01Executive summary
Satellites are now embedded in the daily operation of communications, navigation, banking, aviation, agriculture, weather forecasting, emergency response and national defence. A single compromised spacecraft, or far more commonly a single compromised ground system, can ripple outward into terrestrial critical infrastructure that has nothing obvious to do with space. That coupling is what makes satellite cybersecurity a strategic problem rather than a niche engineering concern.
This model describes the satellite ecosystem as five interacting parts, the space segment, the link segment, the ground segment, the user segment and the supply chain, all governed by an eight-phase mission lifecycle that runs from design to decommissioning. It enumerates the threats that apply to each part, maps them with STRIDE, positions the relevant threat actors, traces a representative end-to-end attack path, and recommends a layered target-state architecture. The analysis is grounded in published guidance from both sides of the Atlantic, including ECSS-E-ST-80C (ECSS 2024), NIST IR 8270 (Scholl and Suloway 2023), NIST IR 8401 (Lightman et al. 2022), Space Policy Directive-5 (The White House 2020), the Aerospace Corporation SPARTA matrix (2022) and Canada's ITSG-33 (CSE 2012).
Headline findings
1. The ground segment is the dominant real-world attack surface. The most consequential space-related cyberattack to date, the February 2022 Viasat KA-SAT incident, never touched a satellite. It began with a misconfigured VPN appliance on the ground and ended with wiper malware bricking tens of thousands of modems across Europe. Threat models that fixate on the spacecraft miss where attackers actually operate.
2. Standards have matured quickly, but adoption is uneven. Between 2020 and 2024 the field gained SPD-5, three NIST satellite profiles, the SPARTA matrix and a dedicated European lifecycle security standard. The guidance is strong. The gap is consistent implementation across a fleet of long-lived, hard-to-patch assets and a deep multinational supply chain.
3. The risk is systemic, not contained to the operator. Because space assets are woven into terrestrial infrastructure, the consequences of a compromise are borne well beyond the operator that was breached. Satellite risk is a societal risk, and it should be scored on that basis.
02Scope and method
This is a reference document, not an assessment of any specific operator. It describes what can be attacked, who would attempt it and what reduces the risk, using the same structured method we apply to client systems. Threats are identified per segment, categorised with STRIDE and mapped to real adversary behaviour through MITRE ATT&CK and the space-specific SPARTA matrix. Where a full assessment would then score each threat for likelihood and impact against a named operator, this model names and defines the threats so the reasoning can be read and challenged.
03The five segments
A satellite system is not one thing to defend. It is five, and the boundaries between them are where risk concentrates.
- Space segment. The spacecraft, its bus and payload, and the flight software that runs them.
- Link segment. The radio-frequency paths that carry commands up and telemetry and data down.
- Ground segment. The mission control centre, ground stations and the networks that operate the constellation.
- User segment. The terminals and modems through which people and systems use the service.
- Supply chain. The manufacturers, integrators and software sources behind every other segment.
Most operators invest heavily in the space segment, because it is the hardest to reach and the most expensive to lose. The KA-SAT attack, examined below, never touched the spacecraft. It went through the ground segment and landed on the user segment, which is exactly where defensive attention tends to be thinnest.
04The mission lifecycle
Security is not a phase, it is a property that has to be carried through eight of them. Design, development, integration and test, launch, commissioning, operations, extension and decommissioning each introduce their own exposure, and a decision taken early, a cryptographic choice or a trust boundary, is often locked in for the fifteen or twenty years the asset flies. The European standard and US policy now both make the same point: security designed in across the lifecycle is the only kind that holds, because most of these assets cannot be meaningfully patched once they are in orbit.
05Threat actors
Capability and intent vary widely, and defensive priority follows them. The classes below are ordered roughly by the capability they bring.
| Class | Profile |
|---|---|
| Nation-state military and intelligence | Highest capability and intent, able to combine cyber access with counterspace means and to abuse legitimate operational tooling once inside. The 2022 KA-SAT attack sits here. |
| State-aligned proxies | Groups operating with state tolerance or direction, often reusing military-grade tooling against softer targets in the ground and user segments. |
| Organised cybercriminals | Financially motivated, most credible against the IT of the ground segment through ransomware and extortion rather than against the spacecraft. |
| Hacktivists | Motivated by disruption and publicity, typically targeting exposed ground infrastructure and public services. |
| Insiders | Operators, engineers and contractors with legitimate access. Little sophistication is required when access is already held. |
| Industrial espionage | Competitors and their proxies seeking mission data, payload configuration or intellectual property rather than disruption. |
| Security researchers | Non-malicious, but their findings define what is publicly possible and shorten the path for others. |
| Opportunistic actors | Low-skill actors exploiting exposed ground IT, misconfiguration and default credentials without a space-specific goal. |
06STRIDE in orbit
STRIDE gives the model its structure. Each category has a specific meaning once it is applied to a space system rather than an office network.
