A decade is a long time in the space industry. In 2017 there was no Starlink or Amazon Leo; no commercial synthetic aperture radar constellations; and U.S. astronauts had to fly on Soyuz rockets to get to the International Space Station.
But in space cybersecurity, a decade is a lifetime, or even more. Indeed, the first Trump administration’s National Cyber Strategy in September 2018 seems to have been the first-ever public U.S. government policy document to specifically mention the need to defend the nation’s space assets against hackers, online spies, and cyberwarfare. It was followed two years later by a White House space policy directive, SPD-5, which laid out the broad outlines of a cyber defense strategy for the space sector.
But these publications were only the visible tip of a long-standing and growing iceberg of concern behind the scenes, at least at the Pentagon, says Bob Gourley, a former Naval intelligence officer with a long career in technology in and out of the Department of Defense.
A DoD-contracted team of private sector red team hackers had mounted successful cyberattacks against U.S. assets on orbit as far back as the late 1990’s, recalls Gourley, who was the J-2 (director of intelligence) at the time for the Joint Task Force – Computer Network Defense, the U.S. military’s first-ever cyber defense organization.
But the conversation was restricted to “the high side” — meaning the issue was only being debated in classified spaces between cleared individuals.
“All that stuff was kept very secret,” says Gourley, referring not just to the vulnerabilities, but to the technology itself, “unique, bespoke, government-built hardware in space,” that was often highly classified.
A turning point, says Gourley, was the revelation in 2015 that the Russian intelligence-linked threat actor Turla was using cyber-exploits to piggy-back on legitimate satellite communications channels to provide command and control for a network of its malware-infected devices. The public reporting of such an advanced and sophisticated attack gave U.S. officials and cleared satellite industry executives an unclassified talking point, to demonstrate that the cyber risk to space assets was not merely theoretical. “We had this threat incident that we could use to help explain to people that this is important … a real threat,” says Gourley.
The inaugural CyberSat conference in 2017 provided a forum where industry insiders and U.S. officials could talk about threats and vulnerabilities to space systems in a way that would have been unthinkable in an unclassified environment a decade earlier, Gourley adds. “CyberSat was crucial in changing attitudes about the need to protect our assets and to share information about this growing threat,” he says.
That change in attitude has been a critical shift, and the most important change over the past decade, he believes. In the past, he describes a mindset of keeping threats “obtuse, obscure, and unknown,” as if keeping vulnerabilities private meant they wouldn’t be an issue.
Space was probably the last high-tech industrial sector to abandon the idea of “security through obscurity” — the concept, long-derided in cybersecurity, that this sector’s IT was different and special enough that no one understood how to attack it.
If “security through obscurity” was already dying at the first CyberSat conference in 2017, the final nail was hammered into the coffin the following year, with the formation of the Space Information Sharing and Analysis Center, or Space-ISAC, an industry membership group dedicated to sharing threat, vulnerability and incident information. Its creation was “a watershed moment in the ability of the industry to collaborate,” says Gourley, reflecting “the understanding that we can’t just try to keep things obscure and hidden. We need to collaborate together and openly discuss our vulnerabilities so we can fix them.”
Commoditizing the Space Tech Stack
Another factor driving the increasingly public conversation about space cybersecurity in the last decade-plus, experts tell Via Satellite, was the explosive growth of commercial space and the transformation it wrought on the industry’s tech stack, both on-orbit and on the ground.
Commercial space companies’ adoption of commodity hardware and software, like ARM chips and Linux-based containers went hand-in-hand with a digital revolution in satellite and ground station technology. Hardware, from regular network switches to specialized or even bespoke items like modems, signal processors and antennas, was being virtualized — replaced with software. And the result was the advent of software-defined satellites, software-defined ground-systems, and software-defined radio frequency, or RF, devices that link them.
Software-defined radios and antennas mean that satellite and ground station frequency, waveform, and signal strength can be updated on-orbit or in situ, providing enormous flexibility to operators. The use of commodity hardware and software had slashed costs for them.
But that commodification and virtualization resulted in a much bigger attack surface, explains Jacob Oakley, chief scientist and cyber space lead at SIXGEN. This is largely because the space industry has failed to learn the hard-won lessons of its predecessors.
“The space community has been happy to embrace … commoditized operating systems and software for ease of development,” he tells Via Satellite. “But in doing so has often forgone utilizing many of the security functionalities that come with such operating systems such as locked down permissions, least privilege, diverse execution levels, OS-based firewalls, etc.”
Virtualization and software-defined satellites have also upended the business of risk analysis, argues Oakley, who teaches space cybersecurity at Black Hat and has helped build the capture-the-flag contest at the famed Defcon Aerospace Village. It’s no longer sufficient for the downside risk to consider only the possible loss of an asset, he says, if it can be reconfigured and used for some nefarious purpose.
“Imagine a satellite that broadcasts music being taken over and turned into a low power jammer or decoy,” posits Oakley. “The music broadcasting service company weighs the cost benefit of cybersecurity budget and implementations in terms of protecting their bottom line and their service, not based on how valuable their reconfigured satellite might be in the hands of an adversary,” he explains.
