SUNDAY, SEPTEMBER 13, 2026|No. 14918
Technology · Policy

Space Cybersecurity Policies Lag Behind Rapid Technological Advancement

Existing international and national policies for space cybersecurity are struggling to keep pace with the rapid innovation and increasing interconnectedness of space systems, creating significant vulnerabilities.

An abstract representation of interconnected satellites in orbit, symbolizing the growing complexity of space technology.
An abstract representation of interconnected satellites in orbit, symbolizing the growing complexity of space technology. · Photo by Tasha Kostyuk on Unsplash
2 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
1 countries
Related coverage

Signals and Space for 09.13.26

Summary

By the N2K CyberWire staff

6 -minute read | 900 words

Space's cybersecurity policy problem.

Host Maria Varmazis and Dr. Mac McGuire sat down to discuss how the cybersecurity policies and practices in space are being outpaced by faster innovation and expansion. Throughout the conversation, the two look at how critical systems and technologies that were never designed for significant interconnectivity are getting connected to an ever expanding space network, even if effective security measures cannot be guaranteed.

The growing space cyber risk dilemma.

This week on T-Minus: Space-Cyber Briefing: we dive deeper into current cybersecurity practices in space and how these policies are rapidly becoming obsolete as spacecraft and technologies become interconnected..

Does this newsletter spark questions for you? Write to us at space@n2k.com to guide how we’ll continue to explore space cybersecurity policies in future podcast episodes and newsletter issues.

The space policy gap.

Space infrastructure has continued to become more sophisticated and connected over the past decade. As these advancements have enabled greater connectivity and availability for space assets, they have also introduced new vulnerabilities, which have not been properly addressed creating significant risk.

Currently, several major treaties, policies, and frameworks that govern cybersecurity and risk management for space systems. These include:

  • Outer Space Treaty: Established the foundational legal framework for international space law, ratified in 1967.
  • Space Policy Directive 5: Established the first comprehensive national cybersecurity policy for US space systems and infrastructure.
  • NIST IR 8270: Provided a guide for managing cybersecurity risks in commercial satellite and space operations.
  • EU Space Act: Created a single, unified legal framework for space activities across all EU member states.

Though these various policies are important, they are not enough to handle the modern space network. For example, the Outer Space Treaty was never written with attacks being able to target assets via networks rather than through a physical pathway.

The same issue can be found in more recent policies. Both the NIST IR 8270 and the Space Policy Directive 5 provide important guidance, but do not establish any building requirements. Due to the nature

  • and in some cases, the age - of these frameworks, much of the responsibility for implementing effective cybersecurity controls is placed on organizations and operators.

The human impact.

The consequences of these policy gaps extend beyond compromised satellites or disrupted communications. While those impacts are still relevant, these increasingly interconnected systems are opening the door for a cyberattack to impact physical systems that support humans operating in space.

Gregory Falco, assistant professor of civil and systems engineering at Johns Hopkins, discussed the operating risks posed to space crews from these cyber risks. Falco emphasized the potential security of these threats, comparing the security of space systems to medical devices rather than traditional information technology:

“It’s almost akin to medical-device security or things of that nature rather than opening email.”

Falco’s paper noted how space’s attack surface has expanded due to greater interconnectivity. This dynamic means potential threats extend beyond traditional terrestrial attacks and now include space-based ransomware and attacks against safety-critical systems, such as onboard air filters. As a result, a cyberattack could have consequences that extend directly to the safety and wellbeing of crew members.

These risks also highlight why traditional cybersecurity approaches may not be sufficient for spacecraft. As Falco continued:

“We should use this opportunity to come up with new or different paradigms for how we handle security of physical systems. It’s a white space. Taking things [that] don’t work perfectly to begin with and popping them into this domain is not going to really serve anyone.”

The challenge, then, is not solely determining how to protect space systems from cyber attacks. Instead, policymakers and industry leaders need to determine how cybersecurity can be incorporated into the design of systems where cyber incidents would have the most immediate in-orbit physical consequences.

This week’s space-cyber headlines.

The news stories we’re reading and thinking about this week.

History for European spaceflight: Isar Aerospace reaches orbit and deploys payloads on second flight.

  • Isar Aerospace is the first European commercial space company to deliver satellites into orbit as a part of its “Onward and Upward” mission.
  • Spectrum vehicles 3 through 7 are already in production, and Isar expects that facility to be capable of producing up to 40 launch vehicles per year.
  • Listen to Maria’s coverage of the story on the CyberWire Daily.

September 5, 2026 | Source: Isar Aerospace

Defense a key focus for new UK $10.6B, 4-year space spending plan.

  • The UK published a new national space strategy focused on defense, security, and economic growth alongside an interagency spending plan totaling $10.6 billion through 2030
  • When announcing the strategy, the government emphasized that this is a top priority “for faster development” within satellite communications, space domain awareness, in-orbit servicing assembly and manufacturing, and access to space.

September 8, 2026 | Source: Breaking Defense

Arqit, Es’hailSat and AIEE Demonstrate Quantum-Safe Satellite Security.

  • In a joint demonstration, Arqit, Es’hailSat, and Advanced International Electronic Equipment Company (AIEE) applied quantum-safe encryption to operational satellite communications infrastructure.
  • During the effort, the companies were able to apply the encryption technology without having to replace existing equipment or disrupt ongoing operations.

September 1, 2026 | Source: Global Newswire

PAN's pipeline reviewed approximately 2 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →