Securing cislunar space—the vast region between Earth and the Moon—presents cybersecurity challenges that far exceed those in low Earth orbit, demanding autonomous defenses, hardened infrastructure, and universal standards from the outset.
The Limits of Terrestrial Cyber Defenses in Deep Space
Traditional cybersecurity strategies, such as centrally managed anomaly detection, routine patching, and hardware replacement, are often impractical or cost-prohibitive in orbit. In cislunar space, these limitations intensify dramatically. Unlike LEO constellations, which refresh hardware every few years, cislunar infrastructure must remain functional for at least 10 to 15 years.
Radio wave latency compounds the problem. A round trip to the Moon takes nearly three seconds; to Mars, between six and 44 minutes. “When we send a command to drive the rover on Mars, we send high level software commands, and they go to a computer on board the rover, and that computer then interprets them,” explains Sam Visner, chairman of the Space Information Sharing and Analysis Center. Autonomy is not optional—it is indispensable.
Attack Surfaces Multiply in a Software-Defined Environment
Cislunar operations are inherently IT-intensive and software-defined. Sensors, telemetry, and commands all flow through software layers. “Every aspect of operations in that environment is going to be IT intensive,” Visner notes. But software-defined everything means every component becomes a potential attack surface.
This complexity is compounded by the sprawling stakeholder ecosystem of NASA’s Artemis program, which involves more than 60 nations and numerous private partners. “Cyber on Earth is already the Wild West. It is hard to hold bad actors accountable, every country has its own set of standards and regulations,” says Matthew Lamanna, a former U.S. Air Force cyber analyst. He argues that universal cybersecurity standards must be established upfront. “The rules need to be set up front, so everyone is meeting the same standards from the beginning, because you cannot do what we tend to do, and try to bolt it on after the fact. That is a recipe for failure.”
Critical Infrastructure, Unforgiving Consequences
In space, everything is critical infrastructure, and failure carries existential stakes. “Down here, if there is a cyberattack and you lose power or water for a day or so, it is bad, but it is survivable. On the Moon: How long can you go without air?” Lamanna warns. A 2024 Government Accountability Office audit found that a cyber attack on a NASA spacecraft could result in loss of mission data, reduced system lifespan, or loss of vehicle control. Auditors noted that while NASA has issued cybersecurity guidance, it has not made it mandatory for programs or embedded it in acquisition contracts.
Latency as a Shield, Power as the Ultimate Challenge
Paradoxically, cislunar distances may offer a defensive advantage. Christopher Stott, CEO of Lonestar Data Holdings, argues that long transmission delays render brute force and password spray attacks infeasible because TCP/IP connections break down. “High latency equals high security,” Stott says. NASA has developed Delay/Disruption Tolerant Networking to address these communications constraints.
Yet the most pressing challenge for a sustained lunar presence remains power. NASA and the Department of Energy are planning a lunar nuclear reactor by 2030. Volta Space Technologies offers an alternative: satellites in lunar orbit that collect solar energy and beam it to surface receivers called LightPorts. The first LightPort is slated for the Moon’s far side this year, aboard Firefly Aerospace’s Blue Ghost Mission 2 lander.
As humanity pushes deeper into cislunar space, the cybersecurity architecture must be as resilient as the life-support systems it protects—built from the start, not bolted on after.
– Originally reported by Satellite Today / Via Satellite. Adapted and republished with editorial context for SpaceSecurityNews.