WSIS Forum 2026
Rapport généré par l'IA

WSIS Action Line C5 Building confidence and security in the use of ICTs

7 intervenants
Résumé

Résumé

Cette discussion, animée par Gretchen Bueermann de la Division des technologies émergentes de l'UIT, a réuni des experts en politique spatiale, des diplomates spécialisés en cybersécurité et des organisations internationales afin d'examiner le défi croissant que représente la sécurisation des infrastructures spatiales face aux cybermenaces . La session s'est appuyée sur une initiative de recherche conjointe entre le Global Cybersecurity Forum (GCF), le Space Policy Institute de l'Université George Washington et l'UIT . Le Dr Scott Pace, qui dirige ces recherches, a expliqué pourquoi la cybersécurité spatiale pose des défis particuliers qui vont au-delà des pratiques terrestres habituelles . Parmi les facteurs clés figurent l'inaccessibilité physique des satellites une fois lancés, les fenêtres de communication intermittentes et l'environnement radiatif hostile susceptible d'endommager les systèmes de mémoire d'une manière difficile à distinguer des attaques malveillantes. . Il a souligné que de nombreux opérateurs de satellites transmettent encore des données en clair et ne disposent pas d'un responsable de la sécurité des systèmes d'information désigné, révélant ainsi des lacunes importantes en matière d'hygiène cybernétique de base . Le Dr Scott Pace a insisté sur le fait que la résilience, mesurée par la rapidité avec laquelle un système peut détecter une attaque et s'en remettre, constitue un objectif plus réaliste que la tentative de prévenir toutes les intrusions . Alexandre Vallet du Bureau des radiocommunications de l'UIT a souligné la nécessité d'un langage conceptuel commun et a mis en garde contre la simple transposition des cadres de cybersécurité terrestres au domaine spatial . L'Ambassadrice australienne pour les affaires cybernétiques, Jessica Hunter, a expliqué que l'Australie a officiellement désigné l'espace comme secteur d'infrastructure nationale critique, et a identifié les malentendus, l'escalade et la détection tardive comme des risques diplomatiques majeurs découlant des cyberincidents affectant les actifs spatiaux . Elle a plaidé pour la poursuite du développement de normes non contraignantes plutôt que de nouveaux instruments juridiques, et a souligné l'importance de connecter les réseaux de cybersécurité existants, comme les équipes d'intervention d'urgence informatique, avec la communauté spatiale . Abdurahman Alhassan du GCF a mis en évidence que la cybersécurité spatiale touche aux dimensions géopolitiques, économiques, sociales et techniques, ce qui en fait par nature une préoccupation multinationale . Le Dr Scott Pace a conclu en soulignant l'importance des intérêts communs entre les nations en développement dépendantes de l'espace et les puissances spatiales fournisseurs de services, et a appelé à une meilleure traduction entre les communautés techniques, juridiques et politiques comme étape fondamentale vers une coordination efficace . Dans l'ensemble, la discussion a convergé vers l'idée que la sécurisation des infrastructures spatiales nécessite une collaboration intersectorielle, un engagement culturellement adapté avec la communauté des ingénieurs, et l'intégration de l'espace dans les stratégies nationales et internationales de cybersécurité plus larges .

Points clés
  • Points clés

  • Objectif général

  • La discussion visait à examiner les défis en matière de cybersécurité auxquels font face les infrastructures spatiales, à explorer le fossé entre les communautés spatiale et cybersécuritaire, et à formuler des recommandations pratiques pour améliorer la cyber-résilience des systèmes spatiaux. Elle a réuni des experts issus de la recherche, des organismes de normalisation internationaux, de la diplomatie nationale et des forums mondiaux de cybersécurité afin de construire un cadre commun pour aborder ces enjeux.
  • --
  • Principaux points de discussion

  • La cybersécurité spatiale présente des défis techniques uniques qui diffèrent de la cybersécurité terrestre. Contrairement aux systèmes au sol, les satellites ne peuvent pas être physiquement accessibles une fois lancés, peuvent connaître de longues interruptions de communication et opèrent dans un environnement de rayonnement hostile susceptible de corrompre les systèmes de mémoire d'une manière qui imite des attaques malveillantes. Ces contraintes rendent les pratiques standard de cybersécurité terrestre nécessaires mais insuffisantes, exigeant des approches spécialisées telles que la détection autonome des intrusions, les processus de démarrage sécurisé ancrés dans le matériel et des architectures axées sur la résilience plutôt que purement préventives.
  • Il existe un fossé culturel et communicationnel significatif entre les communautés spatiale et cybersécuritaire qui doit être comblé. Le Dr Scott Pace a décrit un « gouffre culturel immense » entre les professionnels de l'espace, qui résistent aux instructions extérieures sur la gestion de leurs systèmes, et les professionnels de la cybersécurité, qui appliquent des protocoles stricts. Ce fossé s'étend aux décideurs politiques, aux juristes et aux ingénieurs, qui peuvent tous croire partager un langage commun alors que ce n'est pas le cas, faisant de la traduction entre communautés un défi central. Encourager le développement de normes ascendant, piloté par les ingénieurs, plutôt que des mandats de conformité descendants, a été identifiée comme une voie plus efficace. - Le cadre juridique et de gouvernance international pour la cybersécurité spatiale reste peu développé, avec des normes et des règles encore en cours d'élaboration. Le droit des traités est largement silencieux sur la cybersécurité spatiale, et bien que des instruments régionaux tels que l'EU Space Act soient en cours d'élaboration, il n'existe pas de norme internationale globale. Un éventail d'organismes de normalisation - de l'IEEE à l'ISO en passant par l'UIT - développent des cadres pertinents, mais ceux-ci impliquent différentes parties prenantes et ont des niveaux d'autorité différents. Les normes non contraignantes ont été recommandées comme approche pragmatique à court terme compte tenu de l'évolution rapide du domaine. - Les gouvernements doivent intégrer l'espace dans leurs stratégies nationales de cybersécurité et s'appuyer sur la coordination diplomatique pour gérer les risques transfrontaliers. La désignation par l'Australie de l'espace comme l'un de ses onze secteurs d'infrastructure nationale critique a été citée comme exemple concret de cette approche. Les risques diplomatiques, notamment la mauvaise attribution des incidents, l'escalade et la détection tardive, ont été soulignés comme des préoccupations sérieuses, notamment à la lumière d'incidents tels que l'attaque contre Viasat. Les mécanismes de coordination en matière de cybersécurité existants, tels que les CERT, les ISAC et le Réseau international de surveillance et d'alerte, doivent être plus efficacement connectés à la communauté spatiale. - La collaboration multipartite - réunissant institutions de recherche, gouvernements, industrie et organismes internationaux - est essentielle pour traduire les conclusions en actions. L'initiative de recherche conjointe entre le GCF, le Space Policy Institute de l'Université George Washington et l'UIT a été présentée comme un modèle pour ce type de collaboration. L'implication du GCF a été formulée autour de l'intersection de l'espace avec la géopolitique, l'économie, la connectivité sociale et la sécurité technique - des dimensions qui recoupent son mandat plus large. Le renforcement des capacités, le développement des compétences et l'engagement intersectoriel avec l'industrie ont tous été identifiés comme des facteurs habilitants essentiels.
  • --
  • Ton général

