This discussion brought together space policy experts, cybersecurity diplomats, and international organisations to examine the growing challenge of securing space-based infrastructure against cyber threats . Moderated by Gretchen Bueermann of ITU's Emerging Technologies Division, it drew on a joint research initiative between the Global Cybersecurity Forum (GCF), George Washington University's Space Policy Institute, and ITU .
Dr. Scott Pace, leading the research, outlined why space cybersecurity presents unique challenges beyond standard terrestrial practices . Key factors include the physical inaccessibility of satellites once launched, intermittent communication windows, and the hostile radiation environment that can corrupt memory systems in ways that are difficult to distinguish from malicious attacks . He noted that many satellite operators still transmit data in clear text and lack a designated information security officer, highlighting significant gaps in basic cyber hygiene . Pace emphasised that resilience - measured by how quickly a system can detect and recover from an attack - is a more realistic goal than attempting to prevent all intrusions .
Alexandra Vallet of ITU's Radio Communications Bureau stressed the need for a common conceptual language and warned against simply replicating terrestrial cybersecurity frameworks in the space domain . Australia's Cyber Ambassador, Jessica Hunter, explained that Australia has formally designated space as a critical national infrastructure sector, and identified misunderstanding, escalation, and delayed detection as key diplomatic risks arising from cyber incidents affecting space assets . She advocated for continued development of non-binding norms rather than new legal instruments, and emphasised the importance of connecting existing cybersecurity networks - such as computer emergency response teams - with the space community .
Abdurahman AlHassan of the GCF highlighted that space cybersecurity cuts across geopolitical, economic, social, and technical dimensions, making it inherently a multinational concern . Pace concluded by underscoring the importance of shared interests between space-dependent developing nations and space-providing powers, and called for better translation between technical, legal, and policy communities as a foundational step towards effective coordination .
Overall, the discussion converged on the view that securing space infrastructure requires cross-sector collaboration, culturally sensitive engagement with the engineering community, and the integration of space into broader national and international cybersecurity strategies .
Overall Purpose
- The discussion aims to examine the cybersecurity challenges facing space-based infrastructure, explore the gap between the space and cybersecurity communities, and identify practical recommendations for improving the cyber resilience of space systems. It brings together experts from research, international standards bodies, national diplomacy, and global cybersecurity forums to build a shared framework for addressing these issues.
- --
Major Discussion Points
- **Space cybersecurity presents unique technical challenges that differ from terrestrial cybersecurity.Unlike ground-based systems, satellites cannot be physically accessed once launched, may experience long communication gaps, and operate in a hostile radiation environment that can corrupt memory systems, mimicking malicious attacks. These constraints make standard terrestrial cybersecurity practices necessary but insufficient, requiring specialised approaches such as autonomous intrusion detection, hardware-anchored secure boot processes, and resilience-focused architectures rather than purely preventative ones.
- There is a significant cultural and communicative divide between the space and cybersecurity communities that must be bridged. Dr Pace described a 'giant cultural chasm' between space professionals, who resist external instruction on how to manage their systems, and cybersecurity professionals, who apply strict protocols. This divide extends to policymakers, lawyers, and engineers, all of whom may believe they share a common language but do not, making translation across communities a central challenge. Encouraging bottom-up, engineer-led standards development was identified as a more effective path forward. - The international legal and governance framework for space cybersecurity remains underdeveloped, with standards and norms still emerging. Treaty law is largely silent on space cybersecurity, and while regional instruments such as the EU Space Act are in development, there is no overarching international standard. A spectrum of standards bodies - from IEEE to ISO to ITU - are developing relevant frameworks, but these involve different stakeholders and carry different levels of authority. Non-binding norms were recommended as a pragmatic near-term approach given the fast-moving nature of the domain. - Governments must integrate space into national cybersecurity strategies and leverage diplomatic coordination to manage cross-border risks. Australia's designation of space as one of its eleven critical national infrastructure sectors was cited as a concrete example of this approach. Diplomatic risks - including misattribution of incidents, escalation, and delayed detection - were highlighted as serious concerns, particularly in light of incidents such as the Viasat attack. Existing cybersecurity coordination mechanisms, such as CERTs, ISACs, and the International Watch and Warning Network, need to be more effectively connected to the space community. - Multi-stakeholder collaboration - spanning research institutions, governments, industry, and international bodies - is essential to translating findings into action. The joint research initiative between GCF, George Washington University's Space Policy Institute, and ITU was presented as a model for this kind of collaboration. GCF's involvement was framed around space's intersection with geopolitics, economics, social connectivity, and technical security - dimensions that cut across its broader mandate. Capacity building, workforce development, and cross-sectoral industry engagement were all identified as critical enablers.
- --
Overall Tone
- The overall tone of the discussion is constructive, collegial, and professionally urgent. From the outset, the moderator and panellists frame the conversation as timely and necessary, acknowledging that the international community is only beginning to grapple with these issues. Dr Pace's presentation carries a tone of measured concern, noting real and demonstrated threats while avoiding alarmism, and occasionally using dry humour to illustrate points - for example, describing satellites that still transmit in clear text as "raining data."
- As the panel discussion progresses, the tone becomes more collaborative and solution-oriented, with panellists building on each other's contributions rather than debating. Jessica Hunter's remarks introduce a slightly more diplomatic urgency, particularly around escalation risks and the need for clearer international norms. The closing remarks from Dr Pace and ITU representative strike a hopeful note, emphasising common interests and the value of the partnerships formed. Throughout, the tone remains measured and expert-driven, with no significant moments of tension or disagreement.
Expanded Summary: Securing Space-Based Infrastructure - Cybersecurity, Resilience, and International Coordination
#
Session Overview and Context
This session, held on the fifth day of the WSIS Forum and moderated by Gretchen Bueermann of ITU's Emerging Technologies Division, was convened under WSIS Action Line C5, which addresses building confidence and security in the use of ICTs . Bueermann opened by observing that space-based infrastructure underpins far more of daily life than most people realise, yet the frameworks governing space communications were written long before the international community had to contend with the cyber adversaries it faces today . She framed the session as a timely effort by the international community to coordinate and communicate about what it means to be cyber resilient and cyber secure in the context of space technology .
The discussion drew on a joint research initiative between the Global Cybersecurity Forum (GCF), George Washington University's Space Policy Institute, and the ITU, which is examining the main cyber threats to space systems and the measures that can improve their resilience and safety . The panel brought together Dr. Scott Pace, Director of the Space Policy Institute and Professor of the Practice of International Affairs at George Washington University's Elliott School of International Affairs, who is leading the research; Alexandra Vallet, Chief of the Space Services Department in ITU's Radio Communications Bureau; Jessica Hunter, Australia's Ambassador for Cyber Affairs and Critical Technology; and Abdurahman AlHassan, CEO of the Global Cybersecurity Forum .
---
#
The Unique Cybersecurity Challenges of Space Systems and Demonstrated Threats
Dr. Pace opened the substantive discussion by outlining why space cybersecurity presents challenges that are distinct from - and not fully addressed by - standard terrestrial cybersecurity practices . He identified three fundamental physical constraints that set space systems apart. First, satellites cannot be physically accessed once launched, making hardware replacement or manual intervention impossible . Second, space systems are not in continuous communication, and there may be long gaps between contact windows, unlike terrestrial or internet-based systems . Third, the space environment itself is hostile: radiation effects can corrupt memory systems in ways that are difficult to distinguish from deliberate malicious interference . These constraints mean that terrestrial good practices are, in Pace's words, "necessary but not sufficient" for space .
Pace also noted that space systems operate on long cycle times - a satellite launched today may remain in service for ten to fifteen years - making rapid software updates of the kind possible on consumer devices entirely impractical . They rely on very specialised protocols, a small global supply base for radiation-hardened components, and face severe size, weight, and power limitations . Taken together, these factors create a set of attack surfaces - across the space segment, the ground segment, and the link segment - that are both complex and difficult to defend using conventional means .
Pace was clear that the cyber threats facing space systems are not hypothetical . He described a range of demonstrated threats across the spectrum, from subtle malicious code insertion to blunt jamming and radio frequency interference of the kind seen in GPS systems and over conflict zones . The actors behind these threats range from hobbyists seeking to cause mischief to highly sophisticated nation-state actors . Despite this, Pace observed that many in the space community still operate by "security by obscurity" - assuming that their systems are too niche or unknown to attract attention - a posture he characterised as increasingly untenable .
One of the most striking vulnerabilities Pace highlighted was the prevalence of satellite systems that still transmit telemetry, tracking, and control data in clear text, describing the situation as "raining data" that anyone could collect . He also noted that in many organisations - particularly smaller and entrepreneurial new space startups - there is no designated chief information security officer, with responsibility for cybersecurity unclear or unassigned . Hunter added a segment-level analysis of vulnerabilities: the ground segment is highly interconnected and presents the greatest attack surface exposure; the user segment is most vulnerable due to human fallibility and poor hygiene; and communication links are particularly susceptible to interception and disruption . She also noted that the space segment itself, whilst requiring more sophisticated activity to disrupt from a cyber perspective, is not immune .
Alexandra Vallet of ITU's Radio Communications Bureau reinforced the point about the distinctiveness of space cybersecurity, warning that there is a tendency to replicate terrestrial cybersecurity approaches in the space domain "too much," and that this would be "a mistake" . She noted that satellite communications were historically a niche market, which made space cybersecurity unattractive to cybersecurity specialists and contributed to the current gap . Jessica Hunter, approaching the issue from a national cybersecurity diplomacy perspective, characterised space cybersecurity as "basics plus plus" - standard cyber hygiene applied as a foundation, with additional layers specific to the space domain built on top . While all three speakers agreed that space cybersecurity is distinct, they differed in how sharply they drew the line: Vallet's warning against replication was the most emphatic, whilst Hunter's framing implied a stronger degree of continuity with terrestrial practice.
---
#
Technical Recommendations and the Resilience Paradigm
Pace presented a set of foundational technical recommendations drawn from the joint research report. These include strong cryptography on telemetry, tracking, and control systems; hardware-anchored secure boot processes; multi-factor authentication; and network segmentation to prevent lateral movement across systems . He also emphasised the importance of autonomous intrusion detection systems, arguing that because satellites cannot rely on continuous ground-based monitoring, they must be capable of self-assessment - detecting anomalous commands and taking appropriate action without external intervention . He drew a parallel to broader AI discussions occurring at the conference about the ability to detect and then respond to threats .
