October/November 2026 Issue
Explore »

CyberSat at 10: The 10 Defining Moments of CyberSat

CyberSat was a first-of-its-kind event launched 10 years ago that brought the government, IT, cyber and space professionals together to talk about the security of space assets. It has featured electrifying keynotes, major announcements and stories that reverberated around the world. For a niche event, it has produced its fair share of headlines. In a special feature, Via Satellite Senior Editorial Director and CyberSat Conference Chair Mark Holmes and longtime cyber reporter Shaun Waterman share the 10 defining moments of CyberSat so far.

Keynote in 2017 Makes Global Headlines

CyberSat kicked off in 2017, a first of a kind event that brought the IT, government, space, and end user communities together. It started with a keynote that made global headlines around the world. The keynote was given by Robert Hickey, aviation program manager within the Cyber Security Division of the DHS Science and Technology (S&T) Directorate. Hickey revealed at the opening CyberSat that a team of government, industry and academic officials had successfully demonstrated that a commercial aircraft could be remotely hacked in a non-laboratory setting the prior year. “We got the airplane on Sept. 19, 2016. Two days later, I was successful in accomplishing a remote, non-cooperative, penetration,” he said.

Explore the October/November 2026 Issue

Check out more from this issue and find your next story to read.

Hickey said the details of the hack and the work his team are doing were classified, but said the team accessed the aircraft’s systems through radio frequency (RF) communications, adding that, based on the RF configuration of most aircraft, “you can come to grips pretty quickly where we went” on the aircraft.

This was completely a new disclosure at the time. So, much so it made headlines across the mainstream press, as well as more defence, space and cybersecurity publications. Via Satellite’s sister publication Defense Daily’s coverage was picked up in global headlines. It is perhaps the most talked about keynote in CyberSat’s history.

 Ahead of the Creation of Space Force, Gen. John Raymond Speaks at CyberSat 2017

CyberSat 2017 also featured one of the biggest names in this area talking about the future of space and cybersecurity. Gen. John “Jay” Raymond, commander of Air Force Space Command, gave one of the lunchtime keynotes at CyberSat in 2017. While Raymond was a big name even then, the significance of this keynote would only come later. CyberSat began two years before the U.S. Space Force was announced in December 2019. Raymond would become the first Chief of Space Operations of the U.S. Space Force in 2019 and serve through 2022. His presence at the first CyberSat was highly significant.

Via Satellite’s sister publication Defense Daily covered Raymond’s keynote at CyberSat. Interestingly, he talked about how the U.S. Air Force Space Command needed to focus on the side of the spectrum that the U.S. depends on Air Force Space Command for, which is the defense of U.S. weapons systems and critical infrastructure.

Raymond also talked about how the Air Force was moving its own personnel away from basic support functions to cyber warfighting needs, it opened opportunities for industry to help. “We’re hoping to partner with industry to secure and procure enterprise IT as a service and allowing us to repurpose our airmen to do the job that our nation needs them to do, to defend, and if necessary, fight and go in the cyberspace domain,” he said.

Raymond’s presence at CyberSat looks even more significant now than it did then. He engaged with the space community at CyberSat and two years later, would lead the U.S. into an exciting new era with the Space Force.

Ken Munro demonstrated how it’s possible to hack into a commercial satellite network live onstage at CyberSat in 2018. Photo: Access Intelligence

Pen Tester Wows CyberSat Audience in 2018

The CyberSat audience has evolved over the years with more and more technical people coming to the event year on year. One of the most talked about keynotes in the early years was Ken Munro, partner for Pen Test Partners, who rather than talk about hacking, actually showed how you could hack everything from a kettle to a satellite system on stage.

“To this day, one of my favorite moments from CyberSat is the year when Ken showed how incredibly easy it was to hack into a commercial satellite network. His demonstration was definitely an eye opener for me,” Mark Edwards, Senior Principal Software Systems Engineer, Trident Systems, tells Via Satellite.

CyberSat is delighted to welcome Munro back to CyberSat 2026 for the first time in eight years. Once again, he will demonstrate a hacker’s approach to breaking systems. Certainly, Munro’s keynote in 2018 was a first of its kind for CyberSat and showcased a new dimension for the event. It will be interesting to see what Munro comes up with in 2026 given how the cyber and satellite worlds have changed over the last few years. 