| Category | Manifestation in a satellite system |
|---|---|
| Spoofing | Unauthorised commanding of the spacecraft, forged telemetry, or a rogue terminal presenting as a trusted one. |
| Tampering | Modification of flight software, payload data in transit, or modem firmware on the ground and user edge. |
| Repudiation | Commands or configuration changes that cannot be attributed because the operations network does not log to an evidentiary standard. |
| Information disclosure | Interception of unencrypted telemetry or mission data, or exposure of operational data held in the ground segment. |
| Denial of service | Uplink and downlink jamming, on-board resource exhaustion, or a wiper that removes the user segment from service. |
| Elevation of privilege | Movement from an exposed ground network into the trusted management segment, then to commands only privileged operators should hold. |
07Threat catalogue
The twenty-four threats below are grouped by the segment they act on, with the supply-chain and lifecycle threats that cut across all of them at the end. In a full assessment each would carry a likelihood and impact score against a specific operator. Here they are named and defined so the model can be read and challenged.
Space segment
| T-01 | Command link spoofing Commands the spacecraft accepts as authentic, absent strong command authentication. |
| T-02 | Flight software tampering Unauthorised modification of on-board software, in flight or through the update path. |
| T-03 | Payload data manipulation Alteration of sensor or mission data so what reaches the ground is no longer trustworthy. |
| T-04 | On-board resource exhaustion Deliberate consumption of power, memory or processing to degrade functions. |
| T-05 | Unsafe command sequence Legitimate commands sequenced to place the vehicle in a hazardous or unrecoverable state. |
| T-06 | Flight-software supply chain implant Malicious logic introduced before launch through a compromised component or build. |
Link segment
| T-07 | Uplink jamming Denial of the command path, cutting the operator off from the vehicle. |
| T-08 | Downlink jamming Denial of the telemetry and data path, blinding the operator to vehicle state. |
| T-09 | Meaconing and replay Capture and re-transmission of legitimate signals to confuse or mislead. |
| T-10 | Telemetry eavesdropping Interception of unencrypted telemetry, exposing state and operational patterns. |
| T-11 | Signal spoofing Injection of counterfeit signals, including position and timing services others depend on. |
| T-12 | Protocol exploitation Abuse of weaknesses in space-link protocols not designed for a hostile network. |
Ground segment
| T-13 | Ground network intrusion Initial access to the ground or management network, often via a misconfigured remote-access appliance. |
| T-14 | Lateral movement to operations Movement from a general network into the trusted segment that operates the constellation. |
| T-15 | Abuse of management tooling Use of legitimate operational tools and commands to cause harm, evading malware-only controls. |
| T-16 | Privileged credential theft Capture of operator credentials, granting access that needs no exploit once held. |
| T-17 | Destructive payload on ground assets Wiper or ransomware deployed to ground systems or the devices they manage. |
| T-18 | Operations-centre insider misuse Deliberate or negligent misuse of access by staff or contractors. |
User segment
| T-19 | Terminal firmware wipe Remote destruction of modem or terminal firmware, removing populations of users from service. |
| T-20 | Terminal compromise for pivot A compromised terminal used as a foothold or as part of a botnet. |
| T-21 | User-edge interception Interception of data at the user terminal, where protection is weakest. |
| T-22 | Rogue terminal An unauthorised terminal obtaining access to the network. |
Supply chain and lifecycle
| T-23 | Manufacturing and integration compromise Weakness introduced during build, integration or the broader supply chain. |
| T-24 | End-of-life exposure Weaknesses introduced or left unaddressed during decommissioning and disposal. |
08Attack path: KA-SAT, 2022
On 24 February 2022, the day of the Russian invasion of Ukraine, an attack on the KA-SAT network disabled tens of thousands of satellite broadband modems across Ukraine and Europe. It is the clearest public demonstration of the point this model makes, so it is worth following step by step.
