Security for space systems and, more often, for the organisations that depend on them without owning anything in orbit. Timing and positioning are the dependencies most people forget they have.

What we track

Positioning and timing resilience

EU, UK and international. Guidance following sustained GNSS interference, including in the North Sea.

Ground segment security

All jurisdictions. Obligations attaching to the terrestrial half of a space system, which is where most attacks land.

Space in critical infrastructure regimes

EU, UK and US. Where space services are being brought inside existing critical infrastructure duties.

Satellite communications

All jurisdictions. Security expectations for operators and for enterprise users of satellite links.

Supply chain and export

International. Controls on space technology, and the dual-use questions attached to it.

Standards work

International. Emerging standards for space system cybersecurity and for resilience of dependent services.

Who is in scope

Operators and manufacturers, obviously. Space is listed among the highly critical sectors in NIS2, which brings ground segment operators into a general cybersecurity regime for the first time in several member states.

Dependent organisations are the larger group and the one that does not know it is here. Financial trading, energy grids, telecommunications, logistics, broadcast and emergency services all take precise time or position from satellite signals, and their resilience regulators are starting to ask about it.

Where the deadlines fall

Few fixed dates so far. The obligations arrive through NIS2 transposition where space is in scope, and through resilience regimes that ask you to demonstrate tolerance to the loss of a dependency. Guidance following interference incidents lands without a deadline and becomes the expected standard afterwards.

Where organisations get caught

Dependency nobody procured. Precise time comes into an organisation through network equipment, trading systems and industrial controllers, and it is usually undocumented because nobody bought it as a service. Sustained interference in the North Sea has turned this into a live operational question.

The obligations reach users. If your service degrades when positioning or timing degrades, your resilience regulator is interested in it. The answer that your satellite provider is responsible does not survive contact with an impact tolerance.

The ground segment is the attack surface. Antennas, teleports, control centres and the networks between them are ordinary IT and OT with an unusual consequence. They are frequently secured to a standard set before space entered a critical infrastructure regime.

Questions worth asking now

  • Where does precise time enter our environment, and what happens if it drifts?
  • Which services would degrade if positioning were unavailable for a day?
  • Do we have a holdover capability, and has anyone tested how long it lasts?
  • Is any of this in our impact tolerance analysis, or did we assume the signal is always there?
  • If we operate ground infrastructure, is it in scope under our member state’s NIS2 statute?
  • What does our satellite provider actually commit to, and what does it exclude?

Related domains

Operational resilience covers the tolerance analysis this belongs in. Telecommunications and 5G security covers the networks that deliver it. Cyber-kinetic and OT security covers the systems that consume it.

All sixteen domains and how the Radar works.