An abstract digital illustration of Earth from space enveloped in a luminous network of interconnected lines, overlaid with glowing padlock icons to represent global cybersecurity and satellite infrastructure protection.

Space is no longer a sanctuary.

Reliance on satellites for everything from missile warning to financial timing has pushed the orbital domain to the forefront of cyber operations, where adversaries look for any weakness they can weaponize.

Cyber Intrusions Shape Space Conflict

Space threats and conflict are largely in cyber operations, with adversaries favoring hidden exploits and network infiltration over kinetic attacks, Charles Beames, chairman of the SmallSat Alliance, executive chairman of SpiderOak and TrustPoint and former chairman at York Space Systems, told Constellations.

“Satellites are essentially solar-powered computers in orbit,” said Beames, who is also an investor and retired Air Force colonel.

Destroying a satellite is possible but rarely practical compared to compromising the system through its software and data links, Beames said.

“That too much effort and risk if you just want to go after an enemy’s system. It’s a network. The best way to approach it would be through some kind of Trojan-horse method – some kind of exploit, maybe a zero-day,” he said.

Assume the Breach, Secure by Design

As warfare and critical infrastructure increasingly shift into space – and threats grow rapidly in both scale and sophistication – traditional cybersecurity methods are no longer enough. Operators should no longer assume their networks are safe, Beames warned.

Operators should instead pursue the “zero trust” cybersecurity model for their systems, but what does that entail?

“Even the smartest people in this world have slightly nuanced and different definitions of exactly what “zero trust” means,” Beames said, noting that it must involve using a “secure-by-design” approach to the network infrastructure.

“What it means is that you design your cyber infrastructure – basically all your networks, your software, everything – assuming that it’s already been compromised,” —Charles Beames

“What it means is that you design your cyber infrastructure – basically all your networks, your software, everything – assuming that it’s already been compromised,” Beames said.

The task involves designing transport and security protocols that can function in an environment assumed to be compromised, Beames said. “The reason why there are people like me that are such proponents of this is because that’s the best starting position,” he said. Engineering work always begins with certain assumptions about the operating environment of a system, and design work follows from there. When the process starts with a “secure-by-design” mindset, it leads to stronger outcomes, he said.

“If you begin that way, you end up with a different type of architecture, which is one of the reasons why it’s a challenge – especially for legacy systems,” Beames said.

Legacy Systems Face Unique Challenges

Legacy systems were built in a different era, but the threat environment has evolved quickly, Beames said, likening it to a rapidly mutating organism that constantly adapts. This rapid evolution is the main reason programs such as the GPS III ground segment, called OCX, faced cancellations, cost overruns and long delays, he said. Attempts to develop and deploy that system failed because it began with a traditional cybersecurity model focused on detecting intrusions and responding to them, rather than being designed from the start to operate securely in a compromised environment, he said.

A more effective approach for the modern era begins with a clean-sheet design that assumes compromise from the outset, while still working to keep adversaries out, Beames said. Systems built this way can continue functioning even if parts of them are breached, improving overall operational resilience, he said.

An infographic contrasts traditional cybersecurity, illustrated by a dark castle with a glowing red gate, against a zero-trust model, depicted by a futuristic network of glowing blue digital identity profiles.

Although this method is becoming more common, it is challenging, Beames said. Many companies now exist to assist developers, but most solutions still need to start from scratch and use specialized tools within a software stack. Many of these tools rely on blockchain or distributed-ledger technologies to protect data, he said, adding that security increasingly needs to be implemented at the data level rather than solely at the network level.

Applying zero trust principles to legacy systems is feasible, “but only if you stop expecting the legacy system itself to do the work,” Tommy Flynn, information systems engineer and cybersecurity professional for the Naval Surface Warfare Center, told Constellations, echoing Beames.

“A lot of satellite and ground systems run on outdated protocols, unsupported hardware and operating systems that hit end-of-life years ago,” Flynn said. Traditional Zero Trust relies on modern identity systems and frequent cryptographic exchanges that legacy telecommand and serial telemetry links can’t support, said Flynn. Adding native encryption or extra authentication to those systems risks overloading their limited processors, interrupting real-time telemetry, or causing outages when latency triggers security lockouts, he said.

“Nothing gets a security initiative shelved faster than knocking a mission system offline,” he said.

While it’s more difficult to implement zero trust with legacy architectures, it is achievable, Beames said. There are firms that develop software that connects older systems with newer security tools so they can function together operationally. One example is Omni Federal, which works with many space-industry organizations and is part of the SmallSat Alliance, Beames said. Within the alliance are companies aiming to adopt zero-trust practices as well as those providing supporting tools like Virtru and SpiderOak, he said. Omni Federal serves as specialized middleware, relying on engineers who understand both legacy and modern technologies to make them operate seamlessly, he said.

“So it can be done, but it has to be a priority, frankly,” Beames said. “What has to happen is that the government has to just basically mandate it.”

The government was preparing to mandate that any contract containing CMMC provisions could require a Level 2 third-party assessment to be on file in the Supplier Performance Risk System before announcing this month that the compliance program was suspended. Even if the DoW’s CMMC program had not been suspended for review, the imminent threat to critical data would be reason enough to crack down on cybersecurity, Beames said.

“And zero-trust is a much stricter standard than normal CMMC compliance. This is like a whole other level of operational resilience. Cyber resilience,” he said.

When Awareness Fails, Breaches Force a Change in Perspective

Some companies are even pursuing secure-by-design to gain a competitive advantage. They choose to commit to a secure-by-design approach so they can be viewed more favorably by customers compared with competitors, he said.

Yet there is still some industrywide reluctance to taking a proactive approach, Beames noted.

