The European Space Agency is embedding cybersecurity into the core of its technology development pipeline, launching a coordinated effort under its General Support Technology Programme to address escalating threats to space infrastructure across the full mission lifecycle. As satellites increasingly rely on commercial hardware, shared software platforms, and remote reconfiguration capabilities, the attack surface for space systems now mirrors that of terrestrial critical infrastructure—requiring a strategic, rather than niche, security posture.
GSTP Cybersecurity Roadmap and Industry Collaboration
ESA’s General Support Technology Programme has published the (Cyber)Security Products for Space Systems Protection 2026-2028 document, identifying priority cybersecurity products for accelerated development. This compendium complements the broader GSTP Compendia for Cybersecurity and marks the first time the Agency has formally catalogued both standard upgrades and emerging technologies that the space industry currently lacks but will require in the near term.
A dedicated industry workshop, scheduled for 7 May 2026 at ESTEC, will build on prior work to identify market gaps and establish security priorities. The event aims to form consortia on the spot, matching companies with relevant hardware, software, facilities, or innovative ideas to fast-track product development. “Together with GSTP we have been compiling a security reference architecture constituted by cybersecurity building blocks,” said Antonios Atlasis, Head of ESA’s System Security section. “Our vision is these building blocks will be developed as products by our industry, eventually making them available off-the-shelf for future missions.”
Addressing the Three Most Significant Cyber Threats
The workshop will concentrate on three critical threat vectors: protection of communication links, intrusion detection, and general protection and recovery methods. Quantum computing poses one of the most profound risks, as mature quantum systems could compromise encryption techniques currently safeguarding critical space infrastructure and communications. Simultaneously, the growing need for secure remote software updates—essential for long-duration and flexible missions—introduces new vulnerabilities if not properly protected.
Secure software patching, long standard in terrestrial IT, is a relatively new requirement for space systems. The challenge intensifies in large satellite constellations, where a single vulnerability can replicate across hundreds or thousands of spacecraft. “As satellites increasingly run off-the-shelf components, including software and operating systems, the challenge becomes ensuring that multiple applications—often developed by different organisations—do not introduce a security risk to each other or to the wider system,” Atlasis noted. ESA and GSTP are also focusing on cartographic devices to protect against communication leaks.
Delivering Concrete Cybersecurity Solutions
GSTP is already translating its cybersecurity framework into deployable technologies through targeted development activities matured in under 18 months. A project with OHB Germany is exploring navigation satellites built around highly flexible, reprogrammable computer chips that remain secure throughout their lifetime, using post-quantum cryptography to protect against future quantum attacks. Another activity, TANDI (Trust and Isolation for Applications in Satellites) with Airbus, demonstrates layered security techniques adapted for space to isolate applications, verify integrity remotely, and prevent cascading mission failures from a single software fault or cyberattack.
The ARCA SATLINK Encryptor, led by CYSEC, provides a ready-to-use encryption library for space, managing both data link encryption and secure cryptographic key handling over a satellite’s operational lifetime. These initiatives demonstrate how GSTP is moving cybersecurity from reference architecture to practical, standards-based products for European missions.
What This Means for the Industry
ESA’s structured approach through GSTP signals a fundamental shift: cybersecurity is no longer an afterthought in satellite design but a core procurement and development requirement. By standardising building blocks and accelerating commercial off-the-shelf security products, the Agency is creating a repeatable model that reduces cost and scheduling risk for future missions. For the commercial space industry, this means that security compliance and competitive advantage will increasingly converge—and that the window to integrate robust, quantum-resistant protections is closing fast.
— Originally reported by European Space Agency. Adapted and republished with editorial context for SpaceSecurityNews.