6-minute read | 800 words
Subscribe to the newsletter to receive this issue in your inbox every Sunday.
Defending Space as Critical Infrastructure.
Host Maria Varmazis and Sean MacKirdy, Area Vice President for the National Security vertical at Elastic Government Solutions, discuss why space needs to be treated as a critical infrastructure sector. As space-based technologies advance, they become increasingly intertwined in the services used every day. Yet, despite the greater dependency on these technologies, cybersecurity standards need to become more commonplace to support the long-term health of the industry.
Subscribe and listen to the conversation now.
Standardizing space cybersecurity.
This week on T-Minus: Space-Cyber Briefing: we dive deeper into how stronger cybersecurity standards are necessary for the space sector and what tools are already in place that can serve as a starting point.
Does this newsletter spark questions for you? Write to us at space@n2k.com to guide how we’ll continue to explore cybersecurity standards in space in future podcast episodes and newsletter issues.
Critical infrastructure in space.
Space has become an increasingly important part of the infrastructure that supports daily life and business operations on Earth. From navigation systems, timing systems, to satellite communications, these systems have become the cornerstone of many sectors and industries delivering vital services.
As these systems have become more connected, they have also become a more valuable target for attackers to exploit. Unlike other critical systems and infrastructure, securing these targets prove to be significantly harder than those in traditional IT environments.
Like many OT environments, space infrastructure contains systems that have extremely long lifecycles. However, unlike traditional OT systems, space infrastructure, especially the ones launched decades ago, are largely physically inaccessible and often cannot have their vulnerabilities simply patched or updated.
This creates a unique challenge for space cybersecurity practitioners. Defenders need to account for both a mixture of legacy and modern technologies, each with different capabilities and threat profiles.
Modern spacecraft can include software-defined systems where older infrastructure was designed to be much more limited and purpose-specific. If a vulnerability is discovered in one of these systems, defenders cannot necessarily rely on the same update and patching processes used on systems on Earth.
The SPARTA solution.
One way to address this challenge is to improve how defenders understand and categorize attacks against spacecraft.
The Space Attack Research and Tactics Analysis (SPARTA) framework, developed by the Aerospace Corporation, provides a way for space cybersecurity practitioners to understand, detect, and counter cyber threats against spacecraft and ground systems.
The latest version of the SPARTA framework organizes these in six mission areas:
- Ground Station
- Mission Operations Center
- Launch Integration and Operations
- Ground Networking Services
- Ground Security Operations Center
- Ground Station as a Service
Alongside these categories, the framework also provides implementation tiers for various countermeasures and methodologies for establishing defense-in-depth capabilities.
By standardizing these various categories and outlining compromise techniques, the SPARTA framework echoes the values brought forward by the MITRE ATT&CK framework used in traditional cybersecurity.
For defenders, this provides a common framework for mapping potential attacks against the systems they are responsible for protecting. Rather than treating every spacecraft and ground system as an isolated environment, practitioners can use a shared framework to understand how an adversary could attempt to compromise those systems.
Establishing a common language could become increasingly important as space infrastructure continues to grow more complex, and as defenders attempt to bring together data from systems built across decades of technological development.
The next challenge will involve applying this framework to the vast amount of data generated by space systems. Many spacecraft and ground systems produce telemetry in different formats, making it more challenging for operators to quickly understand what is happening across the broader infrastructure. Normalizing this data into a common scheme that maps activity to the SPARTA framework will allow defenders to quickly identify threats or anomalies.
This week’s space-cyber headlines.
The news stories we’re reading and thinking about this week.
For the first time, the US military confirms it has deployed weapons in orbit.
- Air Force Secretary Troy Meink made the first public declaration that the US has placed “space control weapons” in orbit.
- The disclosure reflects the Space Force’s growing emphasis on preparing for conflict in orbit amid concerns about growing adversary counter space capabilities.
- Listen to Maria’s coverage of the story on the CyberWire Daily.
September 14, 2026 | Source: Ars Technica
ESA starts next phase of IRIS² evolution through Low-LEO activities.
- The European Space Agency (ESA) has signed eighteen consolidation contracts that bring together nearly eighty companies to study new secure and resilient connectivity services.
- The contracts cover associated mission concepts and aim to shape the future of the EU’s secure connectivity constellation, a program which aims to provide Europeans with resilient communication capabilities.
September 17, 2026 | Source: European Space Agency