  • Le ton général de la discussion était constructif, collégial avec une pointe d'urgence. D'emblée, la modératrice et les panélistes ont cadré la conversation comme nécessaire, reconnaissant que la communauté internationale commence à peine à se saisir de ces enjeux. La présentation du Dr Scott Pace était empreinte d'une préoccupation mesurée, notant des menaces réelles et avérées tout en évitant l'alarmisme, et recourant occasionnellement à un humour pince-sans-rire pour illustrer ses propos : décrivant par exemple les satellites qui transmettent encore en clair comme « faisant pleuvoir des données ».
  • Au fil de la discussion, le ton est devenu plus collaboratif et orienté vers les solutions, les panélistes s'appuyant sur les contributions des uns et des autres plutôt que de débattre. Les remarques de Jessica Hunter ont introduit une urgence diplomatique légèrement plus marquée, notamment autour des risques d'escalade et de la nécessité de normes internationales plus claires. Les remarques de clôture du Dr Scott Pace et du représentant de l'UIT étaient empreintes d'optimisme, soulignant les intérêts communs et la valeur des partenariats noués. Tout au long de la discussion, le ton est resté mesuré et guidé par l'expertise, sans moments significatifs de tension ou de désaccord.
Intervenants
DS
Dr. Scott Pace
164 wpm · 19 min
AV
Alexandre Vallet
135 wpm · 3 min
JH
Jessica Hunter
175 wpm · 6 min
AA
Abdurahman AlHassan
99 wpm · 7 min
S
Speaker
155 wpm · 1 min
A
Audience
135 wpm · 29 s
GB
Gretchen Bueermann
149 wpm · 10 min

Résumé élargi : Sécuriser les infrastructures spatiales - Cybersécurité, résilience et coordination internationale

#

Aperçu et contexte de la session

Cette session, tenue le cinquième jour du Forum du SMSI et modérée par Gretchen Bueermann de la Division des technologies émergentes de l'UIT, a été convoquée dans le cadre de la Ligne d'action C5 du SMSI, qui porte sur le renforcement de la confiance et de la sécurité dans l'utilisation des TIC . Gretchen Bueermann a ouvert la session en observant que les infrastructures spatiales sous-tendent bien plus d'aspects de la vie quotidienne que la plupart des gens ne le réalisent, et pourtant, les cadres régissant les communications spatiales ont été rédigés bien avant que la communauté internationale n'ait à faire face aux cyberadversaires auxquels elle est confrontée aujourd'hui . Elle a présenté la session comme une démarche opportune de la communauté internationale pour coordonner et communiquer sur ce que signifie être cyber-résilient et cybersécurisé dans le contexte des technologies spatiales .

La discussion s'est appuyée sur une initiative de recherche conjointe entre le Global Cybersecurity Forum (GCF), l'Institut de politique spatiale de l'Université George Washington et l'UIT, qui examine les principales cybermenaces pesant sur les systèmes spatiaux et les mesures susceptibles d'améliorer leur résilience et leur sécurité . Le panel a réuni le Dr Scott Pace, Directeur de l'Institut de politique spatiale et Professeur de pratique des affaires internationales à l'École Elliott des affaires internationales de l'Université George Washington, qui dirige la recherche ; Alexandre Vallet, Chef du Département des services spatiaux au Bureau des radiocommunications de l'UIT ; Jessica Hunter, Ambassadrice australienne pour les affaires cybernétiques et les technologies critiques ; et Abdurahman Alhassan, PDG du Global Cybersecurity Forum .

---

#

Les défis uniques de la cybersécurité des systèmes spatiaux et les menaces avérées

Le Dr Scott Pace a ouvert la discussion de fond en exposant pourquoi la cybersécurité spatiale présente des défis distincts de ceux de la cybersécurité terrestre classique - et non pleinement couverts par celle-ci . Il a identifié trois contraintes physiques fondamentales qui distinguent les systèmes spatiaux. Premièrement, les satellites ne peuvent pas être physiquement accessibles une fois lancés, ce qui rend impossible le remplacement de matériel ou toute intervention manuelle . Deuxièmement, les systèmes spatiaux ne sont pas en communication continue, et il peut exister de longues interruptions entre les fenêtres de contact, contrairement aux systèmes terrestres ou basés sur Internet . Troisièmement, l'environnement spatial est lui-même hostile : les effets des rayonnements peuvent corrompre les systèmes de mémoire d'une manière difficile à distinguer d'une interférence malveillante délibérée . Ces contraintes signifient que les bonnes pratiques terrestres sont, selon les termes du Dr Scott Pace, « nécessaires mais insuffisantes » pour le domaine spatial .

Le Dr Scott Pace a également noté que les systèmes spatiaux fonctionnent sur de longs cycles - un satellite lancé aujourd'hui peut rester en service pendant dix à quinze ans - ce qui rend totalement impraticables les mises à jour logicielles rapides du type de celles possibles sur les appareils grand public . Ils reposent sur des protocoles très spécialisés, une base d'approvisionnement mondiale restreinte pour les composants durcis aux rayonnements, et font face à de sévères contraintes de taille, de poids et de puissance . Pris ensemble, ces facteurs créent un ensemble de surfaces d'attaque - couvrant le segment spatial, le segment sol et le segment liaison - qui sont à la fois complexes et difficiles à défendre par des moyens conventionnels .

Le Dr Scott Pace a été clair sur le fait que les cybermenaces pesant sur les systèmes spatiaux ne sont pas hypothétiques . Il a décrit un éventail de menaces avérées allant de l'insertion subtile de code malveillant au brouillage grossier et aux interférences de radiofréquences du type observé dans les systèmes GPS et au-dessus des zones de conflit . Les acteurs à l'origine de ces menaces vont des amateurs cherchant à causer des perturbations aux acteurs étatiques les plus sophistiqués . Malgré cela, le Dr Scott Pace a observé que beaucoup d'acteurs de la communauté spatiale fonctionnent encore selon le principe de la « sécurité par l'obscurité », supposant que leurs systèmes sont trop spécialisés ou méconnus pour attirer l'attention, une posture qu'il a qualifiée d'intenable .

L'une des vulnérabilités les plus frappantes que le Dr Scott Pace a soulignées est la prévalence de systèmes satellitaires qui transmettent encore des données de télémétrie, de poursuite et de contrôle en clair, décrivant la situation comme une « pluie de données » que n'importe qui pourrait collecter . Il a également noté que dans de nombreuses organisations, en particulier les jeunes entreprises du New Space, il n'existe pas de responsable désigné de la sécurité des systèmes d'information, la responsabilité de la cybersécurité étant floue ou non attribuée . Jessica Hunter a ajouté une analyse des vulnérabilités par segment : le segment sol est très interconnecté et présente la plus grande exposition aux surfaces d'attaque ; le segment utilisateur est le plus vulnérable en raison de la faillibilité humaine et d'une hygiène insuffisante ; et les liaisons de communication sont particulièrement susceptibles d'être interceptées et perturbées . Elle a également noté que le segment spatial lui-même, bien qu'il nécessite des activités plus sophistiquées pour être perturbé d'un point de vue cybernétique, n'est pas immunisé .

Alexandre Vallet du Bureau des radiocommunications de l'UIT a renforcé le point sur la spécificité de la cybersécurité spatiale, avertissant qu'il existe une tendance à « trop » reproduire les approches de cybersécurité terrestre dans le domaine spatial, et que ce serait « une erreur » . Il a noté que les communications par satellite étaient historiquement un marché de niche, ce qui a rendu la cybersécurité spatiale peu attrayante pour les spécialistes de la cybersécurité et a contribué au déficit actuel . Jessica Hunter, abordant la question sous l'angle de la diplomatie nationale en matière de cybersécurité, a qualifié la cybersécurité spatiale de « bases plus plus » - une hygiène cybernétique standard appliquée comme fondation, avec des couches supplémentaires spécifiques au domaine spatial construites par-dessus . Si les trois intervenants s'accordaient à dire que la cybersécurité spatiale constituait un domaine à part, leurs opinions divergeaient quant à la netteté de la frontière à établir : l'avertissement d'Alexandre Vallet contre la réplication était le plus catégorique, tandis que le cadrage de Jessica Hunter impliquait un degré plus fort de continuité avec la pratique terrestre.