A central conceptual contribution of Pace's presentation was his reframing of what constitutes good cybersecurity for space systems. Rather than measuring success by whether all intrusions are prevented - an impossible standard - he argued that the appropriate measure is resilience: specifically, the time taken to detect, resolve, and recover from an attack . This reflects a zero-trust architecture philosophy, which assumes that penetration will occur and designs systems accordingly . Hunter's recommendations for redundancy, clear incident response plans, and business continuity planning at the national and organisational level were consistent with this resilience-centred approach .
Pace also raised a technically nuanced tension that was not addressed by other panellists: the risk that implementing strong cryptographic systems - particularly hardware-anchored secure boot - could render a satellite permanently inoperable if radiation-induced memory corruption occurs, since the satellite cannot be physically accessed for recovery . He described this as a design challenge requiring careful balancing of cryptographic agility and storage resilience . He further noted that post-quantum cryptographic migration and key distribution in space present unique and as-yet-unresolved challenges, observing that key distribution on the ground is already difficult and that the space environment makes it considerably more so .
Pace also observed that the CIA triad - confidentiality, integrity, and availability - is weighted differently by different communities: security communities prioritise confidentiality, scientific users prioritise integrity, and commercial operators prioritise availability, meaning that not all standards will be equally valued by all stakeholders . This cross-cutting observation underscores why developing universally accepted space cybersecurity standards remains so challenging.
---
#
The Cultural Chasm Between Space and Cyber Communities
One of the most recurring themes across the panel was the cultural divide between the space engineering community and the cybersecurity community. Pace described this as "a giant cultural chasm," noting that space professionals resist being told what to do with their satellites, whilst cybersecurity professionals insist on practices that space operators find constraining . He acknowledged his own identity as a "space guy" navigating this divide, and suggested that it is probably easier to teach space concepts to a cybersecurity professional than to teach cybersecurity to a space professional .
Vallet located the cultural challenge more specifically within the space industry's historical preference for proprietary solutions, arguing that adopting common cybersecurity standards will be "a cultural challenge for space" . She identified research and academic communities as having a key role in driving this cultural change . Hunter confirmed the incompatibility from the cybersecurity side, noting that the standard cybersecurity instinct to "black box" capabilities for confidentiality is "not viable" for space assets, particularly those with national security implications, and that this is precisely where the two communities must come together .
Pace argued that the most promising path forward is not top-down compliance mandates - which space engineers resist - but rather engineer-led, bottom-up standards development that empowers technical communities to determine implementation methods within policy-defined performance goals . He recalled that early efforts to develop satellite cybersecurity standards about a decade ago failed partly because demand was insufficient , but expressed cautious optimism that demand is now increasing as broader consensus grows . Vallet similarly acknowledged that cultural change must precede effective standardisation - a notable point of convergence between a policy academic and an intergovernmental official .
---
#
The Governance and Legal Landscape
Pace provided a frank assessment of the international legal and governance framework for space cybersecurity: at the international level, treaty law is "pretty silent" . While regional instruments such as the EU Space Act are in development, these remain controversial, particularly among US companies uncertain about the standards that will apply . National licensing and regulation, as well as procurement requirements, are the primary levers currently available to governments seeking to induce better security behaviour among satellite operators .
A spectrum of standards bodies is developing relevant frameworks, from the highly technical IEEE - where engineers work largely without lawyers or politicians - through the International Standards Organisation, which incorporates national inputs and priorities, to the ITU, which has a formal voting structure and a broader range of stakeholders . These bodies produce outputs ranging from non-binding norms to detailed technical standards, and they involve different interest groups with different priorities .
Hunter was explicit in recommending that international negotiations should not aim to create new legal instruments, but should instead focus on developing shared expectations and non-binding norms, which offer greater flexibility and inclusivity given the fast-moving nature of the domain . She noted that international law already applies both in the digital space and offline, and that the challenge is less about creating new law than about connecting existing coordination mechanisms to the space community . This position was broadly consistent with Pace's pragmatic acknowledgement of the limits of current international governance.
---
#
National Governance: Australia's Approach and Diplomatic Risks
Hunter provided the most concrete national-level example of the session, disclosing that Australia has formally designated the space sector as one of eleven critical national infrastructure sectors, giving it additional protections and obligations under national law . She noted with satisfaction that several of Pace's recommendations were already embedded in Australia's systems of national significance .
Hunter identified three principal diplomatic risks arising from cyber incidents affecting space assets. The first is the risk of misunderstanding - specifically, whether an incident is a cyber attack or a physical accident - which can lead to different interpretations across governments . She referenced the Viasat incident as a concrete example of how different interpretations of standards, norms, and law can play out in practice . The second risk is escalation, arising from these differing interpretations . The third is the risk of delayed detection, resolution, and recovery, which compounds the first two . These diplomatic risks, she argued, directly inform the solutions that governments should pursue.
At the global level, Hunter advocated for continued development of non-binding norms and for connecting existing cybersecurity coordination mechanisms - including computer emergency response teams (CERTs), the International Watch and Warning Network, and Information Sharing and Analysis Centres (ISACs) - to the broader space community . She described the challenge as finding "the glue" to make these connections work . Pace also specifically highlighted the SpaceISAC - the Space Information Sharing and Analysis Center - as a dedicated coordination mechanism for the space community, distinct from the cyber ISACs serving terrestrial sectors such as financial networks, oil and gas, and transportation. At the regional level, Hunter highlighted the role of AP CERT in the Asia-Pacific region and Australia's co-chairmanship of PAXON, a community focused on CERT initiatives and cybersecurity response capabilities . At the national and organisational level, she recommended redundancy, clear agreements with providers, defined incident response and business continuity plans, clear role definition, and regular risk and vulnerability assessments . She also stressed that effective responses require cross-sectoral collaboration, bringing together not just the space sector but also the energy and telecommunications sectors .
---
#
The GCF's Perspective: Space as a Multi-Dimensional Global Challenge
AlHassan situated the GCF's involvement in space cybersecurity within the organisation's broader mandate to strengthen cybersecurity globally across five dimensions shaping cyberspace - geopolitics, economics, social and behavioural factors, and technical matters - noting that AlHassan named four of these five dimensions explicitly and observed that space cuts across four of them . From a geopolitical perspective, satellite constellations span borders, meaning that a cyber incident in orbit is inherently a multi-nation issue rather than a bilateral one . From an economic perspective, the space economy is heading towards trillions of dollars in value, and a satellite incident carries wide supply chain implications for the global economy . From a social perspective, space underpins connectivity, navigation, disaster response, and food security . From a technical perspective, satellites must be secure by design, since software embedded at launch may remain in operation for decades without the possibility of physical intervention .
AlHassan described the GCF's work as spanning strategic initiatives, research and publication, and the convening of global cybersecurity leaders - including an annual gathering in Duwad of over 10,000 participants from more than 100 countries . He highlighted two recently launched centres: one on cyber economics, developed in partnership with the World Economic Forum, and one on operational technology, developed with Aramco . The partnership with George Washington University's Space Policy Institute was framed as a natural extension of this work, given the convergence of growing dependence on space services and an expanding cyber threat landscape .
---
#
The Role of Research Institutions and Multi-Stakeholder Collaboration
Vallet identified two primary roles for research institutions in shaping the policy conversation on space cybersecurity. The first is to bring conceptual clarity - building a common language and framework that allows different communities to discuss the specificities of space cybersecurity in a coherent way . She argued that this is the most important and urgent contribution research institutions can make, and cited the joint GCF-GWU-ITU initiative as a positive step in this direction . The second role is to build stronger and more iterative standards for space cybersecurity, and to help drive the cultural change needed within the space industry to move away from proprietary solutions towards common protocols .
Pace concluded the panel by reflecting on the broader conditions for progress. Drawing on his experience in ITU spectrum negotiations, he observed that developing countries and space-capable nations share a common interest in the reliable functioning of space systems, since developing nations' infrastructure depends on GPS and satellite communications . He argued that this commonality of interest provides a natural foundation for building international consensus on space cybersecurity . He also returned to the theme of translation, describing policymaking as fundamentally a function of explaining things across technical, legal, and financial communities that all believe they share a common language but do not . This observation served as a fitting intellectual conclusion to the session, tying together the themes of cultural bridging, common language, and multi-stakeholder collaboration that had run throughout the discussion.
---
#
Non-Terrestrial Networks and Mobile-Satellite Convergence
An audience question on the convergence of satellite and mobile operators prompted Pace to address the emerging landscape of non-terrestrial network (NTN) standards. He noted that de facto security standards for NTNs are increasingly being driven by 3GPP, which governs billions of devices, and that these standards are being extended to integrate direct-to-device and LEO systems . The challenge lies in bridging the gap between the 3GPP non-trusted network environment, existing proprietary installed satellite systems, and future delay-tolerant networking architectures - including bundle protocols designed for solar system internet - which operate as overlay networks . Pace directed participants to monitor developments at the World Radiocommunication Conference 2027, particularly around direct-to-device discussions, as these will significantly shape the security protocols implementable across converged satellite-mobile environments . He acknowledged, however, that he could not point to a specific white paper or research project on concrete cybersecurity cooperation between satellite and mobile operators, leaving this as an open area for further investigation .
---
#
Closing Remarks and Institutional Acknowledgements
The session closed with remarks from Brita Malura of the ITU Secretary General's office, who expressed the ITU's gratitude to George Washington University and Dr. Pace for their leadership, and to the GCF and AlHassan personally for providing the GCF as a platform and for the generous support enabling the work . She noted that the ITU's contribution to the initiative spans the Radio Communications Bureau, the Development Bureau, the Standardisation Bureau, and the Secretary General's office, making it a truly organisation-wide collaborative effort . The ITU expressed its anticipation of the next iteration of the handbook and its commitment to continuing the collaboration .