“Cybersecurity is one of those things…having been in this business a long time … I can tell you it’s a little bit like trying to convince people to buy life insurance for a family member. No one wants to buy it until they’re dead, and then they say, ‘Oh, I wish I would’ve had life insurance,’” —Charles Beames

“Cybersecurity is one of those things…having been in this business a long time … I can tell you it’s a little bit like trying to convince people to buy life insurance for a family member. No one wants to buy it until they’re dead, and then they say, ‘Oh, I wish I would’ve had life insurance,’” he said.

In general, people can be prone to thinking of a cybersecurity breach as something abstract or theoretical unlikely to happen to them…until it does, Beames said.

“It’s sort of like once you’ve been mugged, you have a different perspective on street crime than just reading about it in the newspaper,” he explained, emphasizing how quickly perceptions change when the consequences become tangible.

CMMC Phase II May be in Limbo, but the Threat is Certain

If organizations slow security investments in the wake of eased government pressure, shared environments become more vulnerable because each software or hardware component adds another attack surface, Beames said. A single compromised user, device, application or data record can threaten the overall system unless it is secured by design, and any noncompliant participant can expose connected systems, he said.

“And that’s a very dangerous proposition,” he said.

The suspension of CMMC Phase II, along with the 60-day Reform Task Force review announced with it, has formed dangerous perception gap across the Defense Industrial Base, according to Flynn.

“A lot of small and midsize aerospace suppliers are reading the pause as a breather. Nation-state adversaries are reading it as an open window,” —Tommy Flynn

“A lot of small and midsize aerospace suppliers are reading the pause as a breather. Nation-state adversaries are reading it as an open window,” Flynn said. “The intelligence trends point the same direction: threat actors know that regulatory delays cause smaller contractors to deprioritize security spending, defer MFA upgrades and put off migrating Controlled Unclassified Information into hardened enclaves, and they act on that.”

Attackers are bypassing hardened Tier-1 primes and zeroing in on small sub-tier shops holding sensitive design and production data, Flynn said. They’re hunting for weak remote access, abusing old VPNs and pushing fake compliance-auditor lures to drop infostealers. With little to no security staff, these vendors are the easiest way into the defense supply chain, he said.

Additionally, while the certification may be paused, the legal duty to safeguard defense data hasn’t changed, Flynn noted. DFARS requirements, NIST 800-171 and CMMC Phase I self-assessments are still fully in effect, and primes are tightening their own supplier checks, Flynn said. Any small contractor that stops improving security now risks not only espionage but False Claims Act exposure if a breach shows their SPRS scores were inaccurate, he said.

Integrated Systems Increase Stakes for Cyber Breaches

For organizations of all sizes, the cybersecurity risk grows as systems become more integrated, Beames said, noting that one breach can compromise an entire network, adding “if it gets compromised somehow, then the whole thing becomes compromised.”

The impact of a breach depends on the target, but many space systems are treated as critical infrastructure, Beames said. GPS underpins navigation and financial transactions, and compromising its timing signal could disrupt markets. “It’s very, very possible you could collapse the stock market,” Beames said. Trillions of transactions rely on that timing, yet current systems lack the protections seen in more traditional military architectures like satellite communications, he said.

Commercial companies are already exploring PNT alternatives, but some simply repeat GPS signals and could rebroadcast compromised data, while some independent systems operate on land, through cellular networks or in space, he said.

Protecting Critical Infrastructure Demands a Zero-Trust Future

The potential consequences of a cyber attack on space infrastructure could be detrimental, but that doesn’t mean the signs of compromised system will be apparent, said Flynn.

“The strategic goal of space-domain cyber espionage is long-term access, not immediate disruption,” —Tommy Flynn

“The strategic goal of space-domain cyber espionage is long-term access, not immediate disruption,” Flynn said. Once inside a ground station or mission-planning system, state actors focus on mapping the satellite network and quietly pulling telemetry and design data. Using the access to send bad orbital commands or kill payload power would expose them immediately, so they sit dormant and save it for a future conflict when the payoff is worth burning the intrusion, he said.

“Obviously, that patience is exactly why so many of these intrusions go undetected for months,” Flynn said.

Dormant compromises are difficult to detect and may surface only when activated or signaled, Beames said. Some bots arrive through simple means related to human error like thumb drives, and defenders sometimes allow them to operate to study their behavior, he said.

Defending against these breaches can done quietly too.

Object-level encryption can limit what an intruder sees and allow defenders to monitor activity while protecting sensitive data, Beames said.

Managing separate keys for each data type can create orchestration challenges, but some zero-trust tools can remotely rekey systems if needed, he said.

Despite lingering skepticism, several factors could push broader adoption of the zero-trust approach, even if it requires rebuilding entire system architectures. For example, companies tend to act when shareholder value is at stake, Beames said.

Broader awareness may also help. The spread of real-world cybersecurity stories – particularly through social media – could encourage organizations to take threats more seriously, Beames said. Yet awareness alone may not be enough. Beames suggested that government intervention will eventually be necessary, similar to the introduction of seat belt laws. “There are certain things the government needs to just mandate,” he said.

Under this model, zero-trust certification could become a federal requirement, with certain systems placed into controlled environments and tested the way vehicles undergo crash tests, Beames said. Critical infrastructure – banking, energy, transportation, healthcare – would all need to meet these standards to prevent catastrophic failures – including life and death scenarios, Beames warned.

Ultimately, he expects that progress will come from one of two paths: a policymaker championing the issue or a major national-scale cyber incident forcing action. “It’s going to be one of those two paths,” he said.

Explore More:

CMMC’s November Deadline Forces New Calculations Across the Space Industrial Base

Briefing 45: Analyzing the Software Supply Chain Risk to the Space Sector

Maintaining Cybersecurity as a Service in GSaaS