---

#

Recommandations techniques et le paradigme de la résilience

Le Dr Scott Pace a présenté un ensemble de recommandations techniques fondamentales tirées du rapport de recherche conjoint. Celles-ci comprennent une cryptographie robuste sur les systèmes de télémétrie, de poursuite et de contrôle ; des processus de démarrage sécurisé ancrés dans le matériel ; l'authentification multifacteur ; et la segmentation du réseau pour prévenir les mouvements latéraux entre les systèmes . Il a également souligné l'importance des systèmes autonomes de détection des intrusions, arguant que, les satellites ne pouvant pas compter sur une surveillance continue depuis le sol, ils doivent être capables d'auto-évaluation - détecter les commandes anormales et prendre les mesures appropriées sans intervention externe . Il a établi un parallèle avec les discussions plus larges sur l'IA se déroulant lors de la conférence concernant la capacité à détecter puis à répondre aux menaces .

Une contribution conceptuelle centrale de la présentation du Dr Scott Pace a été son recadrage de ce qui constitue une bonne cybersécurité pour les systèmes spatiaux. Plutôt que de mesurer le succès par la prévention de toutes les intrusions - une norme impossible à atteindre - il a soutenu que la mesure appropriée est la résilience : plus précisément, le temps nécessaire pour détecter, résoudre et se remettre d'une attaque . Cela reflète une philosophie d'architecture à confiance zéro, qui suppose que la pénétration se produira et conçoit les systèmes en conséquence . Les recommandations de Jessica Hunter en matière de redondance, de plans clairs de réponse aux incidents et de planification de la continuité des activités aux niveaux national et organisationnel étaient cohérentes avec cette approche centrée sur la résilience .

Le Dr Scott Pace a également soulevé une tension techniquement nuancée qui n'a pas été abordée par les autres panélistes : le risque que la mise en œuvre de systèmes cryptographiques robustes - en particulier le démarrage sécurisé ancré dans le matériel - puisse rendre un satellite définitivement inopérant si une corruption de mémoire induite par les rayonnements se produit, puisque le satellite ne peut pas être physiquement accessible pour une récupération . Il a décrit cela comme un défi de conception nécessitant un équilibre minutieux entre l'agilité cryptographique et la résilience du stockage . Il a également noté que la migration vers la cryptographie post-quantique et la distribution de clés dans l'espace présentent des défis uniques et non encore résolus, observant que la distribution de clés au sol est déjà difficile et que l'environnement spatial la rend considérablement plus complexe .

Le Dr Scott Pace a également observé que la triade CID - confidentialité, intégrité et disponibilité - est pondérée différemment selon les communautés : les communautés de sécurité privilégient la confidentialité, les utilisateurs scientifiques privilégient l'intégrité, et les opérateurs commerciaux privilégient la disponibilité, ce qui signifie que tous les standards ne seront pas également valorisés par toutes les parties prenantes . Cette observation transversale souligne pourquoi l'élaboration de normes de cybersécurité spatiale universellement acceptées reste si difficile.

---

#

Le fossé culturel entre les communautés spatiale et cybernétique

L'un des thèmes les plus récurrents tout au long du panel a été le fossé culturel entre la communauté des ingénieurs spatiaux et la communauté de la cybersécurité. Le Dr Scott Pace l'a décrit comme « un fossé culturel gigantesque », notant que les professionnels du spatial résistent à ce qu'on leur dise quoi faire avec leurs satellites, tandis que les professionnels de la cybersécurité insistent sur des pratiques que les opérateurs spatiaux trouvent contraignantes . Il a reconnu sa propre identité de « spécialiste du spatial » naviguant dans ce fossé, et a suggéré qu'il est probablement plus facile d'enseigner les concepts spatiaux à un professionnel de la cybersécurité que d'enseigner la cybersécurité à un professionnel du spatial .

Alexandre Vallet a situé le défi culturel plus précisément dans la préférence historique de l'industrie spatiale pour les solutions propriétaires, arguant que l'adoption de normes communes de cybersécurité sera « un défi culturel pour le spatial » . Il a identifié les communautés de recherche et académiques comme ayant un rôle clé à jouer dans la conduite de ce changement culturel . Jessica Hunter a confirmé l'incompatibilité du côté de la cybersécurité, notant que l'instinct standard en cybersécurité consistant à « mettre en boîte noire » les capacités pour des raisons de confidentialité n'est « pas viable » pour les actifs spatiaux, en particulier ceux ayant des implications pour la sécurité nationale, et que c'est précisément là que les deux communautés doivent se rejoindre .

Le Dr Scott Pace a soutenu que la voie la plus prometteuse n'est pas celle des mandats de conformité descendants - auxquels les ingénieurs spatiaux résistent - mais plutôt le développement de normes ascendant, piloté par les ingénieurs, qui habilite les communautés techniques à déterminer les méthodes de mise en œuvre dans le cadre d'objectifs de performance définis par les politiques . Il a rappelé que les premières tentatives de développement de normes de cybersécurité satellitaire il y a une dizaine d'années ont en partie échoué parce que la demande était insuffisante , mais a exprimé un optimisme prudent quant au fait que la demande augmente désormais à mesure que le consensus s'élargit . Alexandre Vallet a également reconnu que le changement culturel doit précéder une standardisation efficace - un point de convergence notable entre un universitaire spécialisé en politique et un fonctionnaire intergouvernemental .

---

#

Le paysage juridique et de gouvernance

Le Dr Scott Pace a fourni une évaluation franche du cadre juridique et de gouvernance international pour la cybersécurité spatiale : au niveau international, le droit des traités est « assez silencieux » . Si des instruments régionaux tels que la loi spatiale de l'UE sont en cours d'élaboration, ceux-ci restent controversés, notamment parmi les entreprises américaines qui s'interrogent sur les normes qui s'appliqueront . Les licences et réglementations nationales, ainsi que les exigences en matière de marchés publics, sont les principaux leviers dont disposent actuellement les gouvernements pour inciter les opérateurs de satellites à adopter de meilleures pratiques de sécurité .

Un spectre d'organismes de normalisation élabore des cadres pertinents, allant du très technique IEEE - où les ingénieurs travaillent largement sans avocats ni politiciens - à l'Organisation internationale de normalisation, qui intègre les contributions et priorités nationales, en passant par l'UIT, qui dispose d'une structure de vote formelle et d'un éventail plus large de parties prenantes . Ces organismes produisent des résultats allant des normes non contraignantes aux standards techniques détaillés, et impliquent différents groupes d'intérêt aux priorités diverses .

Jessica Hunter a explicitement recommandé que les négociations internationales ne créent pas de nouveaux instruments juridiques, mais se concentrent plutôt sur le développement d'attentes partagées et de normes non contraignantes, qui offrent une plus grande flexibilité et inclusivité compte tenu de la nature en rapide évolution du domaine . Elle a noté que le droit international s'applique déjà tant dans l'espace numérique que hors ligne, et que le défi consiste moins à créer de nouvelles lois qu'à connecter les mécanismes de coordination existants à la communauté spatiale . Cette position était globalement cohérente avec la reconnaissance pragmatique par le Dr Scott Pace des limites de la gouvernance internationale actuelle.

---

#

Gouvernance nationale : l'approche australienne et les risques diplomatiques

Jessica Hunter a fourni l'exemple national le plus concret de la session, révélant que l'Australie a formellement désigné le secteur spatial comme l'un des onze secteurs d'infrastructure nationale critique, lui accordant des protections et des obligations supplémentaires en vertu du droit national . Elle a noté avec satisfaction que plusieurs des recommandations du Dr Scott Pace étaient déjà intégrées dans les systèmes australiens d'importance nationale .

