Picture a satellite hack and most people imagine a hacker somehow reaching up into orbit. That image is mostly wrong, but it’s a useful place to start because the real weak point is usually sitting in a building on the ground: a control room, a network switch, a login screen somebody forgot to lock down.
A satellite doesn’t operate alone. It’s the last link in a chain that runs from a ground station through control infrastructure, through operators, through the software they use every day. Break a link anywhere in that chain and the damage doesn’t stay put.
It helps to remember how much now runs through space, quietly, in the background. Positioning and navigation. Financial transaction timestamps. Weather forecasting. Emergency communications. Logistics networks that keep freight moving.
The US National Institute of Standards and Technology (NIST) has flagged how central commercial satellite services have become to critical infrastructure generally, not just to the aerospace sector. Once something reaches that level of dependency, treating its security as a specialty niche stops making sense. It becomes infrastructure security, full stop, the same category as power grids and water systems.
So where does an attacker actually go to work? Mostly on the ground. Ground stations handle the raw communications link. Satellite operations centers watch and steer the spacecraft.
Command systems build and send the instructions that tell a satellite what to do. Authentication systems decide who’s allowed to send those instructions in the first place, and that’s often the softest target of all. Get into the systems that issue commands, and you never have to touch the spacecraft directly.
The European Space Agency (ESA) SPACE-SHIELD framework documents this pattern directly, modeling how a compromised ground segment can become a stepping stone into the space segment itself.
Commands sent to a satellite aren’t like a normal web request, either, and that distinction carries weight. A malicious command has the potential to alter a spacecraft’s configuration, disrupt its payload, or knock out communications outright.
NIST doesn’t leave this to aerospace engineers working from separate playbooks. It has applied its Cybersecurity Framework directly to satellite ground segments, treating command and control as exactly the kind of problem cybersecurity teams already know how to think about.
What’s changed the calculus is who’s actually running these systems now. The old picture, one government owning a satellite and controlling everything around it, is mostly gone. Today’s space systems run through commercial operators, cloud platforms, third party vendors, hosted payloads, ground station providers, telecom carriers, and software suppliers, frequently stacked on top of each other.
NIST’s work on hybrid satellite networks treats this explicitly as a web of interacting organizations rather than one entity in charge of the whole stack. That’s a supply chain risk as much as a technical one, and it’s the kind of risk that tends to get discovered only after something has already gone wrong.
Then there’s the operational technology problem, which is where space really parts ways with ordinary IT. Standard security practice assumes you can patch, reboot, and move on. Spacecraft don’t offer that luxury. They run for years on constrained hardware nobody can physically reach, with software that’s difficult to update and availability requirements that leave almost no room for downtime.
Securing that kind of system isn’t just about keeping data private. It’s about keeping command authority intact, keeping the mission running, and knowing the difference between the two when something breaks.
Nobody is going to make a satellite unhackable. That’s not a realistic bar for any complex system, in space or anywhere else. What’s realistic is building for resilience: identity controls, network segmentation, authenticated commands, continuous monitoring, supply chain vetting, and a recovery plan that actually gets tested.
The next serious failure in this industry probably won’t start with a signal beamed down from orbit. It’ll start the same way most breaches do: with something ordinary, on the ground, that nobody was watching closely enough.
Image Source: AI generated with ChatGPT
