviation Security Act (LuftSiG). The focus is on tamper-proof evidence and the four-eyes principle. Moreover, we present how these measures map to NIS2 and ISO/IEC 27001. The emphasis is on verifiable proof for audits, reviews and official inspections, because simple logs are insufficient for robust reconstruction.

About Simon Hegele
TECHWAY - Case Study - Simon Hegele - Session Recording LuftSiG

Simon Hegele Gesellschaft für Logistik und Service mbH is an international provider of logistics and services, active in industry, healthcare and contract logistics. The company handles sensitive customer and order data and operates cross-site IT systems for warehouse management, transport and customer-specific value-added services. At sites close to aviation, the requirements of the Aviation Security Act (LuftSiG) take on particular significance: consequently, the company must ensure audit-compliant session recording that is traceable, verifiable and documented in a tamper-proof manner. At the same time, the implemented measures map consistently to NIS2 and ISO/IEC 27001.

Initial Situation & Motivation

In aviation-adjacent processes, notably in the air cargo environment, secure supply chains and IT systems with restricted access, Simon Hegele is subject to the provisions of the Aviation Security Act (LuftSiG). These demand comprehensive traceability of sensitive access, clear responsibilities and the ability for ex post review by internal bodies or authorities. However, classic system logs were not sufficient for this purpose. First, the specific user activities could not be reconstructed in an evidential manner. Second, a suitable technical solution for the four-eyes principle was lacking. The goal was therefore to establish audit-compliant session recording that produces tamper-proof evidence, valid for audits and external inspections. In parallel, the measures had to be designed to deliberately support the requirements of NIS2 and ISO/IEC 27001.

TECHWAY - Case Study - Simon Hegele Logistik - Sebastian Frank

Sebastian Frank

Head of IT Operations

“With Syteca, we have, for the first time, made privileged access fully traceable, particularly where we need strong evidence in the sense of the LuftSiG. Session Recording and the audit trail form the basis for the four-eyes principle and checks by internal audit and external bodies. At the same time, we can cleanly map the measures to the NIS2 and ISO 27001 requirements.”

Challenge

Three key requirements were paramount:

  • Audit-compliant session recording: complete and immutable capture of privileged sessions for subsequent reconstruction, especially on aviation-related IT systems.
  • Four-eyes principle & organisational control: separation between operations and oversight, with traceable approval and review processes.
  • Regulatory evidence (LuftSiG with mapping to NIS2 & ISO 27001): technical artefacts attesting to access, identity verification and system use, aligned to the needs of internal audit, external auditors and authorities.

The logging and monitoring mechanisms used to date provided only fragmentary information. As a result, conclusive evidence in the sense of the LuftSiG was not achievable with these tools.

Objectives

The following overview presents the project’s central objectives and their alignment with relevant standards and frameworks.

ObjectiveTopic / DomainStandard / Framework
Complete and tamper-proof reconstruction of privileged sessions on aviation-related IT systems.Session Recording
LuftSiG esp. §7a, §9a
ISO 27001 Logging/Monitoring
NIS2 Proofs of effective protective measures
Tamper-proof traceability of user actions, including timestamps, accountability and system context.Audit Trail, Reporting, Forensic Analysis
LuftSiG Traceability & Verifiability
ISO 27001 Logging & Monitoring
NIS2 Reporting obligations & evidence requirements
Implementation of the four-eyes principle for sensitive access through clear roles, control steps and traceable reviews.Organisational Control & Review
LuftSiG Principles of control
ISO 27001 Separation of functions
NIS2 Governance & risk-based controls

The following overview presents the project’s central objectives and their alignment with relevant standards and frameworks.

Session Recording
Objective
Complete and tamper-proof reconstruction of privileged sessions on aviation-related IT systems.
Standard / Framework
LuftSiG not. §7a, §9a
ISO 27001 Logging/Monitoring
NIS2 Proofs of efffective protective measures
Audit Trail, Reporting, Forensic Analysis
Standard / Framework
LuftSiG Traceability & Verifiability
ISO 27001 Logging & Monitoring
NIS2 Reporting obligations & evidence requirements
Organisational Control & Review
Objective
Implementation of the four-eyes principle for sensitive access through clear roles, control steps and traceable reviews.
Standard / Framework
LuftSiG Principles of control
ISO 27001 Separation of functions
NIS2 Governance & risk-based controls
Solution

Why Syteca for audit-compliant session recording?

Decisive was Syteca’s ability to record privileged sessions completely and in a tamper-proof manner and to make them specifically available for inspections. Unlike classic logs or SIEMs, audit-compliant session recording enables a contextual reconstruction of activities that includes context, timestamps and user identity. Syteca thus creates the basis for the four-eyes principle, tamper-proof controls and robust evidence in the sense of the Aviation Security Act.

Audit-compliant session recording without operational disruption

A central criterion was low-friction operation: Syteca could be integrated progressively into existing network, server and application environments without disrupting productive processes. Internal administrators and external service providers work in privileged sessions; these are recorded, enriched with contextual data and stored in a central audit log. As a result, this produces verifiable evidence for LuftSiG-related inspections, and it also provides a solid basis for mapping to NIS2 and ISO/IEC 27001.

Technical controls and evidence for LuftSiG and NIS2

The overview below presents the key functional areas of the Syteca platform and their contribution to LuftSiG compliance, along with supplementary mapping to NIS2 and ISO/IEC 27001.

%3@¼Û}

Taken together, these functions ensure tamper-proof documentation of sensitive events, traceable control of anomalous actions and the practical implementation of the four-eyes principle. For Simon Hegele, Syteca thus forms a technical foundation for evidence compliant with the LuftSiG, with consistent mapping to NIS2 and ISO/IEC 27001.

FunctionDescriptionMapping to LuftSiG / NIS2 / ISO 27001
Session RecordingComplete and tamper-proof recording of privileged sessions with search and playback functions for audits and forensic analyses.
LuftSiG Evidence of security-critical activities
ISO 27001 Logging/Monitoring
NIS2 Proofs of efffective protective measures; incident handling
Four-Eyes Principle (Control & Review Workflows)Traceable approval and review steps that separate operational activities from control and make reviews documentable.
LuftSiG Principles of control & evidence
ISO 27001 Separation of functions
NIS2 Governance & risk-based controls
Role-Based Access Control (RBAC)Granular role and permission concepts to reflect organisational responsibilities and the need-to-know principle.
LuftSiG Access restricted to authorised and vetted persons
ISO 27001 Least privilege & SoD support
NIS2 Risk-based access control