Jessica Hunter a identifié trois principaux risques diplomatiques découlant des cyberincidents affectant les actifs spatiaux. Le premier est le risque de malentendu - plus précisément, la question de savoir si un incident est une cyberattaque ou un accident physique - ce qui peut conduire à des interprétations différentes entre gouvernements . Elle a cité l'incident Viasat comme exemple concret de la façon dont différentes interprétations des normes, des règles et du droit peuvent se manifester en pratique . Le deuxième risque est l'escalade, découlant de ces interprétations divergentes . Le troisième est le risque de détection, de résolution et de rétablissement tardifs, qui aggrave les deux premiers . Selon elle, ces risques diplomatiques influencent directement les solutions que les gouvernements devraient mettre en œuvre.

Au niveau mondial, Jessica Hunter a plaidé pour la poursuite du développement de normes non contraignantes et pour la connexion des mécanismes de coordination en matière de cybersécurité existants - notamment les équipes d'intervention en cas d'urgence informatique (CERT), le Réseau international de surveillance et d'alerte, et les Centres de partage et d'analyse de l'information (ISAC) - à la communauté spatiale au sens large . Elle a décrit le défi comme celui de trouver « le ciment » pour faire fonctionner ces connexions . Le Dr Scott Pace a également spécifiquement mis en avant le SpaceISAC - le Centre spatial de partage et d'analyse de l'information - comme mécanisme de coordination dédié à la communauté spatiale, distinct des ISAC cybernétiques au service des secteurs terrestres tels que les réseaux financiers, le pétrole et le gaz, et les transports. Au niveau régional, Jessica Hunter a souligné le rôle de l'AP CERT dans la région Asie-Pacifique et la coprésidence australienne de PAXON, une communauté axée sur les initiatives CERT et les capacités de réponse en matière de cybersécurité . Au niveau national et organisationnel, elle a recommandé la redondance, des accords clairs avec les fournisseurs, des plans définis de réponse aux incidents et de continuité des activités, une définition claire des rôles, et des évaluations régulières des risques et des vulnérabilités . Elle a également souligné que des réponses efficaces nécessitent une collaboration intersectorielle, réunissant non seulement le secteur spatial mais aussi les secteurs de l'énergie et des télécommunications .

---

#

La perspective du GCF : l'espace comme défi mondial multidimensionnel

Abdurahman Alhassan a situé l'implication du GCF dans la cybersécurité spatiale dans le cadre du mandat plus large de l'organisation visant à renforcer la cybersécurité à l'échelle mondiale selon cinq dimensions façonnant le cyberespace - la géopolitique, l'économie, les facteurs sociaux et comportementaux, et les questions techniques - notant qu'Abdurahman Alhassan a nommé explicitement quatre de ces cinq dimensions et observé que l'espace en traverse quatre . D'un point de vue géopolitique, les constellations de satellites franchissent les frontières, ce qui signifie qu'un cyberincident en orbite est par nature une question multinationale plutôt que bilatérale . D'un point de vue économique, l'économie spatiale se dirige vers des milliers de milliards de dollars de valeur, et un incident satellitaire comporte de larges implications pour la chaîne d'approvisionnement de l'économie mondiale . D'un point de vue social, l'espace sous-tend la connectivité, la navigation, la réponse aux catastrophes et la sécurité alimentaire . D'un point de vue technique, les satellites doivent être sécurisés dès la conception, car les logiciels intégrés au lancement peuvent rester en exploitation pendant des décennies sans possibilité d'intervention physique .

Abdurahman Alhassan a décrit les travaux du GCF, qui couvrent des initiatives stratégiques, la recherche et la publication, et la réunion de dirigeants mondiaux de la cybersécurité - notamment un rassemblement annuel à Duwad de plus de 10 000 participants en provenance de plus de 100 pays . Il a mis en avant deux centres récemment lancés : l'un sur la cyber-économie, développé en partenariat avec le Forum économique mondial, et l'autre sur les technologies opérationnelles, développé avec Aramco . Le partenariat avec l'Institut de politique spatiale de l'Université George Washington a été présenté comme une extension naturelle de ce travail, compte tenu de la convergence entre la dépendance croissante aux services spatiaux et un paysage de cybermenaces en expansion .

---

#

Le rôle des institutions de recherche et de la collaboration multipartite

Alexandre Vallet a identifié deux rôles principaux pour les institutions de recherche dans la structuration du débat politique sur la cybersécurité spatiale. Le premier est d'apporter une clarté conceptuelle - construire un langage et un cadre communs permettant à différentes communautés de discuter des spécificités de la cybersécurité spatiale de manière cohérente . Il a soutenu que c'est la contribution la plus importante et la plus urgente que les institutions de recherche peuvent apporter, et a cité l'initiative conjointe GCF-GWU-UIT comme un pas positif dans cette direction . Le second rôle est de construire des normes plus solides et plus itératives pour la cybersécurité spatiale, et d'aider à conduire le changement culturel nécessaire au sein de l'industrie spatiale pour s'éloigner des solutions propriétaires vers des protocoles communs .

Le Dr Scott Pace a conclu le panel en réfléchissant aux conditions générales du progrès. S'appuyant sur son expérience dans les négociations sur le spectre à l'UIT, il a observé que les pays en développement et les nations dotées de capacités spatiales partagent un intérêt commun dans le bon fonctionnement des systèmes spatiaux, puisque les infrastructures des nations en développement dépendent du GPS et des communications par satellite . Il a soutenu que cette communauté d'intérêts constitue une base naturelle pour construire un consensus international sur la cybersécurité spatiale . Il est également revenu sur le thème de la traduction, décrivant l'élaboration des politiques comme une fonction consistant à expliquer les choses entre des communautés techniques, juridiques et financières qui croient toutes partager un langage commun mais ne le font pas . Cette observation a servi de conclusion intellectuelle appropriée à la session, reliant les thèmes du rapprochement culturel, du langage commun et de la collaboration multipartite qui avaient traversé l'ensemble de la discussion.

---

#

Réseaux non terrestres et convergence satellite-mobile

Une question du public sur la convergence des opérateurs satellitaires et mobiles a conduit le Dr Scott Pace à aborder le paysage émergent des normes de réseaux non terrestres (NTN). Il a noté que les normes de sécurité pour les NTN sont de plus en plus pilotées par le 3GPP, qui régit des milliards d'appareils, et que ces normes sont étendues pour intégrer les systèmes directs vers l'appareil et les systèmes LEO . Le défi réside dans le comblement du fossé entre l'environnement réseau non fiable du 3GPP, les systèmes satellitaires propriétaires installés existants, et les futures architectures de réseau tolérant les délais - y compris les protocoles de faisceau conçus pour l'Internet du système solaire - qui fonctionnent comme des réseaux superposés . Le Dr Scott Pace a invité les participants à suivre les développements à la Conférence mondiale des radiocommunications 2027, notamment autour des discussions sur le direct vers l'appareil, car ceux-ci façonneront de manière significative les protocoles de sécurité pouvant être mis en œuvre dans des environnements satellite-mobile convergés . Il a toutefois reconnu qu'il ne pouvait pas indiquer de livre blanc ou de projet de recherche spécifique sur la coopération concrète en matière de cybersécurité entre opérateurs satellitaires et mobiles, laissant cela comme un domaine ouvert à des investigations ultérieures .

---

#

Remarques de clôture et remerciements institutionnels

La session s'est conclue par les remarques de Brita Malura du bureau du Secrétaire général de l'UIT, qui a exprimé la gratitude de l'UIT à l'Université George Washington et au Dr Scott Pace pour leur leadership, ainsi qu'au GCF et à Abdurahman Alhassan personnellement pour avoir mis à disposition le GCF comme plateforme et pour le soutien généreux ayant permis la réalisation de ces travaux . Elle a noté que la contribution de l'UIT à l'initiative s'étend au Bureau des radiocommunications, au Bureau du développement, au Bureau de la normalisation et au bureau du Secrétaire général, en faisant un effort de collaboration à l'échelle de l'organisation . L'UIT a exprimé son attente de la prochaine itération du manuel et son engagement à poursuivre la collaboration .