Overall, the session converged on a clear set of conclusions: space cybersecurity is a distinct and urgent challenge that cannot be addressed by replicating terrestrial approaches; resilience and recovery capacity are the appropriate measures of success; the primary barriers are as much cultural and organisational as they are technical; multi-stakeholder and cross-sectoral collaboration is indispensable; and non-binding norms, combined with national regulatory levers such as licensing and procurement, represent the most pragmatic near-term governance pathway . The joint research initiative between GCF, George Washington University, and ITU was consistently cited as a model for the kind of collaboration needed to translate these insights into action .
Space systems have distinct attack surfaces across space, ground, and link segments that differ fundamentally from terrestrial systems - Space is physically inaccessible once launched, operates on long cycle times, and faces hostile radiation environments that complicate standard cybersecurity approaches
Arg. 1Dr. Pace argues that space systems present unique cybersecurity challenges because satellites cannot be physically accessed once launched, may operate for 10–15 years without hardware upgrades, and exist in a hostile radiation environment that can cause memory corruption indistinguishable from a malicious attack. Each segment — space, ground, and link — has its own distinct attack surface, and the complexity of these systems creates multiple potential entry points for adversaries.
Dr. Pace noted that satellites, once launched, cannot be physically touched for repairs or replacements , that there may be long gaps in communication with satellites unlike terrestrial systems , and that the space environment can cause radiation-induced memory upsets that are difficult to distinguish from malicious interference . He also highlighted that the more complex a system becomes, the more attack routes exist .
Terrestrial cybersecurity good practices are necessary but not sufficient for space, as satellites cannot be physically accessed for upgrades, have intermittent communications, and run on specialised protocols
Arg. 2Dr. Pace contends that while terrestrial cybersecurity lessons are valuable and applicable, they cannot simply be transplanted into the space domain. The physical inaccessibility of satellites, their long operational lifespans, specialised supply chains, and severe size, weight, and power constraints mean that space cybersecurity requires adapted and additional measures beyond standard ground-based practices.
Dr. Pace stated that terrestrial good practices are not really good enough for space , citing physical inaccessibility, long cycle times of up to 15 years , a very small global supply base for radiation-hardened parts , and severe size, weight, and power limitations alongside specialised protocols .
on: Space cybersecurity presents unique challenges that cannot be addressed by simply replicating terrestrial cybersecurity approaches
on: The extent to which terrestrial cybersecurity practices can and should be applied to space systems
There is a significant cultural chasm between the space and cyber communities, with space professionals resistant to external mandates and cyber professionals unfamiliar with space constraints
Arg. 3Dr. Pace identifies a deep cultural divide between the space and cybersecurity communities as a major obstacle to improving space cybersecurity. Space professionals tend to resist being told how to manage their systems, while cyber professionals may apply terrestrial rules without understanding the unique constraints of space operations.
Dr. Pace described himself as 'a space guy, not a cyber guy' and noted there is 'a giant cultural chasm between those communities,' with space people resisting being told what to do with their satellites and cyber people insisting on certain practices . He also noted that many satellite operators still transmit telemetry in clear text, suggesting a lack of basic cyber awareness in the space community .
on: Workforce development and capacity building are essential components of improving space cybersecurity
on: The appropriate role of top-down regulatory mandates versus bottom-up engineering-led standards in driving space cybersecurity improvements
Diverse and demonstrated cyber threats already exist across space systems, ranging from subtle malicious code insertion to blunt jamming and RF interference, perpetrated by actors from hobbyists to sophisticated nation-states
Arg. 4Dr. Pace emphasises that cyber threats to space systems are not hypothetical but have already been demonstrated in practice. The threat landscape spans a wide spectrum of sophistication, from amateur actors seeking to cause mischief to highly capable nation-state adversaries.
Dr. Pace noted that threats range from subtle actions like inserting malicious code to blunt methods like jamming and RF interference seen in the GPS domain and over conflict zones , and that perpetrators range from hobbyists to sophisticated nation-state actors . He stressed that these threats are not hypothetical .
Many satellite operators still transmit telemetry in clear text, representing a fundamental and easily exploitable vulnerability
Arg. 5Dr. Pace highlights that a surprisingly large number of satellite systems transmit their telemetry, tracking, and control data in unencrypted clear text, representing one of the most basic and easily exploitable security failures in the space sector. This reflects a broader culture of security through obscurity that pervades parts of the space industry.
Dr. Pace expressed amazement at the number of satellite systems that still transmit in clear text, using the vivid analogy that 'it's raining data, go out and get a bowl, and here it is' . He also noted that many space operators still rely on security through obscurity, assuming no one will pay attention to them .
Strong cryptography on telemetry, tracking, and control, hardware-anchored secure boot processes, multi-factor authentication, and network segmentation are foundational technical measures for space cybersecurity
Arg. 6Dr. Pace outlines a set of foundational technical recommendations for improving space cybersecurity, beginning with basic measures such as encrypting telemetry data and progressing to more sophisticated approaches like hardware-anchored secure boot and network segmentation. These measures form the baseline from which more advanced resilience strategies can be built.
Dr. Pace recommended strong cryptography on telemetry, tracking, and control , hardware-anchored secure boot processes , multi-factor authentication , and network segmentation to prevent unrestricted lateral movement across systems .
Autonomous intrusion detection systems are essential for space assets due to intermittent contact and physical inaccessibility, requiring satellites to monitor their own state and detect anomalous commands
Arg. 7Because satellites are far from Earth and only intermittently in contact with ground stations, they cannot rely on external monitoring for security. Dr. Pace argues that satellites must therefore be equipped with autonomous intrusion detection capabilities that allow them to assess their own operational state and identify potentially malicious commands.
Dr. Pace explained that because satellites are far from Earth and have intermittent contact, an autonomous intrusion detection system becomes important . He gave the example that if a satellite receives a command to perform a re-entry burn when it should be cruising to Mars, it should be able to recognise that something is wrong .
The measure of resilience should be the time taken to detect, resolve, and recover from an attack rather than whether a penetration has occurred, reflecting a zero-trust architecture approach
Arg. 8Dr. Pace advocates for a shift in how cybersecurity success is measured in the space domain, moving away from the goal of preventing all intrusions towards measuring how quickly a system can detect, respond to, and recover from an attack. This zero-trust approach assumes that breaches will occur and focuses on minimising their impact and duration.
Dr. Pace stated that the measure of goodness is not the time between attacks but rather the time it takes to resolve an attack and restore the system . He referenced zero-trust architectures as an approach that assumes penetration will occur .
on: Resilience — the ability to detect, respond to, and recover from attacks — is the appropriate measure of cybersecurity success for space systems, rather than the prevention of all intrusions
Post-quantum cryptographic migration and key distribution in space present unique challenges that require careful balancing against the risk of rendering satellites inoperable due to radiation-induced memory corruption
Arg. 9Dr. Pace identifies post-quantum cryptography migration as a particularly complex challenge for space systems, compounded by the difficulty of distributing cryptographic keys to satellites. There is a tension between implementing strong cryptographic systems and the risk that radiation-induced memory corruption could render a satellite permanently inoperable if it cannot be physically accessed for recovery.
Dr. Pace noted that key distribution in space is far more difficult than on the ground , and that if a strong cryptographic system is in place and radiation corrupts memory or storage, the satellite could become a 'brick' with no means of recovery since it cannot be physically accessed . He described this as a design challenge requiring careful balancing of agility and resilience .
International treaty law is largely silent on space cybersecurity, leaving licensing, national regulation, and procurement as the primary levers for inducing better security behaviour
Arg. 10Dr. Pace observes that there is no comprehensive international treaty or binding legal framework specifically addressing space cybersecurity. In the absence of such instruments, governments must rely on national licensing regimes, regulatory requirements, and procurement standards to drive improved security practices among satellite operators.
Dr. Pace stated that at the international level, treaty law is 'pretty silent' on space cybersecurity , and identified national licensing, regulation, and procurement as the primary tools available . He also noted the European Union's proposed Space Act as an example of regional regulatory effort, albeit a controversial one .
on: Existing governance and legal frameworks are inadequate for addressing space cybersecurity, and non-binding norms offer a more flexible and practical path forward than new binding legal instruments
on: Whether international governance of space cybersecurity should pursue new binding legal instruments or focus on non-binding norms and shared expectations
A spectrum of standards bodies — from IEEE to ISO to ITU — are developing space cybersecurity standards, each with different stakeholder compositions and levels of binding authority
Arg. 11Dr. Pace describes a diverse ecosystem of standards organisations working on space cybersecurity, ranging from highly technical engineering bodies like IEEE to intergovernmental organisations like ITU. Each body brings different stakeholder interests and operates with different levels of authority, creating a complex but evolving standards landscape.
Dr. Pace described IEEE as very technically focused with engineers solving problems , ISO as incorporating national inputs and priorities , and ITU as having a voting structure with national representation . He noted that standards range from non-binding norms to detailed technical standards .
There is a commonality of interest between space-capable nations and developing nations that depend on space systems, which can serve as a foundation for building international consensus on space cybersecurity
Arg. 12Drawing on his experience in ITU spectrum negotiations, Dr. Pace argues that there is a natural alignment of interests between countries that operate space systems and developing nations that depend on those systems for their infrastructure. This shared interest can serve as a basis for building international cooperation on space cybersecurity.
Dr. Pace recounted his experience working on ITU spectrum issues, where developing countries supported space system interests because their own infrastructure depended on systems like GPS and satellite communications . He drew a parallel to cybersecurity, arguing that both space-capable and space-dependent nations share a common interest in securing these systems .
Space cybersecurity must be integrated into national cyber strategies rather than treated as a separate domain, and governments should use procurement and licensing as levers to drive security improvements
Arg. 13Dr. Pace recommends that governments treat space cybersecurity as an integral component of their broader national cybersecurity strategies rather than a niche concern for the space sector alone. He also advocates for using the practical tools of procurement requirements and licensing conditions to incentivise better security practices across the industry.
Among his recommendations for governments, Dr. Pace listed integrating space into national cyber strategies rather than keeping it separate, and using licensing and procurement as levers for inducing better security behaviour . He also recommended international consultations through mechanisms including ITU and investing in the workforce .
on: Space-based infrastructure must be recognised and treated as critical infrastructure
Effective policymaking in this domain requires a translation function between technical engineering communities, legal communities, and financial communities, all of whom believe they share a common language but do not
Arg. 14Dr. Pace argues that one of the most important and underappreciated roles in space cybersecurity policymaking is that of the translator — someone who can bridge the communication gaps between technical engineers, lawyers, and financial professionals. Each community operates with its own assumptions and vocabulary, and misunderstandings between them impede effective policy development.
Dr. Pace told his students that 'a lot of what policymaking is is a translation function,' explaining things across technical, legal, and financial communities that all believe they are speaking the same language but are not . He also noted the cultural divide between space and cyber communities as a specific example of this broader challenge .
on: Multi-stakeholder and cross-sectoral collaboration is essential for addressing space cybersecurity effectively
De facto security standards for non-terrestrial networks are increasingly being driven by 3GPP, which governs billions of devices, and these standards are being extended to integrate direct-to-device and LEO systems
Arg. 15Dr. Pace explains that because 3GPP governs the standards for billions of mobile devices, its non-terrestrial network standards are becoming the de facto security baseline for satellite-mobile convergence. These standards are now being extended to cover new direct-to-device and LEO satellite systems, creating both opportunities and challenges for the space cybersecurity community.
Dr. Pace confirmed that de facto security standards are being driven by 3GPP through its non-terrestrial network standards, given the scale of billions of devices governed by these standards . He noted that these standards are being extended to integrate direct-to-device and LEO systems .
The challenge lies in bridging the gap between the 3GPP non-trusted network environment, existing proprietary installed systems, and future delay-tolerant networking architectures such as bundle protocols for solar system internet
Arg. 16Dr. Pace identifies a three-way architectural challenge in the convergence of satellite and mobile networks: reconciling the 3GPP non-trusted network model with the large installed base of proprietary satellite systems, while also preparing for future delay-tolerant networking architectures designed for deep space communications. Navigating these three layers simultaneously is a significant technical and governance challenge.
Dr. Pace described the challenge of moving from the 3GPP non-trusted network reality, through existing proprietary installed systems in LEO and geostationary orbit, to future delay-tolerant networking using bundle protocols, which he described as an overlay network . He also mentioned the possibility of a separate lecture on solar system internet as an illustration of the complexity involved .
Developments at World Radiocommunication Conference 2027 around direct-to-device discussions will significantly shape the security protocols implementable across converged satellite-mobile environments
Arg. 17Dr. Pace points to the upcoming World Radiocommunication Conference 2027 as a critical juncture for the future of security protocols in converged satellite-mobile environments. The decisions made there around direct-to-device communications will have downstream implications for what security measures can practically be implemented.
Dr. Pace advised the audience to look for developments at WRC-27 as direct-to-device discussions occur, because these will affect the environment for security protocols that are going to be implementable .
Space cybersecurity has historically been unattractive to cybersecurity specialists due to satellite communications being a niche market, leading to over-reliance on replicating terrestrial approaches, which would be a mistake
Arg. 1Alexandre Vallet argues that because satellite communications were historically a niche market, they did not attract significant attention from cybersecurity specialists. This has led to a tendency to simply replicate terrestrial cybersecurity approaches when addressing space cybersecurity, which he considers a mistake given the fundamental differences of the space domain.
Vallet noted that historically, space cybersecurity was not attractive for cybersecurity specialists because satellite communications were a niche market , and that there is now a tendency to replicate terrestrial cybersecurity approaches too much, which he characterised as a mistake .
on: Space cybersecurity presents unique challenges that cannot be addressed by simply replicating terrestrial cybersecurity approaches
on: The extent to which terrestrial cybersecurity practices can and should be applied to space systems
Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions and building a common language and framework for policy conversations
Arg. 2Vallet identifies the primary role of research institutions in space cybersecurity as bringing clarity to the concepts being discussed and establishing a common language that can underpin policy conversations. Without this conceptual foundation, he argues, policy discussions risk being built on misunderstandings or misaligned assumptions.
Vallet stated that the most important and urgent role of research institutes is to bring clarity to the concepts being discussed , and that a common language and framework are needed to address the specificities of space cybersecurity in policy conversations . He cited Dr. Pace's presentation as an excellent example of this .
on: Workforce development and capacity building are essential components of improving space cybersecurity
on: The appropriate role of top-down regulatory mandates versus bottom-up engineering-led standards in driving space cybersecurity improvements
The space industry's historical preference for proprietary solutions represents a cultural challenge to adopting common cybersecurity standards, and the research and academic community can help drive that cultural change
Arg. 3Vallet highlights that the space industry's long-standing preference for proprietary, bespoke solutions creates a cultural barrier to the adoption of common cybersecurity standards. He argues that the research and academic community has an important role to play in shifting this culture towards standardised approaches.
Vallet noted that the space industry has historically been very keen on proprietary solutions, and that adopting common standards on space cybersecurity will be a cultural challenge . He argued that researchers and academics can help change this culture and move the industry towards standardised cybersecurity protocols .
on: There is a significant cultural gap between the space and cybersecurity communities that must be bridged
on: Where the primary locus of cultural resistance to space cybersecurity improvement lies and who bears responsibility for change
Cybersecurity for space assets cannot simply black-box capabilities as it would in terrestrial contexts, because space assets are national security assets requiring a different marriage of expertise
Arg. 1Hunter argues that the standard cybersecurity approach of black-boxing a capability to ensure confidentiality and protection is not viable for space assets, which are national security assets with specific operational requirements. This necessitates a unique collaboration between cybersecurity experts and space experts that goes beyond conventional cybersecurity practice.
Hunter stated that cybersecurity will always black-box a capability to ensure it is confidential and protected, but that this is not viable for space assets given their national security status . She argued that this is where the marriage between cybersecurity experts and space experts needs to come together .
on: There is a significant cultural gap between the space and cybersecurity communities that must be bridged
The ground segment is highly interconnected and presents the greatest attack surface exposure, while the user segment is most vulnerable due to human fallibility and poor hygiene
Arg. 2Hunter identifies the ground segment and user segment as the most practically vulnerable parts of the space system architecture. The ground segment's high degree of interconnection creates broad exposure, while the user segment is compromised by human error and poor cybersecurity hygiene.
Hunter described the ground segment as highly interconnected with the greatest risk of attack surface exposure , and the user segment as most at risk because humans are fallible and configure end-user capabilities poorly, with the greatest degree of poor hygiene .
Communication links are particularly vulnerable to interception and disruption
Arg. 3Hunter highlights communication links as a distinct and particularly vulnerable attack surface within the space system architecture, susceptible to both interception of data and disruption of the communications themselves.
Hunter stated that the communications links segment is 'obviously very vulnerable to interception and disruption' .
Cybersecurity for space is essentially "basics plus plus" — standard cyber hygiene applied with additional layers specific to the space domain, including redundancy, clear incident response plans, and regular vulnerability assessments
Arg. 4Hunter characterises space cybersecurity as building upon standard cybersecurity fundamentals rather than replacing them, describing it as 'basics plus plus.' The additional layers required for space include redundancy in communications paths, clear agreements with providers, defined roles and responsibilities, and regular risk and vulnerability assessments.
Hunter agreed with Dr. Pace that space cybersecurity cannot be exactly the same as terrestrial cybersecurity, describing it as 'basics plus plus in space' . She listed recommendations including redundancy and communications path planning, clear agreements with providers, incident response and business continuity plans, clear role definition, and regular risk and vulnerability assessments .
on: Resilience — the ability to detect, respond to, and recover from attacks — is the appropriate measure of cybersecurity success for space systems, rather than the prevention of all intrusions
on: The extent to which terrestrial cybersecurity practices can and should be applied to space systems
Rather than creating new legal instruments, governments should focus on shared expectations and non-binding norms, which offer greater flexibility and inclusivity given the fast-moving nature of the domain
Arg. 5Hunter recommends that international negotiations on space cybersecurity governance should prioritise the development of shared expectations and non-binding norms rather than attempting to create new binding legal instruments. She argues that the flexibility and inclusivity of non-binding norms are better suited to the rapidly evolving nature of the space cybersecurity domain.
Hunter recommended that negotiations continue not to create new legal instruments but to focus on shared expectations and non-binding norms, noting that these offer more flexibility and inclusivity given the fast-moving nature of the domain .
on: Existing governance and legal frameworks are inadequate for addressing space cybersecurity, and non-binding norms offer a more flexible and practical path forward than new binding legal instruments
on: Whether international governance of space cybersecurity should pursue new binding legal instruments or focus on non-binding norms and shared expectations
Australia has designated the space sector as one of eleven critical national infrastructure sectors, embedding additional protections and obligations at the national level
Arg. 6Hunter highlights Australia's decision to formally designate the space sector as critical national infrastructure as a concrete example of how governments can embed space cybersecurity into their national frameworks. This designation brings additional legal protections and obligations that apply to space capabilities.
Hunter stated that under Australia's eleven sectors of critical national infrastructure, the space sector and space capabilities have been designated, giving them additional protections and obligations from a national perspective . She also noted that some of Dr. Pace's recommendations are already embedded in Australia's systems of national significance .
on: Space-based infrastructure must be recognised and treated as critical infrastructure
on: The appropriate role of top-down regulatory mandates versus bottom-up engineering-led standards in driving space cybersecurity improvements
The cross-border nature of space infrastructure creates diplomatic risks including misunderstanding of whether an incident is a cyber attack or a physical accident, risk of escalation, and delays in detection and resolution
Arg. 7Hunter identifies three distinct diplomatic risks arising from the cross-border nature of space infrastructure: the risk of misunderstanding whether an incident is a cyber attack or a physical accident, the risk of escalation due to differing interpretations, and the risk of delays in detecting, resolving, and recovering from incidents. These risks have real-world implications for international relations.
Hunter described the risk of misunderstanding - whether an incident is a cyber attack or a physical accident - as a key diplomatic risk , noting that this can lead to escalation or different government responses . She referenced the Viasat incident as an example of different interpretations of standards, norms, and law playing out . She also identified the risk of delay in detection, resolution, and resilience-building as a third diplomatic risk .
Existing cybersecurity coordination mechanisms such as computer emergency response teams, the International Watch and Warning Network, and ISACs need to be plugged into the broader space community
Arg. 8Hunter argues that the cybersecurity community already has well-established coordination mechanisms for sharing information and responding to incidents, but that these need to be connected to the space community. The challenge is not creating new mechanisms but rather integrating existing ones with the space sector.
Hunter noted that at the global level, computer emergency response teams understand tactical and operational information sharing during incidents , the International Watch and Warning Network can identify risks , and there is a range of points of contact under global mechanisms . She identified the challenge as 'the glue of how we plug that into the broader space community' .
Cross-sectoral collaboration — bringing together the space, energy, and telecommunications sectors — is essential for effective national cybersecurity responses to space-related threats
Arg. 9Hunter emphasises that effective national cybersecurity responses to space-related threats cannot be confined to the space sector alone. The energy and telecommunications sectors are deeply intertwined with space capabilities, and meaningful cybersecurity responses require collaboration across all three sectors.
Hunter stated that the partnership between government and industry is incredibly important and that in Australia it has to be cross-sectoral, bringing together not just the space sector but also the energy and telco sectors when addressing the cybersecurity component .
on: Multi-stakeholder and cross-sectoral collaboration is essential for addressing space cybersecurity effectively
Space cybersecurity cuts across geopolitical, economic, social, and technical dimensions, meaning a cyber incident in orbit is not a single-nation issue but a global one with wide supply chain implications
Arg. 1AlHassan argues that space cybersecurity is distinctive because it intersects with four of the five dimensions that shape cyberspace: geopolitics, economics, social issues, and technical matters. A cyber incident affecting space infrastructure therefore has implications that extend far beyond any single nation, affecting global supply chains, economies, and societies.
AlHassan stated that space cuts across four of the five dimensions shaping cyberspace - geopolitics, economics, social, and technical . He noted that a cyber incident in orbit is not a one-nation issue but an issue of many nations , and that a satellite issue is not just about the satellite but has wider implications for the global economy through supply chains . He also cited connectivity, navigation, and disaster response as social dimensions of space .
on: Space-based infrastructure must be recognised and treated as critical infrastructure
The partnership between GCF, George Washington University's Space Policy Institute, and ITU exemplifies the kind of multi-stakeholder collaboration needed to translate expert insights into actionable policy
Arg. 2AlHassan presents the collaboration between GCF, George Washington University's Space Policy Institute, and ITU as a model for the kind of multi-stakeholder partnership needed to address space cybersecurity effectively. He argues that this partnership bridges the gap between research, policy, and operational expertise.
AlHassan described GCF's partnership with the Space Policy Institute at George Washington University as distinctive because it brings together established space powers and new operators, characterising this bridge-building as a serious response to the challenge . He also outlined GCF's three working methods - strategic initiatives, research, and convening global leaders - as the basis for this collaboration .
on: Multi-stakeholder and cross-sectoral collaboration is essential for addressing space cybersecurity effectively
GCF works across five dimensions — geopolitics, economics, social and behavioural, and technical — and space cuts across four of these, making it a natural and important focus for the organisation
Arg. 3AlHassan explains that GCF's mandate spans five dimensions of cyberspace, and that space cybersecurity is relevant to four of them, making it a natural and strategically important area of focus for the organisation. This breadth of relevance justifies GCF's investment in space cybersecurity research and collaboration.
AlHassan stated that GCF's work spans five dimensions - geopolitics, economics, social and behavioural, and technical - and that space cuts across four of these . He elaborated on each dimension: geopolitical because space spans borders , economic because of supply chain implications , social because of connectivity and disaster response , and technical because systems must be secure by design and software persists for decades .
ITU's contribution to this work spans the Radio Communications Bureau, the Development Bureau, the Standardisation Bureau, and the Secretary General's office, reflecting a truly organisation-wide collaborative effort
Arg. 1The unnamed ITU speaker emphasises that ITU's engagement with the space cybersecurity research initiative is not confined to a single bureau or department but represents a genuinely organisation-wide effort. This breadth of institutional involvement underscores the importance ITU places on this work.
The speaker noted that within ITU, the work is truly collaborative, involving the Radio Communications Bureau headed by Alexandre Vallet, colleagues from the Development Bureau, the Standardisation Bureau, and the Secretary General's office . The speaker described it as 'truly an ITU-wide effort' in supporting the work of George Washington University and GCF .
The question of concrete cooperation examples between satellite and mobile operators on cybersecurity reflects a growing and important area of practical convergence that the industry is actively working through
Arg. 1An audience member raises the question of whether there are concrete examples of cooperation between satellite operators and mobile operators specifically on cybersecurity, in the context of the growing convergence between non-terrestrial networks and mobile systems. This reflects a practical interest in understanding how the industry is operationalising the theoretical frameworks discussed.
The audience member noted the increasing cooperation between satellite operators and mobile operators in the context of NTN and mobile convergence, and asked whether there are any concrete examples of such cooperation specifically in the area of security and cybersecurity .
Space-based infrastructure underpins far more of daily life than most people realise, yet the frameworks governing it were written before modern cyber adversaries existed
Arg. 1Bueermann opens the session by noting that space infrastructure is deeply embedded in daily life, but that the regulatory and governance frameworks designed to protect it predate the sophisticated cyber threats we face today. This gap between the age of the frameworks and the current threat landscape is a central motivation for the session.
Bueermann stated that space-based infrastructure underpins far more of daily life than people realise , and that the frameworks governing space communications and technology were written long before the international community had to contend with today's cyber adversaries .
The international community is beginning to coordinate on what cyber resilience and cyber security mean specifically in the context of space technology
Arg. 2Bueermann observes that there is a growing recognition among international actors of the need to coordinate and communicate about cyber resilience as it applies to space technology. This emerging coordination represents a positive development, though it is still in its early stages.
Bueermann noted that the international community is starting to think about how to coordinate and communicate about what it means to be cyber resilient and cyber secure when it comes to space technology .
Space-based technologies are rapidly demanding recognition as critical digital infrastructure, alongside other sectors such as transportation, finance, and energy
Arg. 3Bueermann argues that space-based technologies should be classified and treated as critical infrastructure, a label that is increasingly appropriate given how much other critical sectors depend on space systems. This framing is important for driving appropriate levels of protection and governance attention.
Bueermann introduced the panellists working on cyber resilience for critical infrastructure and stated that space-based technologies are rapidly demanding that label .
on: Space-based infrastructure must be recognised and treated as critical infrastructure
The joint research initiative between GCF, George Washington University's Space Policy Institute, and ITU represents a valuable model of multi-stakeholder collaboration for addressing space cybersecurity
Arg. 4Bueermann highlights the collaborative research initiative as an example of the kind of partnership needed to tackle complex, cross-cutting issues like space cybersecurity. The initiative brings together expertise from international organisations, academia, and civil society to examine threats and resilience measures.
Bueermann explained that the foundational questions for the session came from a joint research initiative between GCF, George Washington University's Space Policy Institute, and ITU, working to examine the main cyber threats to space systems and measures to improve their resilience and safety . She expressed gratitude to GCF for supporting the initiative and to Dr. Pace for leading the work .
on: Multi-stakeholder and cross-sectoral collaboration is essential for addressing space cybersecurity effectively
Effective responses to space cybersecurity challenges require bringing together diverse perspectives, including those from the space domain, the cybersecurity domain, and national cybersecurity diplomacy
Arg. 5Bueermann emphasises that addressing space cybersecurity requires a genuinely diverse set of perspectives and expertise, spanning the space sector, the cybersecurity community, and the diplomatic sphere. The composition of the panel itself is presented as a deliberate reflection of this need for diversity.
Bueermann noted the diversity of views represented on the panel, including those approaching the issue from the space perspective, those working on cyber resilience for critical infrastructure, and those engaged in national cybersecurity diplomacy . She framed the session as an attempt to tackle these issues through this diversity of expertise .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Dr. Pace argued that terrestrial good practices are 'not really good enough' for space due to physical inaccessibility, long cycle times, and specialised protocols . Vallet warned that there is a tendency to replicate terrestrial cybersecurity approaches 'too much,' characterising this as 'a mistake' . Hunter agreed with Pace that space cybersecurity 'cannot be exactly the same as cybersecurity,' describing it as 'basics plus plus in space' . All three converged on the view that space requires adapted and additional measures beyond standard ground-based practices.
Terrestrial cybersecurity good practices are necessary but not sufficient for space, as satellites cannot be physically accessed for upgrades, have intermittent communications, and run on specialised protocols
Space cybersecurity has historically been unattractive to cybersecurity specialists due to satellite communications being a niche market, leading to over-reliance on replicating terrestrial approaches, which would be a mistake
Cybersecurity for space is essentially "basics plus plus" — standard cyber hygiene applied with additional layers specific to the space domain, including redundancy, clear incident response plans, and regular vulnerability assessments
Pace recommended that space systems be recognised as serving multiple critical infrastructure sectors and integrated into national cyber strategies . Hunter confirmed that Australia has formally designated the space sector under its eleven critical national infrastructure sectors . AlHassan argued that a satellite issue is not just about the satellite but has wider implications for the global economy through supply chains . Bueermann framed space-based technologies as 'rapidly demanding' the label of critical digital infrastructure . All four speakers converged on the necessity of treating space as critical infrastructure deserving commensurate protection.
Space cybersecurity must be integrated into national cyber strategies rather than treated as a separate domain, and governments should use procurement and licensing as levers to drive security improvements
Australia has designated the space sector as one of eleven critical national infrastructure sectors, embedding additional protections and obligations at the national level
Space cybersecurity cuts across geopolitical, economic, social, and technical dimensions, meaning a cyber incident in orbit is not a single-nation issue but a global one with wide supply chain implications
Space-based technologies are rapidly demanding recognition as critical digital infrastructure, alongside other sectors such as transportation, finance, and energy
Pace described policymaking as a 'translation function' across technical, legal, and financial communities . Vallet identified research institutions as critical for building a common language and framework for policy conversations . Hunter stressed that effective responses require cross-sectoral collaboration bringing together the space, energy, and telco sectors . AlHassan presented the GCF-GWU-ITU partnership as a model of bridge-building between established space powers and new operators . Bueermann highlighted the joint research initiative as a valuable example of multi-stakeholder collaboration . All speakers consistently emphasised the need for diverse partnerships.
Effective policymaking in this domain requires a translation function between technical engineering communities, legal communities, and financial communities, all of whom believe they share a common language but do not
Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions and building a common language and framework for policy conversations
Cross-sectoral collaboration — bringing together the space, energy, and telecommunications sectors — is essential for effective national cybersecurity responses to space-related threats
The partnership between GCF, George Washington University's Space Policy Institute, and ITU exemplifies the kind of multi-stakeholder collaboration needed to translate expert insights into actionable policy
The joint research initiative between GCF, George Washington University's Space Policy Institute, and ITU represents a valuable model of multi-stakeholder collaboration for addressing space cybersecurity
Pace described 'a giant cultural chasm between those communities,' noting that space people resist being told what to do with their satellites while cyber people insist on certain practices . Vallet noted that the space industry's preference for proprietary solutions means that adopting common standards will be 'a cultural challenge for space' , and argued that researchers and academics can help change this culture . Hunter observed that the standard cybersecurity approach of black-boxing capabilities is 'not viable' for space assets, requiring a unique marriage of cybersecurity and space expertise . All three identified cultural bridging as a prerequisite for progress.
There is a significant cultural chasm between the space and cyber communities, with space professionals resistant to external mandates and cyber professionals unfamiliar with space constraints
The space industry's historical preference for proprietary solutions represents a cultural challenge to adopting common cybersecurity standards, and the research and academic community can help drive that cultural change
Cybersecurity for space assets cannot simply black-box capabilities as it would in terrestrial contexts, because space assets are national security assets requiring a different marriage of expertise
Pace stated that at the international level, treaty law is 'pretty silent' on space cybersecurity , and identified national licensing, regulation, and procurement as the primary tools available . Hunter recommended that negotiations continue 'not to create new legal instruments' but to focus on shared expectations and non-binding norms, noting these offer 'more flexibility and inclusivity given the fast-moving nature of the domain' . Both speakers converged on the view that soft law and practical governance levers are more appropriate than new binding treaties at this stage.
International treaty law is largely silent on space cybersecurity, leaving licensing, national regulation, and procurement as the primary levers for inducing better security behaviour
Rather than creating new legal instruments, governments should focus on shared expectations and non-binding norms, which offer greater flexibility and inclusivity given the fast-moving nature of the domain
Pace noted that it is 'probably easier to teach space to a cyber person than it is to teach cyber to a space person' and emphasised investing in the workforce as a key recommendation . He also recommended that governments invest in workforce development as part of integrating space into national cyber strategies . Vallet argued that research and academic communities can help change the space industry's culture towards standardised cybersecurity approaches . Both speakers identified education and capacity building as fundamental to closing the gap between the space and cyber communities.
There is a significant cultural chasm between the space and cyber communities, with space professionals resistant to external mandates and cyber professionals unfamiliar with space constraints
Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions and building a common language and framework for policy conversations
Pace stated that 'the measure of goodness is not is there an infinite time between attacks, but rather what's the time it takes to resolve that attack,' referencing zero-trust architectures that assume penetration will occur . Hunter's recommendations for space cybersecurity included clear incident response plans and business continuity plans as core components , and she described space cybersecurity as 'basics plus plus' built on a foundation of resilience . Both speakers framed resilience and recovery capacity as the central goal rather than impenetrable defence.
The measure of resilience should be the time taken to detect, resolve, and recover from an attack rather than whether a penetration has occurred, reflecting a zero-trust architecture approach
Cybersecurity for space is essentially "basics plus plus" — standard cyber hygiene applied with additional layers specific to the space domain, including redundancy, clear incident response plans, and regular vulnerability assessments
Both Pace and AlHassan emphasised the multi-dimensional and cross-border nature of space cybersecurity. Pace noted that space systems serve multiple critical infrastructure sectors and recommended integrating space into national cyber strategies , while AlHassan argued that space cuts across four of the five dimensions shaping cyberspace — geopolitics, economics, social, and technical — and that a cyber incident in orbit is 'not a one-nation issue but an issue of many nations' . Both speakers framed space cybersecurity as inherently global and cross-sectoral rather than a niche technical concern. Both Pace and Hunter drew on demonstrated real-world incidents to illustrate the threat landscape. Pace noted that threats range from subtle malicious code insertion to blunt jamming and RF interference, and that these threats are 'not hypothetical' . Hunter referenced the Viasat incident as a concrete example of how different interpretations of standards, norms, and law can play out when a cyber incident affects space infrastructure . Both speakers used empirical examples to underscore the urgency of the issue and the complexity of attribution and response. Both Vallet and Hunter identified the need to connect existing communities and mechanisms rather than building entirely new ones. Vallet argued that a common language and framework are needed to bridge the gap between space and cybersecurity communities in policy conversations . Hunter noted that existing cybersecurity coordination mechanisms — CERTs, the International Watch and Warning Network, and ISACs — already exist and 'just now need to plug into the space community,' describing the challenge as finding 'the glue of how we plug that into the broader space community' . Both speakers emphasised integration and connection over the creation of new structures. Both Pace and Vallet identified the development of common standards as a critical but culturally challenging endeavour for the space industry. Pace described a spectrum of standards organisations from IEEE to ISO to ITU, each with different stakeholder compositions and levels of authority , and noted that the space community's resistance to top-down instruction complicates standards adoption . Vallet similarly noted that the space industry has historically been 'very keen on proprietary solutions' and that adopting common standards will be 'a cultural challenge for space' . Both saw the standards landscape as evolving but requiring cultural change to be effective. Both Hunter and AlHassan emphasised the inherently cross-sectoral and multi-dimensional nature of space cybersecurity. Hunter stressed that effective national responses require collaboration not just within the space sector but also with the energy and telco sectors . AlHassan argued that space cuts across four of the five dimensions shaping cyberspace, encompassing geopolitics, economics, social issues, and technical matters , and that this breadth justifies GCF's investment in space cybersecurity. Both speakers framed space cybersecurity as a problem that cannot be solved within any single sector or discipline. Both Pace and Bueermann highlighted the gap between the age of existing governance frameworks and the current threat environment. Bueermann opened the session by noting that the frameworks governing space communications 'were written long before we had to contend with the cyber adversaries that we know and love today' . Pace similarly observed that international treaty law is 'pretty silent' on space cybersecurity and that the space community has historically operated by 'security through obscurity' . Both framed this governance gap as a central motivation for the work being discussed.
It was somewhat unexpected that both Pace - a self-described 'space guy' - and Hunter - a self-described 'cyber ops person' - converged on the view that the space community's cultural resistance is the primary obstacle to integration, rather than the cybersecurity community's lack of space knowledge. Pace explicitly stated that 'it's probably easier to teach space to a cyber person than it is to teach cyber to a space person' , and Hunter confirmed that the standard cybersecurity approach of black-boxing capabilities is 'not viable' for space assets, implying that cyber professionals must adapt to space constraints rather than the reverse . This consensus from representatives of both communities on the direction of cultural change was notable.
Across the panel, there was an unexpected degree of consensus that the most pressing barriers to space cybersecurity are cultural and organisational rather than purely technical. Pace highlighted the absence of clear accountability - noting the 'guilty look as people look at each other' when asked who the chief information security officer is - and the cultural resistance of space professionals to external mandates . Vallet identified the space industry's preference for proprietary solutions as a cultural barrier to standardisation . Hunter emphasised that poor hygiene in the user segment, driven by human fallibility, is the greatest practical vulnerability . Given that the session was framed around technical cybersecurity challenges, this convergence on cultural and organisational factors as the primary obstacles was unexpected.
It was somewhat unexpected that both Pace, drawing on his ITU spectrum negotiation experience, and AlHassan, representing a global cybersecurity forum headquartered in Riyadh, converged on the view that the interests of developing and space-dependent nations align naturally with those of space-capable nations. Pace recounted how developing countries supported space system interests in ITU negotiations because their infrastructure depended on GPS and satellite communications , and drew a parallel to cybersecurity . AlHassan similarly argued that a cyber incident in orbit is 'not a one-nation issue but an issue of many nations' and that supply chain implications affect the global economy . This shared optimism about the basis for international consensus, from both a Western academic and a Gulf-based multilateral organisation, was a notable point of convergence.
It was somewhat unexpected that both Pace - a policy academic - and Vallet - a senior official at ITU, an intergovernmental standards body - converged on the view that engineer-driven, bottom-up standards development is preferable to top-down regulatory mandates for the space cybersecurity domain. Pace argued that engineers need to feel 'empowered' and that they have 'choices to make,' and that some of the more promising standards show how to build a secure system 'almost component by component' in a way that avoids compliance being imposed by 'lawyers and other people that the engineers don't really respect' . Vallet, despite representing ITU, acknowledged that the space industry's cultural preference for proprietary solutions means that cultural change must precede standardisation . This shared scepticism about top-down mandates, from a policy academic and an intergovernmental official alike, was unexpected.
The panel demonstrated a high degree of consensus across all major discussion points. Speakers from diverse backgrounds - a space policy academic, a senior ITU official, a national cyber ambassador, and the CEO of a global cybersecurity forum - converged on the following core positions: (1) space cybersecurity is fundamentally distinct from terrestrial cybersecurity and requires adapted approaches ; (2) space must be recognised and governed as critical infrastructure ; (3) the primary barriers are cultural and organisational rather than purely technical ; (4) multi-stakeholder and cross-sectoral collaboration is essential ; (5) non-binding norms and soft law are more appropriate than new binding legal instruments at this stage ; and (6) resilience and recovery capacity are the appropriate measures of cybersecurity success . The joint research initiative between GCF, George Washington University, and ITU was consistently cited as a model for the kind of collaboration needed .
All three speakers agreed that space cybersecurity has unique characteristics, but they differed in how sharply they drew the distinction from terrestrial practice. Dr. Pace argued that terrestrial good practices are 'necessary but not sufficient' , emphasising physical inaccessibility, long cycle times, and specialised protocols as fundamental differentiators . Vallet was more emphatic, warning that the tendency to replicate terrestrial cybersecurity approaches 'too much' would be 'a mistake' , given the specificities of the space domain. Hunter, by contrast, characterised space cybersecurity as 'basics plus plus' , suggesting a stronger degree of continuity with standard cyber hygiene, with additional layers built on top . This reflects a genuine difference in how far the panellists believed the space domain requires genuinely novel approaches versus adapted versions of existing ones.
Terrestrial cybersecurity good practices are necessary but not sufficient for space, as satellites cannot be physically accessed for upgrades, have intermittent communications, and run on specialised protocols
Space cybersecurity has historically been unattractive to cybersecurity specialists due to satellite communications being a niche market, leading to over-reliance on replicating terrestrial approaches, which would be a mistake
Cybersecurity for space is essentially "basics plus plus" — standard cyber hygiene applied with additional layers specific to the space domain, including redundancy, clear incident response plans, and regular vulnerability assessments
Hunter explicitly recommended that negotiations should not aim to create new legal instruments but instead focus on shared expectations and non-binding norms, arguing these offer greater flexibility and inclusivity given the fast-moving nature of the domain . Dr. Pace acknowledged that international treaty law is 'pretty silent' on space cybersecurity , but rather than advocating for non-binding norms as a positive choice, he pointed to licensing, national regulation, and procurement as the practical levers available by default . He also noted the EU Space Act as an emerging regional regulatory effort, albeit a controversial one . Vallet, meanwhile, emphasised the need to build stronger and more iterative standards , and highlighted the cultural challenge of moving the space industry away from proprietary solutions towards common standards , implying a more structured standards-based approach. These positions reflect different views on whether the absence of binding instruments is a gap to be filled or a feature to be preserved.
Rather than creating new legal instruments, governments should focus on shared expectations and non-binding norms, which offer greater flexibility and inclusivity given the fast-moving nature of the domain
International treaty law is largely silent on space cybersecurity, leaving licensing, national regulation, and procurement as the primary levers for inducing better security behaviour
The space industry's historical preference for proprietary solutions represents a cultural challenge to adopting common cybersecurity standards, and the research and academic community can help drive that cultural change
Dr. Pace framed the cultural problem as a two-way chasm between the space and cyber communities, noting that space people resist being told what to do with their satellites while cyber people insist on practices without understanding space constraints . He also noted that many satellite operators still transmit in clear text, reflecting a culture of security through obscurity . Vallet, however, located the cultural challenge more specifically within the space industry's historical preference for proprietary solutions , and placed the responsibility for driving cultural change on the research and academic community . While both identified culture as a barrier, Pace saw it as a mutual misunderstanding between two communities, whereas Vallet characterised it primarily as a resistance within the space industry to adopting common standards.
There is a significant cultural chasm between the space and cyber communities, with space professionals resistant to external mandates and cyber professionals unfamiliar with space constraints
The space industry's historical preference for proprietary solutions represents a cultural challenge to adopting common cybersecurity standards, and the research and academic community can help drive that cultural change
Dr. Pace expressed scepticism about top-down compliance-driven approaches, noting that space engineers resist being told what to do by lawyers and policymakers , and argued that promising standards are those that show engineers how to build secure systems component by component, empowering them with choices . He recalled that early satellite cyber standards efforts failed partly because demand was not yet sufficient . Hunter, by contrast, highlighted Australia's formal designation of the space sector as critical national infrastructure , embedding legal obligations and protections - a clearly top-down regulatory approach. Vallet emphasised the role of research institutions in building a common framework and language , suggesting a more facilitative but still structured approach. These positions reflect a genuine tension between engineering autonomy and regulatory mandate as drivers of security improvement .
There is a significant cultural chasm between the space and cyber communities, with space professionals resistant to external mandates and cyber professionals unfamiliar with space constraints
Australia has designated the space sector as one of eleven critical national infrastructure sectors, embedding additional protections and obligations at the national level
Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions and building a common language and framework for policy conversations
Dr. Pace raised an unexpected and technically nuanced tension that was not addressed by any other panellist: the risk that implementing strong cryptographic systems on satellites could, in the event of radiation-induced memory corruption, render a satellite permanently inoperable since it cannot be physically accessed for recovery . He described this as a design challenge requiring careful balancing of cryptographic agility and storage resilience . This is unexpected because the general thrust of the panel was to advocate for stronger cryptography and security measures , yet Pace identified a scenario where stronger security could paradoxically increase operational risk. No other speaker engaged with this tension, leaving it as an unresolved and potentially significant disagreement between the imperative for strong cryptography and the operational realities of space systems.
Dr. Pace noted that early efforts to develop satellite cyber standards about ten years ago failed because there was not sufficient demand for them , but expressed cautious optimism that demand is now increasing as broader consensus grows . Vallet, however, characterised the space industry's preference for proprietary solutions as a persistent cultural challenge , implying that the resistance remains substantial and that academic and research communities need to actively drive cultural change . This is an unexpected disagreement because both speakers were broadly supportive of standards development, yet they implicitly differed on whether the industry is now ready to embrace common standards or whether significant cultural barriers remain. The practical implications for the pace and approach of standards development are significant.
Dr. Pace briefly referenced the AI discussions occurring elsewhere at the conference in the context of autonomous intrusion detection for satellites , arguing that satellites must be capable of detecting and responding to anomalous commands autonomously due to their physical inaccessibility and intermittent contact . This raised an implicit question about the governance and reliability of AI-driven autonomous responses in space systems - a topic with significant implications - but no other panellist engaged with it. The absence of any response or challenge to this point is unexpected given the broader WSIS context of AI governance discussions, and it represents a potential area of disagreement or at least unresolved tension between the imperative for autonomous response and concerns about the reliability and accountability of such systems.
The panel exhibited a high degree of surface-level consensus on the importance of space cybersecurity, the need for multi-stakeholder collaboration, and the recognition of space as critical infrastructure. However, substantive disagreements emerged around: (1) how distinct space cybersecurity truly is from terrestrial practice, with Hunter's 'basics plus plus' framing contrasting with Vallet's stronger warning against replication ; (2) governance approaches, with Hunter explicitly opposing new binding legal instruments while others implied a need for more structured frameworks; (3) the locus of cultural resistance and responsibility for change, with Pace identifying a two-way chasm and Vallet placing the burden on the space industry's proprietary culture ; and (4) the balance between top-down regulatory mandates and bottom-up engineering-led standards . Several technically significant tensions raised by Dr. Pace - particularly around cryptographic rigidity versus operational resilience and the readiness of industry to adopt common standards - were not engaged with by other panellists, leaving important questions unresolved.
All speakers agreed that space cybersecurity is a genuinely distinct and important challenge that cannot be addressed through simple replication of terrestrial approaches. Dr. Pace outlined the physical and technical reasons for this distinctiveness , Hunter confirmed that black-boxing capabilities as in terrestrial cybersecurity is not viable for space assets , Vallet warned against replicating terrestrial approaches too much , and AlHassan situated the challenge across geopolitical, economic, social, and technical dimensions . However, they differed on how distinct space cybersecurity truly is — Hunter's 'basics plus plus' framing implied more continuity with terrestrial practice than Vallet's stronger warning against replication .
Space systems have distinct attack surfaces across space, ground, and link segments that differ fundamentally from terrestrial systems - Space is physically inaccessible once launched, operates on long cycle times, and faces hostile radiation environments that complicate standard cybersecurity approaches Cybersecurity for space assets cannot simply black-box capabilities as it would in terrestrial contexts, because space assets are national security assets requiring a different marriage of expertise Space cybersecurity has historically been unattractive to cybersecurity specialists due to satellite communications being a niche market, leading to over-reliance on replicating terrestrial approaches, which would be a mistake Space cybersecurity cuts across geopolitical, economic, social, and technical dimensions, meaning a cyber incident in orbit is not a single-nation issue but a global one with wide supply chain implications
All speakers agreed that space should be recognised and treated as critical infrastructure, and that this recognition should be embedded in national and international governance frameworks. Bueermann noted that space-based technologies are 'rapidly demanding' the label of critical infrastructure , Dr. Pace recommended integrating space into national cyber strategies , Hunter highlighted Australia's formal designation of space as one of eleven critical national infrastructure sectors , and AlHassan emphasised the global supply chain and economic implications of space incidents . However, they differed on the mechanisms: Pace favoured procurement and licensing , Hunter favoured national designation and cross-sectoral collaboration , and AlHassan emphasised multi-stakeholder research and convening .
Space cybersecurity must be integrated into national cyber strategies rather than treated as a separate domain, and governments should use procurement and licensing as levers to drive security improvements Australia has designated the space sector as one of eleven critical national infrastructure sectors, embedding additional protections and obligations at the national level Space cybersecurity cuts across geopolitical, economic, social, and technical dimensions, meaning a cyber incident in orbit is not a single-nation issue but a global one with wide supply chain implications Space-based technologies are rapidly demanding recognition as critical digital infrastructure, alongside other sectors such as transportation, finance, and energy
All speakers agreed on the importance of multi-stakeholder collaboration and bridging communication gaps between communities. Dr. Pace described policymaking as a 'translation function' between technical, legal, and financial communities , Hunter called for plugging existing cybersecurity coordination mechanisms into the space community , Vallet emphasised the role of research institutions in building a common language and framework , and AlHassan presented the GCF-GWU-ITU partnership as a model for translating expert insights into action . However, they differed on which communities most needed bridging: Pace focused on space-cyber and technical-policy divides , Hunter on cyber-space and cross-sectoral divides , and Vallet on the research-policy interface .
Effective policymaking in this domain requires a translation function between technical engineering communities, legal communities, and financial communities, all of whom believe they share a common language but do not Existing cybersecurity coordination mechanisms such as computer emergency response teams, the International Watch and Warning Network, and ISACs need to be plugged into the broader space community Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions and building a common language and framework for policy conversations The partnership between GCF, George Washington University's Space Policy Institute, and ITU exemplifies the kind of multi-stakeholder collaboration needed to translate expert insights into actionable policy
Both Dr. Pace and Hunter agreed that the goal of space cybersecurity should be resilience and recovery rather than the prevention of all intrusions. Pace explicitly advocated for zero-trust architectures that assume penetration will occur, measuring success by the time taken to detect, resolve, and recover . Hunter similarly recommended redundancy, clear incident response plans, and business continuity plans as core elements of space cybersecurity . However, Pace framed this as a philosophical shift in how security is measured , while Hunter presented it as part of a practical checklist of 'basics plus plus' , suggesting a difference in how transformative they considered this reorientation to be.
