
Space's cybersecurity policy problem.
Mac Maguire: I mean, especially with something like spacesuits, you know, where a attack, let's call it, in cyber or via network, it doesn't -- it's not simply just hand-waving data packets that, you know, to some people won't mean anything, but it's someone's oxygen supply, right? Like, it's someone's telemetry. It's someone's thermal regulation. It's not -- you know, it's not just numbers and values. You're dealing with lives at that point.
Maria Varmazis: Welcome, I'm Maria Varmazis, and you're listening to "T-minus Space-Cyber Briefing." In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. [ Music ] Hi, there. Thanks for joining me. In today's episode, we're going to take a look at space cybersecurity within the bigger-picture framing of risk management in space missions, and to guide us through that, I'm speaking with Dr. Mac Maguire. She's a researcher with a background in industrial energy processes, chemistry, and astronautical engineering. She recently successfully defended her dissertation -- congratulations -- part of which covers extending spacesuit longevity by quantifying failure points. Physical failure points in those suits rely on mostly unchanged, decades-old technology, for example, and now, no big surprise, those spacesuits are increasingly wired for connectivity. So yes, cybersecurity concerns are also possible physical risks to humans in space exploration. So how are we assessing those kinds of risks in what you might call an extraordinary edge case of a spacesuit? How do you build in safety measures, and what kinds of regulations are or aren't in place? What's still needed? How much is or isn't cybersecurity even a part of this entire conversation? Well, Dr. Maguire will walk us through it.
Mac Maguire: My background spans a number of things, including industrial energy processes, alongside chemistry, astronautical engineering, and that's the spacesuit work that was the focus of my disertation that you're referencing. I'm currently doing some work with the Space Generation Advisory Council and their Space Law and Policy groups. It turns out, those critical infrastructure risks look very similar, whether you're talking about refineries, spacesuits, or satellites. So my dissertation focused on spacesuits, and essentially, just increasing their longevity. A lot of those suits have been in use, to some degree, for -- they're about 40 years. That technology has -- you know, there have been some updates, but that technology has remained largely the same across that entire time. It was timely, let's say, with the recent Artemis missions and things like that, focusing on, like I said, spacesuit longevity and, kind of, extending those capabilities that we have, whether that was cooling line leaks, glove abrasions, clogged ventilation ducts, things like that, especially on the lunar surface with that lunar regolith that everyone loves.
Maria Varmazis: Oh, yes.
Mac Maguire: Yes. You know, kind of, my own research on that long-duration lunar infrastructure and, kind of, expanding that, you know, it runs into that question of, we don't have a settled answer for things like who is responsible for things that happen when it's so far away? You know, like whenever a space asset gets hacked, for example, another cyber focus, you know, we don't have a clear answer as to what entity is responsible for that at this point. The policy is still catching up, let's say.
Maria Varmazis: Yeah, and that really is, kind of, what I was hoping we can dig into a little bit today on the policy side. If you can maybe give me a sense of the lay of the land of what does that look like right now when we're talking about cyber risk, especially for space assets? Like, you mentioned that there are gaps. What's there right now and where -- maybe we can get to the gaps after?
Mac Maguire: Sure. Well, there's a couple of different policies and frameworks, treaties, that are in place right now. There's the Outer Space Treaty, which I think everyone that listens to this podcast is probably familiar with in some way, shape, or form, but it doesn't have any provisions for cyber. You know, like Article 6, you know, states that -- makes states internationally responsible for space activities of their own companies, and then Article 7 says, you know, it makes states liable for damage that their space objects cause, but neither of those anticipated an attack that arrives over networks rather than a physical object, right? Let's say, that wasn't what that was written with in mind.
Maria Varmazis: Yeah, it was it was it became official in 1967, if I remember the year correctly.
Mac Maguire: Yeah. Yes, so it is very foundational, let's say. Maybe that's the kind of way to phrase it.
Maria Varmazis: Yeah.
Mac Maguire: Very foundational documents, you know, and then we have Space Policy Directive 5 that was established in 2020, and that was the first, you know, U.S. cybersecurity policy specifically for space systems, but it's principles of guidance. It doesn't have any binding regulation, right? It doesn't have any teeth to actually, like, enforce things. It's just guidelines. It's more guidelines than the actual rules. That's kind of where that fits in. Then we have a couple of other, you know, things that, kind of, govern the space. The NIST IR 8270 document, which was established in 2023. You know, that translates the NIST cybersecurity framework into space-specific terms, but again, it's voluntary, right? A quote from the abstract, you know, quote, "It is meant to present basic concepts, generate discussions, and provide sample references," end quote, so not regulatory.