Dans l'ensemble, la session a convergé vers un ensemble clair de conclusions : la cybersécurité spatiale est un défi distinct et urgent qui ne peut être relevé en reproduisant les approches terrestres ; la résilience et la capacité de rétablissement sont les mesures appropriées du succès ; les principaux obstacles sont autant culturels et organisationnels que techniques ; la collaboration multipartite et intersectorielle est indispensable ; et les normes non contraignantes, combinées aux leviers réglementaires nationaux tels que les licences et les marchés publics, représentent la voie de gouvernance la plus pragmatique à court terme . L'initiative de recherche conjointe entre le GCF, l'Université George Washington et l'UIT a été constamment citée comme un modèle du type de collaboration nécessaire pour traduire ces enseignements en actions .

Gretchen Bueermann
Thank you. All righty. Good morning, everyone, and thank you for being with us today, for those of you here in the room and those of you joining us online. My name is Gretchen Bierman. I'm from the Emerging Technologies Division here at ITU. And I'll be moderating this session, which sits under the WSIS Action Line C5, Building Confidence and Security and the Use of ICTs. Space -based infrastructure underpins far more of daily life than people realize, although I imagine if you have managed to make it here on a Friday on day five of this conference, that's probably something that you already understand. But with the frameworks governing the infrastructure that underpins space communications and space technology, we're written long before we had to contend with the cyber adversaries that we know and love today. And I think that the international community is starting to think about how we need to coordinate and communicate about what it means to be cyber resilient and cyber secure when it comes to space technology. So I'm quite pleased. I'm very pleased that this group has gathered here today to try to tackle some of these issues. all in the next 45 minutes. But we really have a lovely diversity of views here today, and so I'm really happy that we have those that are approaching it from the space perspective. We have online my colleague Alexandra Vallée, Chief of the Space Services Department in ITU's Radio Communications Bureau, joining us, and Dr. Scott Pace, and I'll check my notes for this one because it's a mouthful, Director of the Space Policy Institute and a Professor of the Practice of the International Affairs at George Washington University's Elliott School of International Affairs. Success? And we also have those working to bring cyber resilience to all critical infrastructure. I think that's a label that space -based technologies are rapidly demanding. So let me introduce Jessica Hunter, Australia's Ambassador for Cyber Affairs and Critical Technology. and Abdul Rahman Al -Hassan, CEO of the Global Cybersecurity Forum. So the foundational questions for this session actually came from a joint research initiative between the GCF, the George Washington University Space Policy Institute, and the ITU. And they're working to examine the main cyber threats to space systems and the measures that improve their resilience and safety. And we're quite thankful to our partners at GCF for supporting this initiative. And we're very thankful to Dr. Scott Pace for leading this work. And so I think alongside some perspectives from ITU and from national cybersecurity diplomacy, maybe we'll start by just asking Dr. Scott Pace, who's leading this research, to set the scene and take us through the architecture and the sort of state of affairs and cybersecurity and space. Thank you, Dr. Pace. And then I'll ask Mr. Al -Shan to say a few words about the GCF and the coordination mechanisms behind this. And then we'll have a short panel discussion. And if time permits, we'll take some questions from the audience. So with that, Dr. Pace, perhaps you can just introduce us a little bit to the work that you have been doing.
Dr. Scott Pace
OK, sure. And let's see. Can I advance a slide?All right. So thank you. Great. Thank you very much. So the focus of our current work is on securing the space layer, meaning satellite systems and their ground segments and the links and so forth between them. We talk about threats. We talk about countermeasures that you can take for those threats. And what the emerging landscape for space cybersecurity looks like, not just from a technical angle, but also from a legal and soft law and standards angle. The reason that some of this is important is because while cybersecurity itself is recognized as a global issue, in fact, Global Cybersecurity Forum, of course, publishes a well -regarded report on cybersecurity factors for countries, their readiness, and so forth, I think more and more countries are realizing that critical infrastructure, transportation, financial, oil and gas, and all that relies on the space segment as well. And so space cybersecurity is a little different than ground cybersecurity, a lot of same lessons, but there are aspects of which are a little different that you have to think about. And I'm a space guy, not a cyber guy, and so what I've learned is there's a giant cultural chasm between those communities. Space people don't want to be told, what to do with their satellite, and cyber people are like, no, you can't do that. and so there are a lot of lessons from cybersecurity that can be translated into space, but some of which have to be modified. One of the reasons why space is different is that the satellites, once you launch them, you can't go touch them, and so grabbing them and pulling out a board and making a replacement is hard to do. The second is they're not in continuous communication all the time, the way you might be, say, with a terrestrial communication system or the Internet. There may be long gaps between the time when you talk to the satellite. And then the space environment itself is rather hostile, and you can have things happen. There can be radiation effects and upsets to your memory systems that are perfectly natural, but you're trying to figure out did somebody do that maliciously or not. So the thing that we talk about is that very simply the segments that we focus on, the space, the ground. The link segments, all of them have, as cyber people would say, different attack surfaces. They're very complex devices, but as more complex you get, the more routes there are in to go and attack them. And I won't bore you with all the details, but the fact is that we have a variety of diverse and demonstrated cyber threats that have occurred. Again, a lot of space people, I think, still operate by security, by obscurity. Gee, no one knows we're here, no one will pay attention to us. And, of course, that really sort of isn't the case. Some things are very subtle, you know, like inserting malicious code. Other things are pretty blunt, like jamming and RF interference that we've certainly seen, say, in the GPS world or certainly seen over various conflict zones. And there's all kinds of people who do this. Some of them are just people having fun, you know, just hobbyists looking out to make trouble. And some are very, very sophisticated nation -state actors. In terms of... These threats are not hypothetical. Again, we go through each of the cases, but let me not bore you with that. But one of the first messages is that terrestrial good practices aren't really good enough when it comes to space. As I said, because of physical inaccessibility, long cycle times when you launch something, that may be there for 10 years, 15 years. It's not something you can do a quick upgrade on your iPhone. They have various types of supply chains, very, very small global fire base for radiation -hardened parts. There are severe size, weight, and power limitations, and somewhat very specialized protocols. So things to think about. There are recommendations, and this is where our report goes into more details. You don't have to read all this now. But there are certainly some very basic rules we like to suggest. Strong cryptography on your telemetry tracking and control. We amaze a number of people. of satellite systems that still transmit clear text all the time. You know, just go out. It's raining data. Go out and get a bowl, and here it is. So, first of all, really simple things like that. Other things more sophisticated, like having a hardware -anchored secure boot process. Okay, that's still emerging. It's very somewhat specialized. Again, people are uncomfortable with it sometimes because when you have a hardware -type secure boot for your system, that means you're tied to that system. It can be pretty rigid. You can't go and rewire it on the fly. Multi -factor authentication, I'm sure all of you have suffered through. Segmenting your networks such that not everything is connected to everything, but that there are passageways you have to come across before you can go from one area to another. Because you're far away from Earth and you're intermittent contact, an autonomous intrusion detection system starts becoming important. You can't depend on somebody else. The satellite itself. Has to know, gee, am I okay or maybe I'm not. You can't depend on somebody else. And that in turn requires the satellite to know something about itself. If it get a command to do a reentry burn when you're supposed to be cruising on your way to Mars, maybe something's wrong. And so knowing the state of your system, physical system, and what should be expected or not expected is part of that kind of monitoring system. And being able to take action. So some of the artificial intelligence discussions that we've been having this week about being able to detect and then respond. And then finally, you know, is there actually somebody in charge? Some amazing number of places where if you ask, who's the chief information security officer? This is sort of guilty look as people look at each other. I thought that was Bob's job. Bob's on leave next week. Well, so the issue, and so some large organizations were able to handle this. Smaller and entrepreneurial organizations, particularly a lot of the new space startups, not so much. So the point is not, as is happening in a lot of cybersecurity, is not to put up some sort of firewall which is impervious to attack and nothing ever gets in. A lot of systems today, some of you might be familiar with zero trust architectures, we assume there's going to be penetration. We assume somebody's going to break through. So the measure of goodness