Threat Model for Satellite Systems Security

A public reference threat model covering the space, link, ground and user segments, the supply chain and the full mission lifecycle, grounded in the current North American and European space security standards and a real worked incident.

Document

CE-TM-SAT-001

Version

1.0

Date

8 June 2026

Classification

Public

01Executive summary

Satellites are now embedded in the daily operation of communications, navigation, banking, aviation, agriculture, weather forecasting, emergency response and national defence. A single compromised spacecraft, or far more commonly a single compromised ground system, can ripple outward into terrestrial critical infrastructure that has nothing obvious to do with space. That coupling is what makes satellite cybersecurity a strategic problem rather than a niche engineering concern.

This model describes the satellite ecosystem as five interacting parts, the space segment, the link segment, the ground segment, the user segment and the supply chain, all governed by an eight-phase mission lifecycle that runs from design to decommissioning. It enumerates the threats that apply to each part, maps them with STRIDE, positions the relevant threat actors, traces a representative end-to-end attack path, and recommends a layered target-state architecture. The analysis is grounded in published guidance from both sides of the Atlantic, including ECSS-E-ST-80C (ECSS 2024), NIST IR 8270 (Scholl and Suloway 2023), NIST IR 8401 (Lightman et al. 2022), Space Policy Directive-5 (The White House 2020), the Aerospace Corporation SPARTA matrix (2022) and Canada's ITSG-33 (CSE 2012).

02Scope and method

This is a reference document, not an assessment of any specific operator. It describes what can be attacked, who would attempt it and what reduces the risk, using the same structured method we apply to client systems. Threats are identified per segment, categorised with STRIDE and mapped to real adversary behaviour through MITRE ATT&CK and the space-specific SPARTA matrix. Where a full assessment would then score each threat for likelihood and impact against a named operator, this model names and defines the threats so the reasoning can be read and challenged.

03The five segments

A satellite system is not one thing to defend. It is five, and the boundaries between them are where risk concentrates.

  • Space segment. The spacecraft, its bus and payload, and the flight software that runs them.
  • Link segment. The radio-frequency paths that carry commands up and telemetry and data down.
  • Ground segment. The mission control centre, ground stations and the networks that operate the constellation.
  • User segment. The terminals and modems through which people and systems use the service.
  • Supply chain. The manufacturers, integrators and software sources behind every other segment.

Most operators invest heavily in the space segment, because it is the hardest to reach and the most expensive to lose. The KA-SAT attack, examined below, never touched the spacecraft. It went through the ground segment and landed on the user segment, which is exactly where defensive attention tends to be thinnest.

04The mission lifecycle

Security is not a phase, it is a property that has to be carried through eight of them. Design, development, integration and test, launch, commissioning, operations, extension and decommissioning each introduce their own exposure, and a decision taken early, a cryptographic choice or a trust boundary, is often locked in for the fifteen or twenty years the asset flies. The European standard and US policy now both make the same point: security designed in across the lifecycle is the only kind that holds, because most of these assets cannot be meaningfully patched once they are in orbit.

05Threat actors

Capability and intent vary widely, and defensive priority follows them. The classes below are ordered roughly by the capability they bring.

ClassProfile
Nation-state military and intelligenceHighest capability and intent, able to combine cyber access with counterspace means and to abuse legitimate operational tooling once inside. The 2022 KA-SAT attack sits here.
State-aligned proxiesGroups operating with state tolerance or direction, often reusing military-grade tooling against softer targets in the ground and user segments.
Organised cybercriminalsFinancially motivated, most credible against the IT of the ground segment through ransomware and extortion rather than against the spacecraft.
HacktivistsMotivated by disruption and publicity, typically targeting exposed ground infrastructure and public services.
InsidersOperators, engineers and contractors with legitimate access. Little sophistication is required when access is already held.
Industrial espionageCompetitors and their proxies seeking mission data, payload configuration or intellectual property rather than disruption.
Security researchersNon-malicious, but their findings define what is publicly possible and shorten the path for others.
Opportunistic actorsLow-skill actors exploiting exposed ground IT, misconfiguration and default credentials without a space-specific goal.

06STRIDE in orbit

STRIDE gives the model its structure. Each category has a specific meaning once it is applied to a space system rather than an office network.

