NASA’s budget got a reprieve — flat-funded at $24.4 billion instead of being gutted. But for cybersecurity, flat funding isn’t a win. It’s a managed decline at a moment when space systems face more threats than ever.
The House Appropriations Committee approved a spending bill on May 13 that keeps NASA’s budget flat, rejecting the White House’s proposed 23 percent cut. Exploration — Artemis, SLS, lunar landers — gets a boost. Science takes a $1.25 billion hit. But one area that doesn’t show up in the line items is cybersecurity, and that’s the problem.
NASA operates one of the most complex and exposed space networks in the world: dozens of scientific spacecraft, deep-space communication arrays, human-rated systems on the International Space Station, and a growing web of commercial partnerships. Every new partner, every new data link, every new spacecraft adds to the attack surface. A flat budget means those surfaces get managed with the same resources as last year — while the threat landscape grows.
The Commercialization Security Gap
The bill sets aside $400 million for the Commercial Low Earth Orbit Destinations program, which aims to replace the ISS with private space stations. That’s a strategic play to seed a commercial space economy. But it also creates a complex cybersecurity challenge: NASA will need to secure data and communications across a network of commercially operated stations, each with its own security posture, its own software stack, and its own vulnerability profile.
The ISS itself has decades of hardened security procedures. Commercial replacements will start from scratch. A manager’s amendment demands regular briefings on NASA’s shifting plans, including the idea of a “core module” that commercial stations could dock to. What’s missing from that conversation is a parallel cybersecurity framework — who secures what, how threats are shared, and what happens when a commercial partner’s system is compromised.
Science Missions, Cyber Risk
The science budget cut of $1.25 billion falls hardest on Earth science, which loses nearly 40 percent. Astrophysics and heliophysics see smaller reductions. But the bill also orders NASA to keep flying missions the agency wanted to retire: Juno at Jupiter, New Horizons in the Kuiper Belt, Chandra and Fermi observatories.
Extended missions are a double-edged sword. They deliver continued science returns, but they also run on aging hardware with increasingly outdated security. Older spacecraft weren’t designed with modern cyber threats in mind. Keeping them flying means maintaining ground systems and communication links that may lack modern encryption, authentication, or intrusion detection.
Nuclear Propulsion, Digital Risk
The bill doubles down on nuclear propulsion — $110 million for nuclear thermal rockets, $50 million for nuclear electric propulsion, and $5 million for fusion research. These are long-term bets on faster deep-space travel. But they also introduce new cybersecurity requirements for systems where failure isn’t an option. A nuclear propulsion system under remote command needs security architectures that go well beyond what current deep-space missions require.
The Bigger Picture
The flat budget is a political compromise that keeps NASA alive but barely moving. For cybersecurity, that means existing vulnerabilities persist, new ones accumulate, and the gap between threat and defense widens incrementally with each passing year.
As NASA pushes deeper into commercial partnerships, lunar infrastructure, and nuclear propulsion, the security requirements grow exponentially. A flat budget can’t keep up — and in space, the cost of a breach isn’t just data loss. It’s loss of mission, loss of vehicle, and potentially loss of life.