Securing the 17th Sector: Why Space is the Next Critical Infrastructure Frontier

By Benny Czarny, Founder and CEO, OPSWAT [ Join Cybersecurity Insiders ]

Space is entering a new boom cycle, expanding beyond rockets, NASA, and satellites-as-communications infrastructure. Three separate headlines from last year make that clear: Elon Musk declared data centers in space were coming soon, Starcloud launched a spacecraft with an Nvidia H100 chip running a version of Google’s Gemini AI model from space, and Google revealed Project Suncatcher to explore satellite clusters equipped with TPUs.

Space is moving from transportation to communication, from communication to data, from data to computation, and from computation to AI. It is now a global digital infrastructure layer involving nation-states, commercial operators, defense agencies, and multinational supply chains…and as history proves, every digital infrastructure layer becomes a cyber target. It is time for CISA, which lists 16 critical infrastructure sectors, to officially declare space the 17th.

Space needs cybersecurity too

For decades, most space programs were owned or heavily controlled by government organizations, such as militaries, intelligence and national research agencies, which do not always disclose incidents publicly. Some cybersecurity failures are described as anomalies, some incidents are classified, and some attacks are handled quietly by agencies, contractors, or defense partners.

Even with this public record limitation, several organizations monitor cybersecurity risks and incidents related to space, including Space ISAC, NASA OIG, and ENISA. After reconciling their results with public sources, I analyzed most known breaches and found that space suffers from the same cybersecurity vulnerabilities as terrestrial critical infrastructure: unsafe files, supplier compromises, weak software update processes, removable media risks, stolen credentials, and poor network segmentation.

We should thus treat space systems as critical infrastructure and the cybersecurity systems that support them as mission-critical infrastructure. Naming space a critical infrastructure sector assigns a federal agency responsible for the sector, creates a formal channel for operators and the government to share threat intelligence, and sets a security baseline for every participant to build toward. Given its importance, space deserves the same structured oversight.

Cybersecurity strategies for space

Cybersecurity for space adds two dimensions that change everything: time and environment.

On Earth, if something goes wrong, we assume we can connect, inspect, patch, restore, or send someone onsite. In space, many of those assumptions break down because communication is slower, more expensive and limited, and harder the farther you move from Earth. Modern security tools increasingly depend on constant interaction with the cloud: reputation lookups, hash checks, signature updates, AI model updates (a growing dependency as AI-enabled systems move into orbit), sandbox submissions, telemetry uploads, and centralized verdicts. On Earth, this works because connectivity is fast and reliable. In space, that assumption is dangerous.

Similarly, if you run a space mission for many years, you cannot assume you can patch your infrastructure given that spacecraft often operate with old hardware, limited memory, radiation-hardened processors, constrained bandwidth, little power, and small communication windows.

What do you do when you cannot rely on fast communication, constant visibility, cloud-based response, or sending someone onsite? I suggest three strategies:

1. Move space cybersecurity from detection first to prevention first

Detection is still useful, especially on ground systems, terminals, and enterprise environments around the mission, but it assumes you can see the attack, and then quickly analyze, respond, and recover. In space, that assumption is weak because visibility may be limited, communication may be delayed, compute may be constrained, and recovery may be slow or impossible. By the time you detect the problem, the mission could already be in jeopardy.

We must adopt a strict zero trust posture for orbital assets. Treat every file, software update, AI model, payload package, command package, and removable media device as untrusted until you inspect, validate, sanitize, and approve it. At the same time, you should use multiscanning, sandboxing, content disarm and reconstruction (CDR), schema validation, signed updates, allow lists, command validation, and audit trails before anything reaches the mission environment.

2. Implement segmentation by design

Don’t treat mission control like normal enterprise IT, and don’t let engineering systems freely touch operational systems. Ensure supplier access is narrow, temporary, logged, and isolated, and aggressively separate ground stations, command paths, software update systems, test environments, and collaboration tools.

A single compromised laptop, stolen credential, infected file, bad update, or supplier breach must never have a path to mission operations. Firewalls are important, but in the most sensitive mission paths, don’t trust a firewall alone. Because firewalls are software controlled, they can be bypassed or compromised. A data diode or unidirectional gateway is the better model because it enforces one-way data movement through hardware, which is harder to breach, not just by policy.

3. Move critical security decisions closer to the mission

Long missions need local validation, onboard integrity checks, safe mode behavior, rollback planning where possible, and security processing closer to the spacecraft. That also means investing in ruggedized, radiation-tolerant hardware capable of enforcing security controls locally. As we move security decisions away from Earth and closer to the mission, we cannot assume that traditional cloud services, enterprise appliances, or software agents will always be available, practical, or compatible with the operating environment.

While the cloud can support planning, analysis, and coordination from Earth, don’t use it as a real-time control loop for deciding whether something is safe. The farther a mission moves from Earth, the more cybersecurity must shift from detecting and responding to preventing, isolating, and hosting locally

Prevention-first cybersecurity for space

While most public incidents today originate from terrestrial systems, as space programs evolve and orbit becomes cheaper to reach, we should not assume that cyberattacks will always come from Earth. The threat landscape will expand as governments, or even commercial operators, position spacecraft, satellites, or other orbital assets closer to a target to support cyberattacks, electronic warfare, interception, jamming, spoofing, or intelligence gathering operations.

Space cybersecurity cannot be built around the idea that someone on Earth will always be available to fix the problem. It must be local, deterministic, segmented, and prevention-first.

Join our LinkedIn group Information Security Community!

No posts to display