Maria Varmazis: Yeah, I'm noticing a trend there with the idea of "guidelines," "suggestions."
Mac Maguire: Yeah.
Maria Varmazis: Yeah, okay, that feels like quite a gap. You know, I know there's understandable pushback from people who go, "Listen, the job is hard enough as it is. I don't want regulation making it harder."
Mac Maguire: Sure.
Maria Varmazis: At the flip side, if there's no sense of consequences, I suppose, or "no teeth" as you say, I mean, what are we doing here?
Mac Maguire: Sure.
Maria Varmazis: Yeah.
Mac Maguire: Absolutely. I mean, especially with something like spacesuits, you know, where a attack, let's call it, in cyber or via network, it doesn't -- it's not simply just hand-waving data packets that, you know, to some people won't mean anything, but it's someone's oxygen supply, right? Like, it's someone's telemetry. It's someone's thermal regulation. It's not, you know? It's not just numbers and values. You're dealing with lives at that point.
Maria Varmazis: Yeah, yeah, that's exactly it. I mean, I know a lot of times when, shorthand, we talk about, you know, hacking in space, a lot of the default assumption is we're talking about satellites. Cool. Yes. Understandable, but I mean, that's not it exclusively.
Mac Maguire: Sure.
Maria Varmazis: There are other assets, and certainly, there are humans in space, and their well-being is paramount.
Mac Maguire: Absolutely.
Maria Varmazis: Yeah, and truly, their lives are very much at risk, and the cyber vector is, so to speak, I feel like underappreciated, not with this audience, but in general. This is sort of a general frustration I've had, and I'm sure I'm not alone in this, is everything has been, like, "suggested guidelines," and that's just not enough. We've seen that it's not enough. People are, sort of, being left out hanging to dry a little bit here. I mean, how do we move past this and get to a place where, again, to use your phrase, "we have things with teeth?"
Mac Maguire: Absolutely. I mean, I want to preface that there are some things that exist or are trying to exist. So the EU Space Act that was proposed in 2025, that is the most significant regulatory move that we've seen yet. You know, that would require cybersecurity risk assessments across full life cycles of satellites, mandating, you know, onboard cybersecurity for those new satellites, and create, you know, like a resilience network across the union space for those member states. The kicker with that is it's still being negotiated to death in Parliament. [laughter]
Maria Varmazis: Yeah.
Mac Maguire: We have, you know, those lofty ideals, but I think we're, kind of, getting in our own way when it comes to a lot of that. I think, in my mind, again, coming at this as somebody who's not necessarily a cyber expert -- let me make that caveat -- but one thing, kind of, off the top of my head, that you could implement, almost immediately -- I won't say immediately because we know how fast government moves, but that would start to put things on the right track. You know, making cybersecurity mandatory at the point of a contract or license, right, is not -- it can't be optional at that point. Right now, like you said, almost everything is voluntary or a guideline. You know, we already know how to fix this. We've seen this happen in other circumstances with the energy grid, pipelines, et cetera, you know, drawing from other experiences that I've had, but the actual fix is physically writing the cybersecurity required into a procurement process rather than, kind of, after an incident forces that to happen.
Maria Varmazis: Time for a quick break now. When we return, more with Dr. Maguire on risk management for space applications [ Music ] We're back now. Let's dive back into my conversation with Dr. Mac Maguire. This is maybe a bit of a woo-woo question, but what do you attribute to, sort of, the resistance that there has been to getting more serious about cybersecurity in space?
Mac Maguire: Sure. I think there's a couple of things. One, I think it's exactly like you said earlier. The more perceived hurdles there are in the way, the more difficult it makes a process, the less likely people in the sciences are to want to push and do that, especially if it's not directly related to the cool, flashy parts of science. I'm calling out myself there as well. You know --
Maria Varmazis: That's fair.
Mac Maguire: -- some scathing condemnation of the science field as a whole. I think, you know, it's more -- I don't want to say, mundane, but it is very, you know, you have to get that done, right? It's not maybe fun for everyone. I'm sure there are people that find it fascinating and engaging, but, you know, I think that is a big part of it. It's not super flashy. I think because the infrastructure, the mechanical infrastructure, is growing so rapidly, the commercial space in this area is growing exponentially, I think you have a lot of, just simply, lagging policies. Like, you simply have a lot of, "Oh, we didn't foresee this happening" in, like you said, 1967. Like, we had no way of conceptualizing this or things getting to this point? And so I think a lot of it is we are simply playing catch-up. I don't want to say that it's almost, like, too late to play catch-up at this point, but it feels like, you know, we need to really develop those frameworks, and we really need to invest in communication. That's a very big part of it -- communication between agencies, communication between government and the public and private and all of the different sectors that are now playing in this space. You know, like, we all want, essentially, the same things, maybe getting to it in different ways, but if we want that to happen, we all need to play nice, right?