is not is there an infinite time between attacks, but rather what's the time it takes to resolve that attack? How resilient are you to detect, resolve, fix that attack and come back is a measure of resilience, not whether or not an attack or penetration has occurred. And there's different aspects of designing for resilience, agility in your cryptographic systems. There's a whole separate discussion about post -quantum migration, which, again, we can go for days, and also with key distribution in space. You think key distribution on the ground is tough. Imagine what it's like in space. You can't just go in and say, hey, this is the best way to do it. You can't just go in and say, hey, this is the best way to do it. This leads back to how spacecraft people, though, get concerned, because they know that their memory systems sometimes can be corrupted and have to be fixed. If you have a strong cryptographic system and, say, you have a radiation effect and your memory or storage goes bad, your satellite can turn into a brick and your ability to then recover from that because you can't touch it. So how do you balance off that kind of agility that you want with the resiliency in your storage systems These are things that design people are going to get into. In terms of the laws, well, it's pretty silent. I mean, there's not a lot at the international level. Treaty law has some things that imply it, but as you probably all know, there's not much there. There are some regional systems. The European Union has a Space Act in proposal, somewhat controversial with U .S. companies, others who are wondering what the standards are going to be and how they're going to apply. There's national law and licensing also as a lever. So two particular tools, the licensing and regulations themselves, but also procurements. You know, what are governments going to buy and what standards are they going to ask for in these areas? So no overarching international, you know, treaty or standards and this sort of thing. But in fact, lots of technical standards that are emerging. So you're seeing places like IEEE developing new standards for security of components and how those things will fit together. And there's kind of a spectrum of these standards organizations. IEEE, as many of you know, is very geeky. Engineers walk in the room, don't really have much in the way of lawyers and politicians, but they're the engineers trying to solve their problems. But then as you move across the spectrum, you go to something like the International Standards Organizations and you have national inputs. And so national priorities also start to come in there. And you come to ITU, and the ITU T sector has a whole structure there where there's voting and all kinds of other things. So there's a range of areas where standards are developed and worked on at multiple different levels. They have different sets of interest groups that come into these sorts of standards. Many of these things are sort of non -binding norms listed up here, and some are fairly clear and detailed technical standards that you can watch. And so what we're trying to get to in some recommendations, we look at the various major stakeholders, governments themselves, the satellite owner operators, and then users who are sometimes the beneficiaries or victims of this cybersecurity. and some of the recommendations are fairly basic, which is simply, first of all, recognizing that space systems do serve a multiple critical infrastructure, so it's not just something for space people to worry about, using licensing and procurement as a lever for inducing behavior, integrating space with national cyber strategies, not separate, international consultations through a variety of mechanisms, including ITU and others, and particularly investing in the workforce. You know, again, as a space guy, I think I found that it's probably easier to teach space to a cyber person than it is to teach cyber to a space person, you know, and it's just methods of habits and thinking. But it is a multidisciplinary kind of problem, and so having education like that is true for any major level of technical development. For the owner -operators, again, some very basic things, encrypting by default, adopting zero -trade, trusting your network. building resilience into your architecture. Have somebody who's responsible for thinking about this, even if it's only a part -time job, but somebody to be that sort of focal point. And then finally, managing your supply chain. You know, where did something come from? Is there a kind of a bill of materials that you can read where this thing comes from? And so that's supply chain issues, of course. There are terrestrial issues as well as the space issue. For the public sector, you know, space is part of your supply chain. You should be asking for security guarantees or service -level agreements. Plan for degradation. Really think about your endpoints. Your terminals are one of the most common attack surfaces that will happen. And share what you learn. There are a variety of information -sharing organizations, one particularly for space. There's the SpaceCenter. There's the SpaceISAC information -sharing group. But there's also CyberISACs and one for particular terrestrial systems. So if you're in financial networks or oil and gas networks or transportation, there are various places to share lessons learned. and problems. Lastly, in close, that the issues involved here are both technical and governance issues. Terrestrial hygiene, of course, as I hopefully made the point, is necessary but not sufficient. Plural standards are around. Procurement is a lever. Capacity building is important. Manage for structural tensions. A common thing in cyber is talking about the phrase CIA, confidentiality, integrity, and availability. Different groups care about different things. Security communities, of course, care about confidentiality. Scientific users are really big on integrity. They don't care if anybody steals their data, but boy, don't mess with the data. The data better have a high degree of integrity. Commercial people are all about availability. This thing has got to run because this is where we make money. Not all things are equal for all communities, and people stress different things.
Gretchen Bueermann
You narrowly avoided it. Narrowly avoided it. No, I have to say that I don't think I've ever seen someone who is self -described as a non -cyber person put ISO 27001 on a slide. So I think that maybe we can give you a sort of like an honorary pin at the end of this. Yeah. Not a badge. Yes, 256. Yeah, exactly. I'll point you later. No, but thank you so much for this introduction. And I think it's a great baseline for us to have this conversation. And I'll turn it over to Mr. Al -Hassan, who maybe you can talk a little bit from the cyber perspective and the GCF about why you're involved in this and why it's important.
Abdurahman AlHassan
Thank you very much and good morning, everyone. It is a privilege to be with you today in Mrs. 2026, a platform that has for more than two decades embedded the conviction that the cyberspace future must be shaped collectively. So the GCF, the Global Cyber Security Forum, was established as an independent organization and nonprofit organization headquartered in Riyadh with a single mission to contribute in strengthening the cybersecurity posture globally by working with all relevant stakeholders from government, from private sector, from academia, and from NGOs and NGOs. With that, we do this in three ways. First, through strategic initiatives, which are programs that has been launched to translate the insights of the experts to actions in real life. And the second one, through which we conduct and publish research for issues that will define the future of cyberspace. And that's part of why we are contributing. We are contributing with George Washington University to do the research in space. And third, by convening global cybersecurity leaders, we gathered in Duwad with over 10 ,000 participants from around more than 100 countries to discuss and to exchange views about the cross -cutting issues in cybersecurity. So over the past years, we have successfully launched several initiatives that spans from cybersecurity, child protection in cyberspace, and recently we have launched together with the UN a global initiative on capacity building. We have also launched two centers with the objective to advancing multi -stakeholder. A collaboration in areas related to cybersecurity. The first center related to a center for cyber economics, it has been launched. together with the World Economic Forum, and we are working together with them to produce some key numbers and key reports about the intersection of cybersecurity and economics. The second center was on the operational technology. It has been launched together with Aramco and Energy Company in the Kingdom and the globe. And additionally, our flagship research is centered around identifying shared priorities, building the evidence and the housing partner to act together. In that spirit of producing knowledge, we have partnered with the Space Policy Institute. in George Washington University, where space has two most consequential trends. The first one is that there is a growing dependence on the space surface in the world. And the second one is expanding cyber threat landscape, where we need to find a solution to tackle these areas. And that's what exactly makes this partnership distinctive with George Washington University. And as Scott has mentioned, what makes really this partnership distinctive is what makes Wizzles distinctive.. Yes. operators and and established space power and energy so that bridge building is a serious response to the challenge and I take this opportunity to thank George Washington for this excellent partnership and we hopefully the outcome of this report will be beneficial for the world. Thank you.
Gretchen Bueermann
Thank you very much for that and I think I would be remiss if I didn't also on behalf of the ITU thank you for your contribution to this valuable research because it's really I think a good example of the types of collaborations that we discuss when we think about this. In that spirit I think I'd like to turn it over to our panel and our colleague Alexandra Vallee is also here online and just before I ask you the first question I'll just note to our panelists that if we'll try to do one or two rounds depending on time I know that But almost everyone has a flight to catch, so I will try to keep it brief. So if you could, for your remarks, three to four minutes. But I think in the spirit of the introductions that we've just heard, Alexander, maybe you can tell us a little bit more about sort of zooming out, how you see the most useful roles for research institutions and the wider expert community in shaping the policy conversations on both space and cybersecurity.