Moreover, as RF systems have become increasingly digital and software defined, “the boundary between EW [electronic warfare] and cyber attack has largely disappeared,” adds Oakley. “What begins as an RF effect, such as jamming or spoofing, can create an opening for a cyberattack, while a compromised software system can be used to manipulate signals or produce an RF effect.”
A Whole-of-System-Based Approach
The dissolution of that boundary changes the way organizations need to think about cybersecurity, Oakley says, realizing that the spacecraft itself was only part of a vulnerable system, all of which had to be protected.
“A decade ago, much of the security model rested on the idea that satellites were difficult to reach and therefore difficult to attack,” Oakley says. “Today, government and commercial operators recognize that an adversary may never need to touch the spacecraft directly. They can target ground systems, software updates, supply chains, user terminals, or RF links.”
This means that “organizations can no longer assess or defend these risks [from cyber and EW, or from attacks on the satellite vs attack on the ground systems] separately. They have to test the full system and the ways an adversary could move between the RF and cyber domains,” Oakley concludes.
That adoption of that systemic approach to security is the biggest thing that’s changed in the last decade, argues Norm Laudermilch, CISO of Earth Observation (EO) satellite operator and spatial intelligence provider Vantor.
“If you think back 10 years, cybersecurity in space has evolved from protecting satellites as isolated assets — you design, build, and launch this thing that operates by itself, and then you have to protect it — to protecting entire mission ecosystems all together,” he explains.
The new space tech stack is not just vulnerable; it’s interconnected, says Laudermilch. Today, the RF devices used to communicate with satellites “are just software-defined radios running on a Linux box in a cloud infrastructure somewhere.” Current satellite infrastructure “depends on RF software-defined radios, IP networking, cloud infrastructure, identity systems, APIs, [and] encryption.”
This convergence, Laudermilch says, means an adversary can attack an RF layer or software layer or even the identity layer or backend management through third party software.
Ten years ago, he recalls, “you had to attack the satellite. Now you can deny [space-based] critical infrastructure services and critical intelligence services without ever touching a satellite. That’s the big change.”
A whole-of-system-based approach to security means adopting a much broader lens, Laudermilch explains, encompassing everything from network and RF-based attacks to information operations aimed at reputational damage.
“Now we think about our space infrastructure as one big thing that needs to be protected: It’s the satellites, it’s the ground infrastructure, the cloud services, the AI models that process the data, the software supply chains, the RF communications,” Laudermilch says.
“Ten years ago, it was ‘Protect the firewall, protect the network.’ Today, that’s simply not enough. Everything’s connected. Everything’s distributed, and so our philosophy has had to change,” he adds.
“Here’s the stuff that most people miss — even public narratives. What is the world saying about your company and your satellites and your infrastructure? These things all have to be defended together now, as one ecosystem.”
Narrative attacks on social media — what a layperson might call shitposting — are important because the bot networks and sock-puppet armies that are often behind them are frequently associated or in partnership with cyber threat actors, Laudermilch says. “We’ve noticed that negative narrative attacks on social media that we can detect using AI, are often a leading indicator for a cyber attack, so narrative intelligence is a really big focus at Vantor today.”
The other big change Laudermilch identified in space cybersecurity over the past decade is the shift from prevention to resilience. Zero Trust is a cybersecurity approach based on the principle of “assume compromise,” starting from the proposition that the attacker is already inside the network. But that principle had other impacts, too, says Laudermilch, “Resilience has become more important than prevention.”
“We know prevention is not 100 percent achievable,” he adds. “The focus has shifted to resilience, which is what happens when prevention fails. That’s where our big focus is these days. So it’s not ‘Can we stop every attack?’ It’s — How do we continue the mission despite the attack?”
Lack of Leadership on Space Cyber Policy
After the change of administration in 2021, the Biden White House continued to build on the policy foundation the first Trump administration had laid, says Lauryn Williams, a career Department of Defense official who worked at the White House from 2022 to 2024.
The challenge was to convert the high-level principles of SPD-5 into “concrete action” and more granular regulation, says Williams, now at the Center for Strategic and International Studies. The Biden administration’s key achievements in this regard were an update to the security standards required of commercial vendors by U.S. intelligence agencies, and new NIST standards, she says.
In both the first Trump and Biden administrations, space cybersecurity policy was helmed by the vice president. Their role chairing the National Space Council ensured the issue was high on the White House agenda, capturing the attention of the national security policy machine, says Williams.
“You need a champion in the interagency,” she explains, referring to the complex and sometimes fractious process by which policy is made between government departments rather than within them, meaning it’s all too easy to get tied up in bureaucratic turf disputes or stand-offs between equally powerful players.
“There is power in being able to bring [everyone] together,” Williams says.
But in the current administration, Vice President J.D. Vance does not appear to have the space cybersecurity portfolio, and the National Space Council, despite being revived (again) last year, seems to be in temporary abeyance.
With so many stakeholders jockeying for advantage in the interagency, say current and former officials, a single powerful institutional leader is needed. “When everyone’s in charge, no one’s in charge,” Space-ISAC Chairman Sam Visner told an event at George Washington University earlier this year. VS