Initial access
A misconfigured VPN appliance on the KA-SAT ground network, operated on Viasat's behalf by the Skylogic subsidiary, allowed remote access to the trusted management segment.
Lateral movement
The attacker moved through the trusted management network to the specific segment used to operate the network, without touching the spacecraft.
Abuse of legitimate tooling
From that position the attacker issued legitimate, targeted management commands to a large number of residential modems, so no exploit against the modems was required.
Destructive impact
The AcidRain wiper overwrote key data in the flash memory of tens of thousands of SurfBeam2 modems, rendering them inoperable and requiring reflashing or replacement.
Spillover
Downstream effects included the loss of remote monitoring and control of roughly 5,800 Enercon wind turbines in Germany, alongside disruption to thousands of customers across Europe.
Attribution
On 10 May 2022 the European Union and the Five Eyes governments publicly attributed the attack to the Russian military intelligence service.
The satellites were never the target. The path ran through a remote-access weakness in the ground segment, then used the operator's own management tools to reach the user segment. A satellite operator's resilience depends on the hygiene of the network that commands it.
09Alignment to SPARTA
The Aerospace Corporation's Space Attack Research and Tactic Analysis matrix is the first publicly available threat framework built specifically for spacecraft. It follows the same tactics-and-techniques structure as MITRE ATT&CK, which makes it a natural partner to this model. Where ATT&CK describes how the ground segment is compromised in enterprise terms, SPARTA describes what can then be attempted against the spacecraft itself. Reading the two together closes the gap between a ground-network intrusion and its consequence in orbit, which is precisely the gap the KA-SAT attack exploited.
10Defence in depth
No single control secures a satellite system. The measures below work because they overlap, so a failure in one is caught by another.
- Segment the ground network. Separate general IT from the trusted operations segment, so access to one is not access to the other.
- Harden remote access. Treat every remote-access appliance as a primary target. Enforce strong authentication, restrict exposure and monitor it closely.
- Authenticate commanding. Require strong authentication on the command path so a spoofed command is rejected rather than executed.
- Encrypt the link. Protect telemetry and mission data in transit so interception yields nothing usable.
- Log to an evidentiary standard. Record operational actions so any command or change can be attributed and challenged afterwards.
- Watch for legitimate-but-hostile action. Detection cannot rely on malware signatures alone when the adversary uses the operator's own tools.
- Secure the supply chain. Assess components and build pipelines before launch, when a defect can still be corrected without a mission call.
11Residual risk
The point of the exercise is the distance between two numbers. A representative ground-segment intrusion enters the register with a high inherent score, because its likelihood is real and its impact reaches terrestrial infrastructure. The controls above move it, but they do not erase it, and the residual position is what an operator has to decide whether to accept.
Likelihood → · I inherent, R residual, illustrative
Scored across a full operator, the residual view becomes a heat map that ranks where remaining exposure sits. It is the ranking, not the individual cell, that tells a programme where its next dollar belongs.
12Target-state architecture
A defensible satellite system separates its operations network from everything else, authenticates and encrypts its links, and logs its commanding to a standard that survives scrutiny. Remote access into the operations segment is minimised, hardened and watched. Command authority is held narrowly and every use of it is attributable. None of this makes an attack impossible. It makes the path longer, louder and more likely to be caught before it reaches impact, and it means that when a question is asked afterwards, the answer is in the logs rather than in a reconstruction.
13Emerging concerns
Proliferated constellations and automation
Constellations of thousands of satellites, operated through heavily automated ground systems, change the shape of the problem. Automation that helps operators also helps attackers scale, and a single flaw in a common ground platform now has thousands of vehicles behind it.
On-orbit servicing and software-defined payloads
Rendezvous, proximity operations and in-orbit reconfiguration create new command paths and new trust relationships between vehicles. Each is a fresh boundary that must be authenticated and monitored.
AI-scaled offence and the quantum transition
The combination of AI-scaled offence and an approaching quantum transition will stress current practices faster than they are being adopted, particularly for assets whose cryptography was fixed a decade before either arrived.