Alexandre Vallet
Yes, thank you, and good morning to all. Yes, I think, in fact, we have had an excellent example of what, in my view, is the most important and urgent role of research institutes. In these discussions, we have had an excellent example with the introduction by Dr. Pace, and this is to bring clarity in the concepts that we are discussing. Because historically, space cybersecurity was not really – attractive for cybersecurity specialists because satellite communication were in the past. and East Market. And therefore, there is a tendency now that when we address space cybersecurity, to try to replicate, in my view, too much what has been done in terrestrial cybersecurity. And this would be a mistake as highlighted by Dr. Pace's presentation. There are specificities for space cybersecurity that need to be recognized. But in my view, also, we need to build a common language to speak about these specificities and to make sure that we have a kind of common framework to address these discussions and especially the policy conversation. In my view, this would be the first main role to bring clarity to the concepts. And I think we have a great example this morning. I hope also that the work done by George Washington University together with GCF and ITU will be of great help to the And the report will also help as a positive step towards this goal. The second role I see is to build stronger and stronger standards for cybersecurity in an iterative manner, of course, with a lot of agility. But also, knowing that one of the challenges when it comes to space is that the space industry has historically been very keen on proprietary solutions. And adopting common standards on space cybersecurity will also be a cultural challenge for space. So I think here the research world, the academics and other researchers can can help change this culture. So that would be my two main points, bringing clarity to the framework and also encouraging cultural change to move towards standardized solutions for cybersecurity protocols.
Gretchen Bueermann
Thank you so much for that and I think it's very useful to hear it from the ITU perspective as well because I think, I know that you think a lot especially when you think about the radio regulations thinking about how, at which pace things tend to move and how far in advance we need to be considering these things as we adapt and maybe on that note I'll turn to Ms. Hunter who I think Cyber Ambassador is perhaps one of my favorite job titles I've heard in a long time but maybe if you think about these topics from the national perspective and thinking about building cyber resilience from your position how can governments best approach this type of coordination and response when space -enabled infrastructure spans international borders and the space domain?
Jessica Hunter
Dermeen. Thanks, Gretchen. I appreciate the opportunity for us to be part of this panel. And if Scott is the space guy, then I'm definitely the cyber ops person. So this is a great example of us all working together. And I promise you, space is not the forgotten child when it comes to cybersecurity. And I'll share a bit on that. And so I think the panel and Scott's done a great job of setting the scene. So I will adjust a little bit what I say, mindful of time. I think the panel's in agreement that cybersecurity for space assets and space capabilities is not just a technical challenge. And that's because of it crossing digital borders and national borders and importantly, jurisdictions. And that's where some of the legal frameworks come into play there. But that requires a holistic approach. And in Australia, in particular, from a national perspective, we've recognized that criticality of space capabilities. So under our 11 sectors of critical national infrastructure, we have designated the space sector and space capabilities. So that gives it additional protections and additional obligations from a national perspective. And I'm excited to see that some of Scott's recommendations on the screen are already embedded in our systems of national significance in Australia. But what I thought I might do to unpack that a little bit is explain some of the diplomatic risks that we see with cybersecurity against space assets. I won't bore folks too much on the cybersecurity threat picture, but I will touch a little bit on where we think the most vulnerable segments are and then play out, I think, globally, regionally and locally, what some of the government solutions are in that space. So just in terms of diplomatic risks, because of the cross-border nature and because, frankly, there is a lot that is not commonly understood about space capabilities to non-space guys, the first is that risk of misunderstanding. And risk of misunderstanding in that, is it a cyber attack? Or was it just a physical accident that has occurred in any of the four segments? And that obviously leads to then a risk of escalation or different responses across different governments in terms of how they're interpreting the information. And we've seen that play out in some of the incidents that Scott's already put up on the screen, and particularly around the Viasat matter several years ago. So that's where we start to see different interpretations of standards, norms and law and different relationships between governments. And I think probably the third risk diplomatically is that risk of delay of detection of the matter, resolution of the matter and then building resilience back in. So those, I would say, are the diplomatic risks which form into the solutions that we propose. And some of the technical risks across the four segments, I think, if I'm going to generalise as a cyber security person, which is very scary to do, in the space segment, that's really more of the trusted space, which requires or trusted capability, which requires quite sophisticated... activity to disrupt from a cyber perspective. But when you move into the ground segment and the user segment in particular, ground segment's highly interconnected and has greatest risk of exposure or attack surface exposure. And then user segment, humans are fallible. We're the ones that are most at risk because of the way we configure that end user capability. And frankly, that's where there's greatest, poorest hygiene. And then finally, on the comms links space, obviously very vulnerable to interception and disruption. So from a cyber security perspective, I see four attack surfaces that need to be protected. And to Scott's point made earlier, cyber security will always black box the capability to ensure that it is confidential and protected. But particularly in space and to the point around it being a national security asset, that is not viable. So that's where the marriage needs to come together between cyber security experts and in particular space experts. So with those risks understood, what is kind of the framing of government? At a global level. Obviously, there are non -binding norms in place, which, frankly, at the moment, given the fast -moving nature of this domain, there's a bit more flexibility and inclusivity when you have non -binding norms. So I would recommend that negotiations continue not to create new legal instruments, but actually focus more around shared expectations and some of those non -binding norms. And we see international law, obviously, apply both in the digital space and, obviously, online and offline. But at a global level, there is already a wide variety of networks that exist within the cybersecurity community that just now need to plug into the space community. So in particular, at the global level, you have computer emergency response teams, which truly understand the tactical and operational sharing of information when there are incidents. You have the International World and Warning Network, which is able to, again, identify risks that can come out. And, obviously, there is a range of points of contact under the global mechanism to kind of connect countries. But I think the challenge is the glue of how we plug that into the border space community. If I pivot just to the region in particular, Australia within the Asia -Pacific region, AP CERT is very much focused on our particular region, which is growing significantly, particularly the race of LEOs into the region because of so many fragmented island nations. Australia in particular is also co -chair of PAXON, which is a specific community coming together to lead CERT initiatives and cybersecurity response capabilities. So there are mechanisms in place, including ISACs, which Scott's mentioned, and now it's just that plug -and -play capability. And finally, just to bring it to a local level, I think we've already talked about some of the recommendations around redundancy and comms path, clear agreements with providers, clear incident response plans, business continuity plans, clear role definition, who's actually responsible for which component of the segment. and regular risk assessments and vulnerability assessments. All of that is grounded in basic cybersecurity awareness. So I do agree with Scott that it cannot be exactly the same as cybersecurity. It's kind of basics plus plus in space. So how do you add on to the top? And then finally, I've talked a lot about diplomacy in governments. None of that happens without industry. So that partnership is incredibly important. And we've learned in Australia it has to be cross -sectorial as well. So it's not just the space sector, but the energy and the telco sector need to come together when you're talking about the cybersecurity component. Thank you.
Gretchen Bueermann
Thank you so much for that. And I think there's a lot to unpack there. But maybe, and Dr. Pace, I hope you don't mind, but I know that Mr. Al -Hassan has to leave quite soon. But I really would love to hear his perspective on this because, you know, at the beginning of your remarks, you said space is not the forgotten child. And I think that we see that's increasingly true, right? We see it now. It's becoming more popular. of the conversation when we talk about critical digital infrastructure. And so I think perhaps I would love to hear from the GCF perspective, you know, why space? Why be involved in this? And what do you see as the opportunity for GCF to turn these findings from the report into action?
