The shift from custom-hardened electronics to programmable components on satellites is creating security gaps that regulators and operators have only begun to address. At a Washington symposium this week, officials from multiple agencies described how off-the-shelf radio hardware, commoditized supply chains, and compressed development timelines are converging to expand the attack surface available to adversaries.
ESA security engineering manager John Irving said the spread of programmable satellite radios means anyone with a few hundred dollars in receiver gear can capture spacecraft signals and probe onboard firmware. “This is the guy in his bedroom, hacking away,” Irving said, describing how satellite targeting has become accessible beyond state-sponsored attackers.
Charles Fritz, chief of staff at the State Department’s Bureau of Emerging Threats, warned that vulnerabilities anywhere in the satellite supply chain, which weaves through dozens of nations, can ripple into broad data loss. He called for secure-by-design adoption across the sector and urged allied governments to cut adversarial components from procurement.
Space Force deputy chief of cyber operations Seth Whitworth observed that the industry’s transition from custom-built spacecraft to standardized platforms has eliminated the protection that one-of-a-kind system designs once provided. He said orbital data centers will demand security investment comparable to what cloud providers allocate for ground infrastructure.
FCC Space Bureau official Carolyn Mahoney noted that foreign regulators track the commission’s space modernization closely, though the current rulemaking targets licensing procedures rather than cybersecurity.
Fritz said offensive operations by adversary states blur the line between space and cyber domains. Russia has already proven it can disrupt satellite networks through cyber means during wartime, while China builds its space, cyber, and conventional military capabilities in parallel.