Our method, in the open.

We publish full reference work so the way we think about risk can be examined rather than taken on trust. Each piece names its sources and its date, and the method behind it is the one we run for clients.

CE-TM-SAT-001  ·  v1.0  ·  8 June 2026

Threat Model for Satellite Systems Security

A public reference model across the space, link, ground and user segments and the supply chain, grounded in ECSS-E-ST-80C, the NIST satellite profiles, SPD-5, SPARTA and ITSG-33, with a kill chain worked through the 2022 Viasat KA-SAT incident from initial access to attribution.

24

named threats

8

actor classes

18

sections

Read the threat model

Read alongside it

The method the threat model applies, set out in full.

How a risk score is reached

The likelihood and impact anchors, and why scoring risk twice, before and after controls, is the part most assessments get wrong.

The scoring model

The frameworks behind the work

What NIST SP 800-30, ISO/IEC 27005, STRIDE and MITRE ATT&CK each contribute, and where each one stops.

The frameworks

Further reference work is published as it clears review. We would rather release nothing than release something we cannot stand behind.

Want this applied to your environment?

The method we publish here is the method we run for clients. Tell us what you operate and what you need to decide.

Request an assessment