Abdurahman AlHassan
Thank you very much. In fact, the GCF work spans across the five dimensions that shape the cyberspace, the geopolitics, economics, social and behavioral and technical. What makes space remarkable is that it cuts across these four dimensions out of five, which are geopolitics, economics, social and technical. From a geopolitical lens, space surfaces spans borders in the space. So I set out a constellation of two countries, so dozens. A cyber incident that will take place in the orbit is a one -nation issue. So it is an issue of many nations, and that's why it is a geopolitical issue, not a one -nation issue. From a country to a nation, this economy is heading to trillions. But the fact is quite a lot of it carries a supply chain. So if there is an issue with the satellite, it is not the issue of the satellites, but it is a wider issue that will impact the global economy. From a social dimension, connectivity, navigation, disaster response, it is a global issue. Communication, food, security. structure for the economy as a secure sovereign participant or elsewhere. And from a technical dimension, cybersecurity have I say that systems must be secure by design. And once you build the satellite and the software will stay for decades. So it cannot be at the orbit and the issue needs to be dealt with accordingly. So it's about security and strategy. for every stakeholder that we work with, and that's why the GCF is collaborating with George Washington University to double down our efforts in that direction.
Gretchen Bueermann
Thank you so much for that, and I think you outlined, I appreciate the sort of categories that you've outlined it in, and I wonder if perhaps, Dr. Pace, hearing sort of the central themes that each of our panelists deals with, both in the sort of regulatory space and standards from the national perspective, from the perspective of GCF thinking about putting these things together, maybe perhaps you can help us to wrap up our panel by thinking about, you know, in your report and in the presentation you've made, you've set out these seven strategic imperatives, and that includes closing the gap between aerospace and cybersecurity communities, which I think we're already doing right now. But, and I... I'm not asking you to pick one, but perhaps take, maybe is there a central constraint or somewhere that we start? Where do we begin with solving some of the problems that have been articulated today?
Dr. Scott Pace
Okay, that's a great question. You can't do everything. You have to set priorities. I think one of the first scene -setting things is to stress how much commonality people have. I spent about ten years doing a lot of ITUR stuff, you know, spectrum fights over radio. When space spectrum was considered sort of a boutique topic off to the side compared to there was this new thing called 3G that everybody was excited about. And in those discussions, of course, I was working on the U .S. side. And what was striking to me was how much we had in common, how much support we got from the developing world, because we had a common set of interests. We wanted our space systems like GPS and satellite communications all to work. All these developing countries wanted this to work because they recognized their infrastructure. depended on it. And so while there were industrial policy conflicts, frankly speaking, with parts of Europe, in terms of where things came out in the ITU, the alliance of interest between space powers, so to say, U .S., and the needs of the developing world kind of came together, and we found a lot of common ground and agreement to work with. So my orientation, you know, comes from, I see a commonality of interest, and I think cyber is also that. The countries that depend on space systems and the countries that are in the area of providing space systems both have a common interest. So then the next thing I would say after that understanding is to recognize how important the technical community is in this. And going back to my discussion about, you know, space people don't want to be told what to do. But so some of the more promising standards that are coming out. do show how to build a secure system almost component by component. And what it avoids is a top -down structure being told to do compliance, maybe by lawyers and other people that the engineers don't really respect. And so to some extent you want to give, well, you want policy and lawyers to say, these are the social needs that we have to have. These are the performance goals we're trying to get at. You also want to think, well, who are the people who are actually going to do this? And so they need to feel that they are empowered and that they have choices to make. Okay, I've got to do what my boss tells me to do, but I'm going to do it in a way that has my own creativity so I'm not just being told what to do as if I don't really have a mind of my own. And I think what's been encouraging in the standards world, we're seeing some of that start to emerge. I remember about ten years ago, So friends of mine in the satellite community were working on early satellite standards, cyber standards, because they were concerned of regulation coming in, and they wanted to kind of preempt that and have their own standards so they wouldn't be. And it didn't really go anywhere. And it didn't go anywhere because there wasn't really that large of a demand for it. And so what I see changing is that demand is increasing as there is this recognition that it is a broader consensus about it. But the same resistance to top -down instruction, goals, don't tell us how to do something. And so this is where there needs to be a conversation across these different cultures, not just space and cyber cultures, but across sort of technical engineering cultures and policymakers. I often tell my students that a lot of what policymaking is is a translation function. You're trying to explain things across a technical community to a legal community. You're trying to explain things across a technical community to a financial community. They all think they're speaking the same language, and they're not. And so, you know, multiple translation functions is a lot of what this is about.
Gretchen Bueermann
I think that's quite a fitting conclusion, considering the diversity of functions that we have in the room. I know we only have about two minutes left. I wanted to leave it to see if we could take one or two questions from the audience. But I think before we do that, I believe my colleague, Brita Malura, has just a few remarks.
Speaker
Thank you, Gretchen. And thanks to the panelists. So this is less of a remark and more of a thank you on behalf of the ITU. You know, we are very grateful to George Washington University and Professor Pace, obviously for his outstanding leadership in this effort, which is a very valuable resource for the ITU. We are also grateful to the Global Cybersecurity Forum and to Abdur Rahman personally, A, for providing the GCF as a platform, and also for the generous support that they're offering for this work to happen. And within the ITU, it's truly a collaborative effort. As you can see, Alexander there heads this work in the Radio Communications Bureau. There are colleagues from the Development Bureau, the colleagues from the Standardization Bureau, and where I sit in the Secretary General's office with Gretchen. So it's truly an ITU -wide effort in terms of supporting the work that George Washington University and GCF are doing. And we look forward to the next iteration of the handbook that we can be consulting on. Thank you very much.
Gretchen Bueermann
Thank you very much, Preetam. Thank you. Thank you. Some of our panelists may need to leave, so I won't hold you hostage here. But I think we did have just one question. So for those that are remaining, please go ahead.
Audience
Hello, thank you very much for the interesting panel I have a question related to NTN and mobile convergence and we see an increasing cooperation between satellite operators and mobile operators and I would like to know if there is any concrete examples of such cooperation in security and cyber security
Gretchen Bueermann
I think you've got about 30 seconds to answer this.
Dr. Scott Pace
The first answer is yes and what you're seeing in 3GPP, the non -terrestrial network standards that are rolling out there and the challenge that we have, I think the space community has, is de facto security standards are being driven by 3GPP. I mean there are billions of devices and the non -terrestrial network standards are built in there but these are also trying to integrate into new systems direct -to -device, LEO systems and so forth that are new. And one of the charts I didn't show was you have these networks on the ground, you have existing proprietary systems, LEO and geosystems already in orbit, and you have actually future systems. I can give a whole separate lecture on solar system internet, if anybody wants, which has delay -tolerant network and bundle protocols. So the challenge is going from the 3GPP non -trusted network reality, existing installed base of proprietary systems, and then moving ahead for delay -tolerant networking, which is an overlay network that happens. So I would say...
Gretchen Bueermann
15 seconds.
Dr. Scott Pace
Look for things at work 27, as some of the direct -to -device discussions occur, because that will affect the environment for the security protocols that are going to be implementable.
Audience
Is there a recommended white paper or some research project that you would share with us?
Dr. Scott Pace
I don't have a good one. perhaps you do can discuss this great topic
Gretchen Bueermann
I would love to ask you for sure I am appreciative for the question and then thank you to all of our panelists I'm sorry we didn't have more time together thank you to everyone for joining us here today and I really appreciate the discussion and I hope that we can continue it so thank you have a good day and thank you Alexander

Avertissement : Il ne s'agit pas d'un compte rendu officiel de la session. DiploAI génère ces ressources à partir d'enregistrements audiovisuels ; elles sont présentées telles quelles, y compris d'éventuelles erreurs. En raison de contraintes logistiques (audio/vidéo ou transcriptions), les noms peuvent être mal orthographiés. Nous nous efforçons d'être aussi précis que possible.