
The hidden risks in space supply chains.
Jen Sovata: I actually think it is something that is lacking in the space community. I think they believe that if they're cyber secure from an IT perspective, that they'll be fine, but in reality, it's all of those little components that are truly vital.
Maria Varmazis: Welcome, I'm Maria Varmazis, and you're listening to "T-Minus Space Cyber Briefing." In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. Hi, everybody, and thanks for joining me. Today's episode is an expert look at global space supply chain risk, and we're not just talking about the hardware, but spacecraft software is an increasingly important part of this conversation, too. Jen Sovata at Claroty is my guest today, and she sees space supply chain risk as an accumulation of small vulnerabilities across tiers. That includes counterfeit or tampered parts, limited visibility into sub-tier suppliers, and software that can be altered during design development or deployment. We get into all of that in our conversation. Here it is.
Jen Sovata: Thank you so much for having me on, Maria. It is great to be here. I am Jen Sovata. I'm the General Manager of the Public Sector at Claroty, which is an operational technology cyber physical systems company, and what we do is we protect all of the physical devices that are out there. That could be your global supply chain. It could be your space-based systems, ground stations, your building management systems, IoT and the like. I'm just happy to be here.
Maria Varmazis: Thank you, Jen, so much for joining me today, and you have a very wide-ranging expertise, and there are, sort of, a million questions I wanted to pepper you with, but I'll focus, for the sake of our conversation, on something that I've been really curious about, which is sort of the state of the space supply chain and the risk present there. I'm curious what comes to mind for you when we talk about space supply chain risk.
Jen Sovata: Yeah, you know, what's interesting is that everybody thinks about the headline-grabbing adversary, but it's actually, I think, more important to talk about the accumulation of really small weaknesses across the tiers of the supply chain. That includes counterfeit parts, tampered components, dependencies between them, visibility, having lack of visibility between sub-tier suppliers, those little mom-and-pop shops that they make one screw, but that one screw is so important that you need it, and then understanding the firmware, software, and other capabilities that can get altered anywhere across the design and development deployment.
Maria Varmazis: Often when I try to broach this topic, understandably, in sort of the space realm, we tend to focus a lot on the hardware side and selfishly, I'm also getting very interested in the software and firmware side of things, mainly because I feel like it hasn't gotten as much attention. I could be wrong here because of how exquisite the systems have been, historically, one-offs per spacecraft, but my understanding is that is changing at high speed. I'm wondering about the software-level supply chain risk also, if you could talk to me a little bit more about that.
Jen Sovata: Sure. If we think about the fact that we now have companies that are pumping out hundreds of satellites a year, as opposed to one every five years, the risks have changed from a software perspective. There's always new software that's being developed. When the U.S. government used to build space systems, they developed the software and they developed the hardware, but it wasn't an iterative process. It really was something like, okay, we have one space system, we have one software package that we need to load, but now because they're continually manufacturing, they're continually updating, making them more sensitive, making them more secure, and as you continue to operate and develop and deploy software, glitches can happen. You can have a code problem, you can have a deployment problem, you can have insider threat that's actually something that you hadn't thought about before because it is so dynamic.
Maria Varmazis: I was just reading recently that the FCC is trying to open up, for example, more spectrum to direct-to-device for communicating with satellites. Something that's been talked about in the cyber realm a little bit is how direct-to-device sort of opens up a brand-new part of the threat landscape in a way that maybe hadn't been present for satellites historically. I'm wondering your thoughts on that and what, maybe, direct-to-device might be as an opportunity for risk.
Jen Sovata: Yeah, I think if we think about how things have been going just even in the Ukraine War and how satellite technology has been affected by very simple basic types of threats, jamming, for example, GPS jamming, so when we think about opening it up more broadly to a larger spectrum. As we know, the spectrum, depending on the spectrum you're in, is more or less vulnerable. As we continue to develop and change, we have to think about the threat vector differently because now that enables a larger threat vector and possibly a different threat vector than what we had originally thought. Being able to adapt to that is something that we're going to need to be able to think through and also build to.
Maria Varmazis: What are your recommendations there for that adaptation?
Jen Sovata: Yeah, I think one of the things that we need to be thinking about is not just software, but also, the hardware that goes into it. If we think about operational technology systems, we have a space segment, we have a launch segment, we have a ground segment, and you've got the payload and the bus, and you've got servos and gyros and all sorts of things that move the spacecraft. Well, if the controller gets modified through software, then you could send the spacecraft into an orbit that was not planned. From a launch segment, you have the rocket itself and the ground support and the ground systems and all of the things that control that functionality of what you're doing in space, whether it's taking images, whether it's listening to things, whether it's providing communications, and if you are able to impact the ground segment by changing some of the hardware, programmable logic controllers, and other things, you might be able to impact the space segment. Then finally, if we think about other components of the entire space system, it's really the design and the assembly and it all working as an ecosystem. Everything is interactive. It's linked and is vital to the operation of that system.
Maria Varmazis: How would you describe the maturity of that ecosystem right now, in terms of recognizing the risk that's there or maybe trying to proactively get in front of it?
Jen Sovata: I actually think it is something that is lacking in the space community. I think they believe that if they're cybersecure from an IT perspective, that they'll be fine. In reality, it's all of those little components that are truly vital. If we think about how long space ground systems have been around, besides the more modern companies like SpaceX and United Launch and other things, but the legacy systems that the U.S. government operates have legacy firmware, have legacy operational technology devices, and those devices, you can't just rip and replace because it impacts the entire ecosystem. You can't take it all down because that'll impact operations like we do with IT systems, figuring out how to work with those systems differently is important and understanding how to secure them is important.