The Formation of Space-ISAC in 2018

The second CyberSat conference in 2018, boasted quite a roster of government and private sector speakers, including keynotes from federal CISO Grant Schneider and the top civilian at U.S. Cyber Command David Luber. But possibly the most consequential news from the conference came in remarks from the floor. After one of the panel discussions, Fred Gaudlip from Kratos made an impromptu announcement during the Q&A that a small group of space companies had been working on forming an information sharing and analysis council, or ISAC, for the industry.

The establishment of the Space ISAC was formally announced in the following year at the 35th Space Symposium. The organization is headquartered in Colorado Springs, Colorado and is co-located with the National Cybersecurity Center (NCC), which serves as the executive and administrative function of the Space ISAC. Space ISAC joined as an official member of the National Council of ISACs in 2020.

ISACs dated back to President Clinton’s 1998 Presidential Decision Directive-63 (PDD-63), which directed the establishment of private-sector organizations to share threat and vulnerability data on an all-hazards basis within critical infrastructure sectors. The next year, the financial services industry founded FS-ISAC as the very first operational ISAC, establishing the baseline model for peer-to-peer threat intelligence pooling.

But space had never been formally considered a critical infrastructure sector by the U.S. government, and Space-ISAC was one of the first councils to emerge from such a sector. The operational technology, or OT-ISAC was formed the next year in 2019 in Singapore.

The Debate Over Space as a Critical Industrial Sector in 2021

The 2021 CyberSat conference took place shortly after a long-running debate within the new Biden administration about whether to formally designate space as a critical infrastructure sector had concluded. The first ever National Cyber Director Chris Inglis delivered the news about the result during a Q&A after his keynote. “I don’t think so,” he said in response to a question on whether space would be designated as the 17th official critical infrastructure sector.

The decision was something of a milestone in the long march of U.S. policymakers away from the sector-based approach to defending critical infrastructure. That view “leads us to a false conclusion,” Inglis said — the idea that each sector could be defended in isolation. In reality, all the sectors were interconnected and it was an illusion to think “that we can get one of those right in the absence of [getting] the other 15 right,” he said.

Inglis pointed out that the most important risks, like extreme weather events or mass-effect terror attacks, for example, almost always impact multiple critical infrastructure sectors. And failures in one sector — energy, banking and water most obviously — can set off a cascade of failures across multiple sectors.

Space is an excellent example of the failings of a sector-based approach, experts say. A space-based capability like GPS, for example, would have very little effect on the space sector if it failed and a huge impact on financial services, transportation and energy, where GPS is an essential service.

Viasat’s Engagement with the CyberSat Community

One of the defining moments — if not the defining moments — in space and cybersecurity was in 2022, when Viasat was famously the subject of a targeted denial of service attack on the KA-SAT satellite network in Europe just ahead of Russia’s invasion of Ukraine. Phil Mar, vice president and CTO of Engineering for Viasat Government and a member of CyberSat’s advisory board, has been a regular speaker at CyberSat, both on the unclassified and classified part of the event.

Mar has been willing to share lessons learned and how Viasat has responded to the events in 2022, both in the short term and the long-term. The denial of service attack made global headlines beyond just the space and cybersecurity communities. Viasat and Mar in particular worked with CyberSat in the aftermath to share their learnings and experiences with the community. It is something that the CyberSat community has found incredibly valuable, with Mar’s keynotes/speeches being some of the most well-received and thought-provoking. As CyberSat has become more technical, there is a demand for more actionable insights. Viasat has probably spoken more at CyberSat about the events of 2022 and the aftermath than at any other event, thus providing the communities with invaluable learnings. To this day, it remains a key reference point for the space and cybersecurity community, and thanks to Mar and Viasat, the CyberSat community has been given critical intelligence from the front lines. 

The Aftermath of the Viasat Hack Opens Door to Critical Industry Briefing in 2022

The hack of Viasat ground terminals that immediately preceded the Russian invasion of Ukraine in February 2022 was a huge turning point for the industry in two senses. Firstly, it highlighted a well-understood but long-ignored truth: That “dual use” commercial satellites which provide military communications or command and control alongside their civilian services are likely targets in great power conflicts. Secondly it illuminated a newly emerging understanding about satellite communication and data transport: You don’t have to touch the satellite to attack the service.

Just two months after the attack at CyberLEO in Los Angeles in May, Space ISAC Executive Director Erin Miller told attendees that U.S. intelligence officials were so concerned about the threat to other satellite operators that they organized an unprecedented briefing for company executives. The Office of the National Director of Intelligence issued “clearances for a day” to satellite operators so they could get a classified briefing on the Viasat hack.