CategoryManifestation in a satellite system
SpoofingUnauthorised commanding of the spacecraft, forged telemetry, or a rogue terminal presenting as a trusted one.
TamperingModification of flight software, payload data in transit, or modem firmware on the ground and user edge.
RepudiationCommands or configuration changes that cannot be attributed because the operations network does not log to an evidentiary standard.
Information disclosureInterception of unencrypted telemetry or mission data, or exposure of operational data held in the ground segment.
Denial of serviceUplink and downlink jamming, on-board resource exhaustion, or a wiper that removes the user segment from service.
Elevation of privilegeMovement from an exposed ground network into the trusted management segment, then to commands only privileged operators should hold.

07Threat catalogue

The twenty-four threats below are grouped by the segment they act on, with the supply-chain and lifecycle threats that cut across all of them at the end. In a full assessment each would carry a likelihood and impact score against a specific operator. Here they are named and defined so the model can be read and challenged.

Space segment

T-01Command link spoofing
Commands the spacecraft accepts as authentic, absent strong command authentication.
T-02Flight software tampering
Unauthorised modification of on-board software, in flight or through the update path.
T-03Payload data manipulation
Alteration of sensor or mission data so what reaches the ground is no longer trustworthy.
T-04On-board resource exhaustion
Deliberate consumption of power, memory or processing to degrade functions.
T-05Unsafe command sequence
Legitimate commands sequenced to place the vehicle in a hazardous or unrecoverable state.
T-06Flight-software supply chain implant
Malicious logic introduced before launch through a compromised component or build.

Link segment

T-07Uplink jamming
Denial of the command path, cutting the operator off from the vehicle.
T-08Downlink jamming
Denial of the telemetry and data path, blinding the operator to vehicle state.
T-09Meaconing and replay
Capture and re-transmission of legitimate signals to confuse or mislead.
T-10Telemetry eavesdropping
Interception of unencrypted telemetry, exposing state and operational patterns.
T-11Signal spoofing
Injection of counterfeit signals, including position and timing services others depend on.
T-12Protocol exploitation
Abuse of weaknesses in space-link protocols not designed for a hostile network.

Ground segment

T-13Ground network intrusion
Initial access to the ground or management network, often via a misconfigured remote-access appliance.
T-14Lateral movement to operations
Movement from a general network into the trusted segment that operates the constellation.
T-15Abuse of management tooling
Use of legitimate operational tools and commands to cause harm, evading malware-only controls.
T-16Privileged credential theft
Capture of operator credentials, granting access that needs no exploit once held.
T-17Destructive payload on ground assets
Wiper or ransomware deployed to ground systems or the devices they manage.
T-18Operations-centre insider misuse
Deliberate or negligent misuse of access by staff or contractors.

User segment

T-19Terminal firmware wipe
Remote destruction of modem or terminal firmware, removing populations of users from service.
T-20Terminal compromise for pivot
A compromised terminal used as a foothold or as part of a botnet.
T-21User-edge interception
Interception of data at the user terminal, where protection is weakest.
T-22Rogue terminal
An unauthorised terminal obtaining access to the network.

Supply chain and lifecycle

T-23Manufacturing and integration compromise
Weakness introduced during build, integration or the broader supply chain.
T-24End-of-life exposure
Weaknesses introduced or left unaddressed during decommissioning and disposal.

08Attack path: KA-SAT, 2022

On 24 February 2022, the day of the Russian invasion of Ukraine, an attack on the KA-SAT network disabled tens of thousands of satellite broadband modems across Ukraine and Europe. It is the clearest public demonstration of the point this model makes, so it is worth following step by step.

01

Initial access

A misconfigured VPN appliance on the KA-SAT ground network, operated on Viasat's behalf by the Skylogic subsidiary, allowed remote access to the trusted management segment.

02

Lateral movement

The attacker moved through the trusted management network to the specific segment used to operate the network, without touching the spacecraft.

03

Abuse of legitimate tooling

From that position the attacker issued legitimate, targeted management commands to a large number of residential modems, so no exploit against the modems was required.

04

Destructive impact

The AcidRain wiper overwrote key data in the flash memory of tens of thousands of SurfBeam2 modems, rendering them inoperable and requiring reflashing or replacement.