Maria Varmazis: This feels like a good place to take a break. We'll be right back. Let's get back to my conversation with Jen Sovata at Claroty about space supply chain risk. I'm -- as you say all that, also, I'm wondering about when we think of the supply chain, it being more globalized, I don't know if actually that's necessarily a correct assertion that it is becoming more globalized. Sometimes I think it is. Sometimes I'm thinking it's much more localized. Thoughts on the global supply chain? I'm just curious. Do you agree with the assertion?
Jen Sovata: I totally agree with you, and, you know, believe it or not, the White House agrees with you. They actually released an Executive Order yesterday that's about securing America's defense supply chain and ensuring domestic acquisition of critical materials, and so this isn't just a critical minerals issue. This is a, hey, we have a reflective mirror that's only built in China. It is critical to our satellites, but the only place that develops it is China, but that's a country that we have restrictions on buying certain things from certain companies, from certain -- you know? If we think about it from that perspective, it's huge. I mean, it's -- it's a huge problem. It's bigger than people think, and it's not about entire components. It's not about buying an aircraft. It's about buying the small, little widget that we don't have everywhere.
Maria Varmazis: Right, so, I guess, how do we get to there from here? I mean, there are -- aerospace is so fascinating the more I've learned about it with these with all these really tiny suppliers that do make that one, exquisite screw for a thing and they've been doing it for decades and they're really good at it. You know, it might be just two people running that shop. I mean, how do we safely keep them in the fold but also make sure that they are doing what they need to do on the risk side of things? I mean, we don't want to be burdensome, but at the same time, the risks are present and growing, so how do we get there?
Jen Sovata: Yeah, I think we have to think about resilience in the supply chain. If we have just one mom and pop doing it, I think that's a problem. We need to be thinking about how do we make four mom-and-pops doing it. Because the scale of satellite build development and manufacturing has increased, that one mom-and-pop is no longer making one widget for one satellite a year. They can now make hundreds of widgets for the hundreds of satellites a year, so being able to create that redundancy is not as much of a problem today as it would have been previously.
Maria Varmazis: That's a great point, and I'm wondering also, are there areas of this discussion around supply chain risk in the space industry that you feel are usually under-discussed? I'm just curious if there's something that you'd really like to make sure that we discuss because I bet there is.
Jen Sovata: Yeah, I think one of the biggest things that isn't really discussed is how variable the space ecosystem really is. We think about the satellites, mostly, but as I mentioned before, it's the ground stations, it's the launch pads, it's all of the communication between the satellite and those things. Looking at it as an entire ecosystem is just as important as looking at it from did that satellite get to the orbit that it needed to get to? If we think about the recent Blue Origin explosion that happened on the launch pad --
Maria Varmazis: Yeah.
Jen Sovata: It was huge because it didn't just impact the launch of that satellite, it impacted the entire supply chain because they had to rebuild their launch pad. They have to rebuild the satellite. They have to think about, is it a structural problem? Was it a software problem? Is it a cybersecurity problem? What is the issue within that entire ecosystem that caused that explosion to happen? Yes, we have the technical reason, but is there something else behind that technical reason? Understanding how that all plays together is important.
Maria Varmazis: I'm curious also if there's something that a cyber professional who's listening to this who maybe is not in the space realm, maybe is interested in moving into it, but what would you want them to know about the space industry supply chain risks that maybe they haven't thought about?
Jen Sovata: Yeah, I think that there's a couple of things. One, defense in depth is important. We need to have more robust, resilient systems from a cybersecurity perspective. We need to have continuous monitoring, so we need to have in those manufacturing plants, a continuous monitoring of all of the arms that are building all of the components to make sure that they're doing what they need to be doing. That all of the pieces are manufactured to the precise materials that they are. We need integrity in our software, and that's not just IT software. That's also the firmware that goes into those operational technology devices, and then we need to have visibility into the supply chain so that we can understand how to continually protect and evolve the protection of that supply chain.
Maria Varmazis: Well, Jen, it has been an absolute pleasure speaking with you. You are a fount of knowledge, and I've learned a ton from you today. I want to make sure if there's any sort of concluding thoughts you want to leave our audience with, I give you that opportunity.
Jen Sovata: Sure, I would love to, and thank you for chatting with me today. It's been really fun. I think that one of the biggest things I want to bring up is that in space, we can't treat the supply chain resilience as just a procurement problem. In space, cybersecurity and supply chain integrity are really, really important, as well as mission assurance, so cybersecurity and cyberattacks can affect spacecraft, the link, the ground segment, and the risks of all of that is no longer limited to the one layer of what we talk about. Understanding, as I mentioned earlier, sort of, the ecosystem is really important as we look at space, supply chain, and our capabilities across the globe.
Maria Varmazis: Jen, thank you so much for joining me today. I really appreciate it and thank you so much for sharing your expertise with me.
Jen Sovata: Thank you.
Maria Varmazis: That's T-minus Space Cyber Briefing brought to you by N2K CyberWire. If you like what you heard today, you'll also enjoy our newsletter called Signals in Space. In it, you'll get research and notes pulled together by our producer Ethan Cook and me, along with this week's top space cyber news stories. You can subscribe by visiting thecyberwire.com/newsletters. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like our show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to space@N2K.com. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at N2K.com. Thanks again for listening to T-Minus. I am your host, Maria Varmazis. This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzman and Tré Hester, with original music by Elliot Peltzman. Our Executive Producer is Jennifer Eiben, with Content Strategy by Ma'ayan Plaut. Peter Kilpe is our Publisher. See you next week.