The briefing was pulled together under the leadership of Dr. Stacey Dixon, principal deputy director of national intelligence, a U.S. intelligence official confirmed later to Via Satellite. The agencies briefing included the FBI and the National Air and Space Intelligence Center, according to Kevin Coggins, a Booz Allen Hamilton vice president and board member of Space ISAC. Miller called it a “milestone moment” at the time.

Space Force Acknowledges Dependence on Commercial Environments for Training in 2024

CyberSat predated the foundation of the U.S. Space Force by two years, but the conference always featured military keynotes from agency heads and general officers. The foundation of the Space Force in 2019 saw an expansion of the involvement of the U.S. military in the panels and fireside chats. CyberSat became one of the premier venues for the discussion of Space Force programs that would impact industry, like the long-running saga over the Infrastructure Asset Pre-Assessment program, or IA-Pre.

Space Force officers like Space Systems Command Chief Information Officer Col. Jennifer Krolikowski became stars at the conference, touting new programs for industry. But the open Q&A sessions, and the presence of a broad and generally eagle-eyed press corps, meant that speakers had to be prepared to answer questions offstage as well as on. There’s no backstage exit to a closed-off green room at CyberSat.

That set up encourages transparency from speakers. At CyberSat 2024, when Col. Erica Mitchell, commander of Delta 26, the Space Force unit that defends the National Reconnaissance Office from cyberattacks and online espionage, spoke about her unit’s training efforts, she acknowledged that they had to use a private sector cyber range for part of the contests, and run them at an unclassified level as a result, because the Space Force’s own cyber range wasn’t ready.

Growing Technical Specialization and Operational Relevance in 2024

CyberSat has always had a technical bent. There have always been technical deep dives of one kind or another among the presentations. But in 2024, the conference launched a formal full-blown technical track, with a review board assessing competing proposals. The initial track in 2024 showcased the work of the DHS Science and Technology division and the FFRDC Aerospace Corp on on-orbit intrusion detection.

2024 also saw the first ever CyberSat tabletop exercise, staged by Space ISAC, in which players had to deal with an incident at a lunar mining facility. This year the Space ISAC tabletop exercise will return as participants work through a scenario examining real-world threats to space systems from detection and response, to decision-making and resilience planning. 

NRO Announces Major New Cyber Program at CyberSat 2025

Johnathon Martin spoke in 2025 as the incoming director of the brand-new NRO Space Cyber Program. Photo: Access Intelligence

At CyberSat 2025, in another major first for the event, the National Reconnaissance Office (NRO) revealed it had established a space cyber program to serve as the central hub for space cyber activities across the agency. This was covered comprehensively in Via Satellite’s sister publication – Defense Daily. The brand new cyber program was revealed by Johnathon Martin, the acting deputy director of the NRO’s Office of the Chief Architect and the incoming deputy director of the NRO Space Cyber Program. The program’s scope will tie together all aspects of space cyber for policy and governance, R&D, engineering, acquisition, and operations, he said.

Martin told the CyberSat audience that the program would be based on three pillars. “First, we’re establishing clear strategic priorities for space security,” Martin said. “Second, we’re accelerating the integration of cybersecurity capabilities into our space systems. Our team is working directly with program offices to bake cybersecurity and design processes from day one, not as an afterthought. We’re ensuring the bar is high, that programs have what they need to be successful and reach the criteria, and ensuring that they do. We’re doing this while minimizing system complexity and without hindering our acquisition and operational tempo. Third, we’re flattening decision making hierarchies. The NRO chief information security officer has been named the NRO’s space cyber executive.”

The NRO has been a regular participant at CyberSat down the years and will be back again in 2026. However, this was a highly significant moment in 2025, as it is not every day a major U.S. government agency reveals a brand-new cyber program. This was perhaps the major talking point of CyberSat 2025, and we will likely get an update on the progress of the program at CyberSat 2026.

“Johnathon Martin’s keynote at CyberSat 2025 is probably the one that stands out most to me. What I appreciated was the openness of the discussion. He talked very candidly about where his organization was going with space cybersecurity, the challenges they were facing, and where he believed things needed to improve,” Brandon Bailey, principal engineer for The Aerospace Corporation, tells Via Satellite. VS

In This Issue