6-minute read | 875 words
Subscribe to the newsletter to receive this issue in your inbox every Sunday.
The hidden risks in space supply chains.
Host Maria Varmazis and Jen Sovada, General Manager of Public Sector at Claroty, explore how vulnerabilities within the space supply chain can impact mission assurance. They discuss how cybersecurity in space expands well beyond protecting satellites themselves and impact launch infrastructure, operational technology, suppliers, and critical manufacturing.
Subscribe and listen to the conversation now.
The weakest link in space.
This week on T-Minus: Space-Cyber Briefing: we look at the space supply chain and how the sector's manufacturing revolution is changing not only how spacecraft are built but also how they must be secured.
Does this newsletter spark questions for you? Write to us at space@n2k.com to guide how we’ll continue to explore the space supply chain in future podcast episodes and newsletter issues.
Space’s cyber-physical system.
Historically, the space sector has followed a relatively linear development process. Spacecraft were commissioned by the government, designed, built, and then launched over several years, oftentimes with software designed specifically to support that mission.
Now, that commercial market is changing.
As more private companies become involved in the space industry, there is a greater drive to lower costs, increase production, and make more interoperable software and hardware. That shift is reflected in how government agencies increasingly seek commercial technologies and reusable systems to support future missions.
Recognizing this evolution, NASA published its “Interoperability and Concepts of Operation Assessment for Space Relay Services and Partnerships.” In the technical memorandum, NASA identified three pillars for improving interoperability across future space architectures:
- Standards development to allow spacecraft and ground systems from different organizations to communicate using common technical specifications.
- Spectrum and regulatory coordination to ensure that expanding commercial and government operations can share increasingly congested radio frequencies without interference.
- Technology development to advance hardware and software capabilities to support interoperable communications and future mission architectures.
Together, these pillars create a more connected and resilient space ecosystem. But they also increase the number of organizations, suppliers, and technologies that must be trusted and secured.
NASA has also begun strengthening oversight of its supplier network. In 2024, the agency implemented Supply Chain Visibility (SCV) Reporting requirements for major contracts to improve insight into prime contractors and lower-tier suppliers. The initiative reflects a broader recognition that resilience depends not only on securing spacecraft, but also on understanding the increasingly complex web of organizations responsible for building them.
The same trends that improve collaboration and accelerate innovation also expand the attack surface. Every additional supplier, software update, firmware revision, and operational dependency introduces another opportunity for compromise.
A larger attack surface.
As the space ecosystem has expanded, so has the sector’s cybersecurity attack surface.
While attacks against satellites themselves are still important, such as with the Viasat attack in 2022, these attacks only represent one piece of a much larger threat landscape.
Software supply chains represent one vulnerability area where frequent updates and integrated software create significant concerns. Whether it be through introduced errors during development, compromised code, or insider threats, these represent areas that could affect systems long before a spacecraft reaches orbit.
Firmware presents another challenge. Many operational technology devices used through manufacturing plants, launch facilities, and ground stations rely on embedded systems that are often both difficult to update and remain in use for years. Securing these systems requires a different approach than traditional enterprise IT because many of these systems cannot be taken offline for routine maintenance or replacement.
These risks extend beyond individual components. For example, a compromise impacting industrial control systems or programmable logic controllers could disrupt manufacturing, altering mission operations, or degrading communications.
The challenge is that these systems cannot be viewed independently. Satellites, launch infrastructure, manufacturing facilities, ground stations, industrial control systems, and suppliers form a single ecosystem, meaning a vulnerability in one area can have cascading effects across the entire sector.
As the commercial space continues to grow, cybersecurity cannot be treated solely as an IT function or a procurement requirement. Mission assurance increasingly depends on securing the entire ecosystem, from manufacturing plants and suppliers to launch infrastructure, ground systems, software, and the spacecraft themselves. As the next generation of space operations begins, supply chain resilience will prove to be just as important as developing and launching new technologies.
This week’s space-cyber headlines.
The news stories we’re reading and thinking about this week.
USSPACECOM Issues Space Warfighting Environment 2040 for Joint Force Space Operations.
- US Space Command has published its Space Warfighting Environment 2040 document that lays out the trends and conditions that are expected to be seen in space and beyond.
- The document urges the US to increase contested space training and lists China, Russia, Iran, and North Korea as key disruptors.
- Listen to Maria’s coverage on the CyberWire Daily.
July 28, 2026 | Source: Executive Gov
US Space Cybersecurity: 'No One Is in Charge'
- The US lacks a single leader for space cybersecurity leaving responsibilities fragmented across agencies including the Department of Defense, Federal Communications Committee, and others.
- The industry is calling for stronger governance as threats grow to provide stronger leadership, better public-private coordination, and a unified approach to securing space systems.
July 27, 2026 | Source: Gov Info Security