The measure of resilience should be the time taken to detect, resolve, and recover from an attack rather than whether a penetration has occurred, reflecting a zero-trust architecture approach Cybersecurity for space is essentially "basics plus plus" — standard cyber hygiene applied with additional layers specific to the space domain, including redundancy, clear incident response plans, and regular vulnerability assessments
- Space systems present fundamentally distinct cybersecurity challenges compared to terrestrial systems, owing to physical inaccessibility once launched, long operational cycle times, intermittent communications, hostile radiation environments, and specialised protocols that prevent direct application of standard terrestrial cybersecurity approaches.
- Demonstrated cyber threats to space systems already exist across all four segments — space, ground, link, and user — ranging from subtle malicious code insertion to blunt jamming and RF interference, perpetrated by actors from hobbyists to sophisticated nation-states. Many satellite operators still transmit telemetry in clear text, representing a basic and easily exploitable vulnerability.
- The measure of good cybersecurity for space systems should be resilience — specifically the time taken to detect, resolve, and recover from an attack — rather than the prevention of all penetration, reflecting a zero-trust architecture philosophy adapted for the space domain.
- Foundational technical recommendations for space cybersecurity include strong cryptography on telemetry, tracking, and control; hardware-anchored secure boot processes; multi-factor authentication; network segmentation; autonomous intrusion detection; and clear assignment of responsibility for cybersecurity within organisations, including among smaller and entrepreneurial space startups.
- International treaty law is largely silent on space cybersecurity, leaving national licensing, regulation, and procurement as the primary levers for inducing better security behaviour. Rather than creating new legal instruments, governments should focus on shared expectations and non-binding norms, which offer greater flexibility given the fast-moving nature of the domain.
- There is a significant cultural chasm between the space and cyber communities that must be bridged. Space professionals are resistant to external mandates, whilst cyber professionals are often unfamiliar with space constraints. Effective policymaking requires a translation function between technical engineering, legal, and financial communities.
- Research institutions play a critical role in bringing conceptual clarity to space cybersecurity discussions, building a common language and framework for policy conversations, and encouraging cultural change within the space industry away from proprietary solutions and towards common cybersecurity standards.
- Space cybersecurity must be integrated into national cyber strategies rather than treated as a separate domain. Australia has designated the space sector as one of eleven critical national infrastructure sectors, providing a model for other nations.
- Existing cybersecurity coordination mechanisms — including computer emergency response teams, the International Watch and Warning Network, and Information Sharing and Analysis Centres (ISACs) — need to be actively connected to the broader space community to enable effective incident response and information sharing.
- De facto security standards for non-terrestrial networks are increasingly being driven by 3GPP, and developments at the World Radiocommunication Conference 2027 around direct-to-device discussions will significantly shape the security protocols implementable across converged satellite-mobile environments.
- There is a commonality of interest between space-capable nations and developing nations that depend on space systems, which can serve as a foundation for building international consensus on space cybersecurity, much as it did in earlier ITU spectrum negotiations.
- Cross-sectoral collaboration — bringing together the space, energy, and telecommunications sectors — is essential for effective national cybersecurity responses to space-related threats, and industry partnership is indispensable to any government-led effort.
“There's a giant cultural chasm between those communities. Space people don't want to be told what to do with their satellite, and cyber people are like, no, you can't do that.”
“The measure of goodness is not whether there is an infinite time between attacks, but rather what's the time it takes to resolve that attack. How resilient are you to detect, resolve, fix that attack and come back is a measure of resilience, not whether or not an attack or penetration has occurred.”
“Terrestrial good practices aren't really good enough when it comes to space. Because of physical inaccessibility, long cycle times when you launch something, that may be there for 10 years, 15 years. It's not something you can do a quick upgrade on your iPhone.”
“We need to build a common language to speak about these specificities and to make sure that we have a kind of common framework to address these discussions and especially the policy conversation.”
“Space is not the forgotten child when it comes to cybersecurity... under our 11 sectors of critical national infrastructure, we have designated the space sector and space capabilities. So that gives it additional protections and additional obligations from a national perspective.”
“A cyber incident that will take place in the orbit is not a one-nation issue. So it is an issue of many nations, and that's why it is a geopolitical issue, not a one-nation issue.”
“A lot of what policymaking is is a translation function. You're trying to explain things across a technical community to a legal community. You're trying to explain things across a technical community to a financial community. They all think they're speaking the same language, and they're not.”
“Cybersecurity will always black box the capability to ensure that it is confidential and protected. But particularly in space and to the point around it being a national security asset, that is not viable. So that's where the marriage needs to come together between cybersecurity experts and in particular space experts.”
What are the concrete examples of security and cybersecurity cooperation between satellite operators and mobile operators in the context of NTN (Non-Terrestrial Network) and mobile convergence?
As satellite and mobile operators increasingly converge, understanding existing cybersecurity cooperation frameworks is critical to identifying gaps and best practices. Dr. Pace acknowledged the question but could only partially address it within the time constraints, suggesting this warrants deeper investigation.
What recommended white papers or research projects exist on NTN and mobile convergence security?
Dr. Pace admitted he did not have a good reference to share, highlighting a gap in accessible, consolidated research on this topic. Identifying or producing such resources would be valuable for practitioners and policymakers working at the intersection of satellite and mobile security.
How should post-quantum cryptography migration be approached for space systems, particularly given the constraints of physical inaccessibility and long operational lifespans?
Dr. Pace raised post-quantum migration as a separate and complex discussion in its own right, noting that key distribution in space is far more challenging than on the ground. This remains an unresolved and urgent area as quantum computing advances threaten current cryptographic standards.
How can the balance between cryptographic rigidity (hardware-anchored secure boot) and the need for resilient recovery from radiation-induced memory corruption be achieved in spacecraft design?
Dr. Pace identified a fundamental design tension: strong cryptographic systems can render a satellite unrecoverable if memory is corrupted by radiation, yet weaker systems are more vulnerable to attack. Resolving this trade-off is essential for building genuinely resilient space systems.
How can autonomous intrusion detection systems for satellites be developed and standardised, given the intermittent communication windows and the need for satellites to self-assess their own state?
Dr. Pace highlighted that satellites cannot rely on ground-based monitoring during communication gaps and must be capable of self-diagnosis. This points to a significant research need in autonomous, AI-driven intrusion detection tailored to the space environment.
How can the cultural chasm between the space engineering community and the cybersecurity community be bridged effectively, particularly to encourage space operators to adopt cybersecurity best practices without imposing top-down compliance mandates?
Both Dr. Pace and Alexandre Vallet identified cultural resistance within the space industry as a major barrier to adopting cybersecurity standards. Understanding how to foster voluntary, engineer-led adoption of security practices is critical to improving the overall security posture of space systems.
How can national cyber strategies be better integrated with space cybersecurity considerations, and what governance models best support this integration across jurisdictions?
Dr. Pace recommended integrating space into national cyber strategies, and Jessica Hunter described Australia's approach of designating space as critical national infrastructure. Further research is needed on how different national governance models can be harmonised given the cross-border nature of space infrastructure.
What international legal or soft-law frameworks are needed to address cyber incidents affecting space systems, particularly to reduce the risk of misattribution, misunderstanding, and escalation between states?
Jessica Hunter highlighted the diplomatic risks of cyber incidents in space, including misinterpretation of whether an event was a cyber attack or a physical accident, as illustrated by the Viasat incident. Developing clearer international norms and attribution frameworks is essential to preventing unintended escalation.
How can existing cybersecurity coordination mechanisms (such as CERTs, ISACs, and the International Watch and Warning Network) be effectively connected to the broader space community to enable timely incident response?
Jessica Hunter noted that while many cybersecurity coordination networks already exist, the 'glue' connecting them to the space community is missing. Research into interoperability and integration between these communities would significantly improve collective incident response capabilities.
How can procurement and licensing mechanisms be more effectively used as levers to incentivise space operators, particularly new space startups, to adopt cybersecurity best practices?
Dr. Pace identified procurement and licensing as key policy tools but noted that smaller and entrepreneurial space organisations often lack even basic cybersecurity governance. Further research is needed on how regulatory and procurement frameworks can be designed to reach these actors without stifling innovation.
How can a common conceptual language and framework for space cybersecurity be developed to facilitate policy conversations across the space, cyber, legal, and financial communities?
Alexandre Vallet stressed the need for a common language to discuss space cybersecurity specificities, and Dr. Pace described policymaking as a 'translation function' across technical, legal, and financial communities. Developing shared terminology and frameworks is a foundational step for effective international coordination.
How can supply chain security for space systems be improved, including the development of software bills of materials and oversight of the limited global supply base for radiation-hardened components?
Dr. Pace highlighted the very small global supply base for radiation-hardened parts and the importance of supply chain transparency. Given the long operational lifespans of satellites and the risks of compromised components, this is a critical area requiring further research and standardisation.
What capacity-building programmes are needed to develop a workforce that is proficient in both space systems and cybersecurity, and how should educational curricula be structured to address this multidisciplinary challenge?
Dr. Pace noted that it may be easier to teach space concepts to cybersecurity professionals than vice versa, and emphasised the importance of workforce investment. Designing effective multidisciplinary education and training programmes is essential to closing the talent gap in this emerging field.
How should the security of direct-to-device LEO satellite systems be addressed within the evolving 3GPP non-terrestrial network standards, particularly as these systems integrate with existing proprietary satellite architectures and future delay-tolerant networking protocols?
Dr. Pace outlined the complex layering of legacy proprietary systems, emerging 3GPP NTN standards, and future delay-tolerant networking protocols, noting that de facto security standards are being driven by 3GPP. Understanding how security can be maintained across this heterogeneous environment is an urgent and underexplored research area.
What are the geopolitical implications of cyber incidents affecting multi-national satellite constellations, and how can international governance frameworks be designed to address incidents that span multiple sovereign jurisdictions?
AlHassan emphasised that a cyber incident in orbit is inherently a multi-nation issue due to the cross-border nature of satellite constellations. Research into appropriate international governance and response mechanisms for such incidents is essential given the growing geopolitical significance of space infrastructure.
How can the principle of 'security by design' be operationalised for satellite systems given that software embedded at launch may remain in operation for decades without the possibility of physical intervention?
AlHassan highlighted that satellites must be secure by design because their software may remain unchanged for decades in orbit. Further research is needed on design methodologies, testing frameworks, and standards that can ensure long-term security resilience from the point of manufacture and launch.
