The Moon is three seconds away. That’s the round-trip lag for a radio signal between Earth and lunar orbit. For a hacker, that delay is a nightmare. For a satellite defender, it’s an even bigger one.
Cybersecurity on Earth is hard enough. In space, it’s a beast. But in cislunar space—the vast region between our planet and the Moon—the playbook breaks entirely. The workarounds that keep Low-Earth Orbit constellations safe simply don’t scale to a quarter-million miles.
Latency Is the New Threat Vector
Radio waves take nearly three seconds to travel to the Moon and back. To Mars, it’s between six and 44 minutes. That’s not just an inconvenience—it rewrites the rules of cyber defense. You can’t sit at a console and steer a rover in real time. You send high-level software commands, and the onboard computer figures out the rest.
“We don’t send a radio signal which operates a hydraulics system,” explains Sam Visner, chair of the Space-ISAC. “We send high level software commands.” That makes cislunar space intensely IT-dependent. Sensors, telemetry, commands—everything flows through software. And software-defined systems are attack surfaces waiting to happen.
The good news? Latency can be a shield. Christopher Stott, CEO of Lonestar Data Holdings, points out that brute-force attacks and password spraying rely on fast, repeated logins. At lunar distances, TCP/IP connections time out. “High latency equals high security,” he says. NASA has already developed Delay/Disruption Tolerant Networking (DTN) to keep interplanetary networks alive through those gaps.
Critical Infrastructure Gets a Lot More Critical
On the Moon, there’s no backup grocery store. No backup atmosphere. Matthew Lamanna, a former Air Force cyber analyst, puts it bluntly: “Down here, if you lose power for a day, it’s survivable. On the Moon: How long can you go without air?”
Every system becomes life support. That’s not new for NASA—the agency has decades of experience building redundant, resilient hardware. But the attack surface is sprawling. More than 60 countries have signed the Artemis Accords. Private companies are piling in. Each partner brings its own security standards, its own vulnerabilities, its own insider threats.
Lamanna argues for universal cybersecurity rules baked in from day one. “You can’t do what we tend to do and try to bolt it on after the fact,” he says. “That is a recipe for failure.” A 2024 Government Accountability Office audit found NASA had issued cybersecurity guidance but hadn’t made it mandatory for programs or contracts. Some Artemis elements did include testing requirements, but the approach remains patchwork.
What This Means for the Future of Lunar Operations
Cislunar infrastructure will need to function for 10 to 15 years without hardware refresh cycles. That’s a decade-plus of software aging, unpatched vulnerabilities, and evolving threats—all at a distance where autonomy isn’t optional, it’s mandatory.
The race to the Moon is also a race to secure it. The three-second lag isn’t just a technical constraint. It’s a design constraint for an entire new class of cyber defense. And if we get it wrong, the consequences won’t be a data breach. They’ll be a life-or-death system failure, silently playing out a quarter-million miles away.
—
*Originally reported by [SatelliteToday Cyber](https://www.satellitetoday.com/cybersecurity/2026/04/07/cybersecurity-in-space-is-hard-in-cislunar-space-its-really-hard/). Adapted and republished with editorial context for SpaceSecurityNews.*