05

Spillover

Downstream effects included the loss of remote monitoring and control of roughly 5,800 Enercon wind turbines in Germany, alongside disruption to thousands of customers across Europe.

06

Attribution

On 10 May 2022 the European Union and the Five Eyes governments publicly attributed the attack to the Russian military intelligence service.

The satellites were never the target. The path ran through a remote-access weakness in the ground segment, then used the operator's own management tools to reach the user segment. A satellite operator's resilience depends on the hygiene of the network that commands it.

09Alignment to SPARTA

The Aerospace Corporation's Space Attack Research and Tactic Analysis matrix is the first publicly available threat framework built specifically for spacecraft. It follows the same tactics-and-techniques structure as MITRE ATT&CK, which makes it a natural partner to this model. Where ATT&CK describes how the ground segment is compromised in enterprise terms, SPARTA describes what can then be attempted against the spacecraft itself. Reading the two together closes the gap between a ground-network intrusion and its consequence in orbit, which is precisely the gap the KA-SAT attack exploited.

10Defence in depth

No single control secures a satellite system. The measures below work because they overlap, so a failure in one is caught by another.

  • Segment the ground network. Separate general IT from the trusted operations segment, so access to one is not access to the other.
  • Harden remote access. Treat every remote-access appliance as a primary target. Enforce strong authentication, restrict exposure and monitor it closely.
  • Authenticate commanding. Require strong authentication on the command path so a spoofed command is rejected rather than executed.
  • Encrypt the link. Protect telemetry and mission data in transit so interception yields nothing usable.
  • Log to an evidentiary standard. Record operational actions so any command or change can be attributed and challenged afterwards.
  • Watch for legitimate-but-hostile action. Detection cannot rely on malware signatures alone when the adversary uses the operator's own tools.
  • Secure the supply chain. Assess components and build pipelines before launch, when a defect can still be corrected without a mission call.

11Residual risk

The point of the exercise is the distance between two numbers. A representative ground-segment intrusion enters the register with a high inherent score, because its likelihood is real and its impact reaches terrestrial infrastructure. The controls above move it, but they do not erase it, and the residual position is what an operator has to decide whether to accept.

ImpactRI

Likelihood →  ·  I inherent, R residual, illustrative

Scored across a full operator, the residual view becomes a heat map that ranks where remaining exposure sits. It is the ranking, not the individual cell, that tells a programme where its next dollar belongs.

12Target-state architecture

A defensible satellite system separates its operations network from everything else, authenticates and encrypts its links, and logs its commanding to a standard that survives scrutiny. Remote access into the operations segment is minimised, hardened and watched. Command authority is held narrowly and every use of it is attributable. None of this makes an attack impossible. It makes the path longer, louder and more likely to be caught before it reaches impact, and it means that when a question is asked afterwards, the answer is in the logs rather than in a reconstruction.

13Emerging concerns

Proliferated constellations and automation

Constellations of thousands of satellites, operated through heavily automated ground systems, change the shape of the problem. Automation that helps operators also helps attackers scale, and a single flaw in a common ground platform now has thousands of vehicles behind it.

On-orbit servicing and software-defined payloads

Rendezvous, proximity operations and in-orbit reconfiguration create new command paths and new trust relationships between vehicles. Each is a fresh boundary that must be authenticated and monitored.

AI-scaled offence and the quantum transition

The combination of AI-scaled offence and an approaching quantum transition will stress current practices faster than they are being adopted, particularly for assets whose cryptography was fixed a decade before either arrived.

14Standards landscape

The guidance an operator can build on has matured quickly. Each of the following contributes something distinct, and none is sufficient alone.

StandardSourceContribution
ECSS-E-ST-80CECSS, 2024The European standard for security across the full space-system lifecycle, designing security in rather than bolting it on.
NIST IR 8270Scholl and Suloway, 2023An introduction to cybersecurity for commercial satellite operations, framing the problem for operators.
NIST IR 8401Lightman et al., 2022Applies the Cybersecurity Framework to the satellite ground segment, where most real attacks land.
SPD-5The White House, 2020US policy setting cybersecurity principles for space systems, strong on principle but voluntary in force.
SPARTAAerospace Corporation, 2022A space-specific tactics-and-techniques matrix, the ATT&CK analogue for spacecraft and link.
ITSG-33CSE, 2012Canada's lifecycle approach to IT security risk management, the control and risk backbone we build on.