14Standards landscape
The guidance an operator can build on has matured quickly. Each of the following contributes something distinct, and none is sufficient alone.
| Standard | Source | Contribution |
|---|---|---|
| ECSS-E-ST-80C | ECSS, 2024 | The European standard for security across the full space-system lifecycle, designing security in rather than bolting it on. |
| NIST IR 8270 | Scholl and Suloway, 2023 | An introduction to cybersecurity for commercial satellite operations, framing the problem for operators. |
| NIST IR 8401 | Lightman et al., 2022 | Applies the Cybersecurity Framework to the satellite ground segment, where most real attacks land. |
| SPD-5 | The White House, 2020 | US policy setting cybersecurity principles for space systems, strong on principle but voluntary in force. |
| SPARTA | Aerospace Corporation, 2022 | A space-specific tactics-and-techniques matrix, the ATT&CK analogue for spacecraft and link. |
| ITSG-33 | CSE, 2012 | Canada's lifecycle approach to IT security risk management, the control and risk backbone we build on. |
15Are current practices sufficient?
The honest answer is partly. The frameworks now exist and are good. Whether they are sufficient depends on whether they are implemented consistently across an industry with very uneven maturity, and on whether they keep pace with how attackers actually operate.
Strengths
- A coherent body of guidance now spans both continents. SPD-5, the NIST satellite profiles, SPARTA and ECSS-E-ST-80C give operators a clear, current baseline that did not exist five years ago.
- The principle of designing security in across the full lifecycle, rather than bolting it on, is now explicit in both the European standard and US policy.
- Space-specific tooling such as SPARTA closes the gap that generic IT frameworks left around the spacecraft and link.
Weaknesses and gaps
- Most published guidance is voluntary. SPD-5 sets principles but contains no enforcement mechanism, and adoption across commercial operators is inconsistent.
- The ground segment, repeatedly the decisive target, is still often secured to ordinary enterprise standards rather than to the standard its consequences demand.
- Long asset lifetimes lock in cryptographic and architectural decisions that age badly, and many fielded assets cannot be patched at all.
- Supply-chain assurance remains immature relative to the depth and internationalism of the space supply chain.
Projection
The Viasat incident demonstrated that a state-level actor can produce continent-scale disruption through the ground segment alone, and the conditions that enabled it, exposed remote access and abuse of trusted command paths, are common. The most likely future is not an exotic in-orbit hack but more of what already works: ground intrusions, supply-chain compromise and denial of service, executed at greater scale.
Bottom line
Current practices are sufficient to defend a well-resourced, well-run programme that actually implements them. They are not yet sufficient across an industry where implementation is optional and uneven, and the gap sits mainly in the ground segment and the supply chain rather than in orbit.
16Conclusions
Satellite security is decided on the ground far more often than in space. The standards to do it well now exist, and the task is implementation across a long-lived, deeply interconnected fleet. An operator that segments its ground network, hardens remote access, authenticates its commanding and assesses its exposure honestly is defending against the attacks that actually happen. One that trusts the spacecraft's remoteness to protect it is defending against the wrong threat.
17Professional services
This model is published so the method behind it can be examined. Applied to a specific operator, the same method produces a scored threat risk assessment: each threat rated for likelihood and impact, controls mapped to what is already in place, residual risk established and a remediation roadmap sequenced by risk reduction. That is the work Cyber Electra does for clients, in space and in every other sector where the consequences of getting risk wrong are real.
Cite this document as: Cyber Electra Inc., Threat Model for Satellite Systems Security, CE-TM-SAT-001 v1.0, 8 June 2026. Authored by T. Published in the open under the terms on this site.
18References
- [1]ECSS, Space Engineering: Security in Space Systems Lifecycle, ECSS-E-ST-80C, 1 July 2024.
- [2]Scholl, M. and Suloway, T., Introduction to Cybersecurity for Commercial Satellite Operations, NIST IR 8270, 2023.
- [3]Lightman, S. et al., Satellite Ground Segment: Applying the Cybersecurity Framework to Satellite Command and Control, NIST IR 8401, 2022.
- [4]The White House, Space Policy Directive-5: Cybersecurity Principles for Space Systems, 2020.
- [5]The Aerospace Corporation, Space Attack Research and Tactic Analysis (SPARTA) matrix, 2022.
- [6]Communications Security Establishment, IT Security Risk Management: A Lifecycle Approach, ITSG-33, 2012.
- [7]Guerrero-Saade, J.A. and van Amerongen, M., AcidRain: A Modem Wiper Rains Down on Europe, SentinelLabs, 2022.
- [8]Council of the EU and Five Eyes governments, attribution statements on the KA-SAT attack, 10 May 2022.
- [9]Supporting frameworks: MITRE ATT&CK; NIST SP 800-30 Revision 1, 2012; ISO/IEC 27005:2022.