Maria Varmazis: Yeah, absolutely, and I'm wondering if, almost, I'm asking the wrong question about, you know, does the regulatory hammer need to come down, or is this something where maybe the industry can lead first? I don't know if it's relevant, but I'm just -- I'm remembering that recently there was the CMMC requirement. Oh, I'm trying -- I'm hoping I'm not misremembering this, but there was a -- there was a CMMC requirement for cybersecurity that, kind of, got dropped at the last minute rather recently. I'm just thinking, okay, that was a regulatory thing. A lot of people were hoping it would, sort of, help move the needle. I guess it was considered too burdensome, so maybe this becomes a thing. Should it, or maybe it will become a thing that industry can try and lead first before regulation becomes a more burdensome thing? I don't know where I'm going --
Mac Maguire: Sure, [laughter] curious to know. I definitely think that if we want things to actually be implemented, we want industry -- we want to make it easy for industry to say yes, right? We want it to be easy for them to actually feasibly implement these things. You know, policy can hand-wave. It's, you know, and declare all of these things that they want, but in reality, somebody has to go out and actually make those things happen. It's engineers, technicians. It's, you know, it's not just a -- "And so it is done."
Maria Varmazis: Yeah. Yeah, no.
Mac Maguire: That happens, right? That has to be put in place for those things to actually happen, and I do think industry can make more clear, maybe to policy creators, here are things that are actually feasible for industry to implement. Maybe that's a 5-year, a 10-year plan. You know, here's things that are a little more feasible for us to physically implement now. Here are things in the future that we can build towards, and I think that there also needs to be, kind of, overlap between policy and industry, of policy offering incentives or, like, at least saying, hey, this is, you know, if we encourage you to go in this direction and you do, and it makes everything safer and more secure, you know, here are some benefits that can be had by all parties involved. You know, and again, I don't know exactly what those would be. I don't want to speak, you know, beyond my area of expertise there, but I do think there are ways that industry can lead and it can be effective, right? Then it is up to the policy people to listen and pay attention.
Maria Varmazis: Yeah.
Mac Maguire: Not just saying, yeah, that sounds good, but, like, actually listen for comprehension, I guess, is the other part of that.
Maria Varmazis: Yes, listening and understanding, yes, exactly, instead of just simply hearing.
Mac Maguire: Yeah.
Maria Varmazis: Yes, completely understood. Yeah, I want to make sure that I give you the last word. I always like to make sure I give guests an opportunity to address anything before we wrap up, like anything we missed or any concluding thoughts that you have, since I recognize we're coming to the end of our time.
Mac Maguire: Sure.
Maria Varmazis: So, yeah, anything at all that you want to mention to the audience, by all means.
Mac Maguire: I think, essentially, to end this off, you know, like I want to, kind of, make a mention of who these things actually affect and who is missing from the table when these decisions are being made. You know, every framework that we, kind of, discussed up to this point, the EU Space Act, the NIST framework, you know, it's built by and for incumbent spacefaring states and large operators as those increase in the industry. You know, Global South nations are disproportionately exposed. You know, they're more reliant on those aging ground station infrastructures. They typically have the least capacity to absorb a cyber incident, but they have the least voices in bodies like the United Nations Committee on Peaceful Uses of Outer Space, for example, where those rules are currently being negotiated. You know, and I think they're doing that, you know, a system hundreds of thousands of miles away is autonomous by necessity, and who owns the risk? Is it necessarily just a liability question? It's a design question, right? You have to -- resilience has to be engineered in from the start. There's no fallback of a human fixing it when you're thousands of miles away.
Maria Varmazis: That's a great question. Well, I think it's a wonderful place to leave the conversation, as well, and give everyone something to really think about. Dr. Maguire, thank you so much for joining me today and for sharing your expertise with the audience. I greatly appreciate it.
Mac Maguire: Absolutely. Thank you for having me.
Maria Varmazis: And that is "T-minus Space-Cyber Briefing" brought to you by N2K Cyberwire. If you like what you heard today, you will also enjoy our newsletter, "Signals in Space." You'll get research and notes pulled together by our producer Ethan Cook and me, along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com/newsletters. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to space@n2k.com. We are proud that N2K Cyberwire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at N2K.com. Thank you for listening to "T-Minus." I am your host, Maria Varmazes. This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzman and Tré Hester, with original music by Elliot Peltzman. Our Executive Producer is Jennifer Eiben, with Content Strategy by Ma'ayan Plaut. Peter Kilpe is our Publisher. See you next week.