15Are current practices sufficient?

The honest answer is partly. The frameworks now exist and are good. Whether they are sufficient depends on whether they are implemented consistently across an industry with very uneven maturity, and on whether they keep pace with how attackers actually operate.

Strengths

  • A coherent body of guidance now spans both continents. SPD-5, the NIST satellite profiles, SPARTA and ECSS-E-ST-80C give operators a clear, current baseline that did not exist five years ago.
  • The principle of designing security in across the full lifecycle, rather than bolting it on, is now explicit in both the European standard and US policy.
  • Space-specific tooling such as SPARTA closes the gap that generic IT frameworks left around the spacecraft and link.

Weaknesses and gaps

  • Most published guidance is voluntary. SPD-5 sets principles but contains no enforcement mechanism, and adoption across commercial operators is inconsistent.
  • The ground segment, repeatedly the decisive target, is still often secured to ordinary enterprise standards rather than to the standard its consequences demand.
  • Long asset lifetimes lock in cryptographic and architectural decisions that age badly, and many fielded assets cannot be patched at all.
  • Supply-chain assurance remains immature relative to the depth and internationalism of the space supply chain.

Projection

The Viasat incident demonstrated that a state-level actor can produce continent-scale disruption through the ground segment alone, and the conditions that enabled it, exposed remote access and abuse of trusted command paths, are common. The most likely future is not an exotic in-orbit hack but more of what already works: ground intrusions, supply-chain compromise and denial of service, executed at greater scale.

Bottom line

Current practices are sufficient to defend a well-resourced, well-run programme that actually implements them. They are not yet sufficient across an industry where implementation is optional and uneven, and the gap sits mainly in the ground segment and the supply chain rather than in orbit.

16Conclusions

Satellite security is decided on the ground far more often than in space. The standards to do it well now exist, and the task is implementation across a long-lived, deeply interconnected fleet. An operator that segments its ground network, hardens remote access, authenticates its commanding and assesses its exposure honestly is defending against the attacks that actually happen. One that trusts the spacecraft's remoteness to protect it is defending against the wrong threat.

17Professional services

This model is published so the method behind it can be examined. Applied to a specific operator, the same method produces a scored threat risk assessment: each threat rated for likelihood and impact, controls mapped to what is already in place, residual risk established and a remediation roadmap sequenced by risk reduction. That is the work Cyber Electra does for clients, in space and in every other sector where the consequences of getting risk wrong are real.

Cite this document as: Cyber Electra Inc., Threat Model for Satellite Systems Security, CE-TM-SAT-001 v1.0, 8 June 2026. Authored by T. Published in the open under the terms on this site.

18References

  • [1]ECSS, Space Engineering: Security in Space Systems Lifecycle, ECSS-E-ST-80C, 1 July 2024.
  • [2]Scholl, M. and Suloway, T., Introduction to Cybersecurity for Commercial Satellite Operations, NIST IR 8270, 2023.
  • [3]Lightman, S. et al., Satellite Ground Segment: Applying the Cybersecurity Framework to Satellite Command and Control, NIST IR 8401, 2022.
  • [4]The White House, Space Policy Directive-5: Cybersecurity Principles for Space Systems, 2020.
  • [5]The Aerospace Corporation, Space Attack Research and Tactic Analysis (SPARTA) matrix, 2022.
  • [6]Communications Security Establishment, IT Security Risk Management: A Lifecycle Approach, ITSG-33, 2012.
  • [7]Guerrero-Saade, J.A. and van Amerongen, M., AcidRain: A Modem Wiper Rains Down on Europe, SentinelLabs, 2022.
  • [8]Council of the EU and Five Eyes governments, attribution statements on the KA-SAT attack, 10 May 2022.
  • [9]Supporting frameworks: MITRE ATT&CK; NIST SP 800-30 Revision 1, 2012; ISO/IEC 27005:2022.

Want this rigour on your own systems?

The method behind this model is the method we run for clients. Tell us what you operate and what you need to decide.

Request an assessment