The Democratization of Space Expands the Attack Surface

▶ Watch (1:35)

The space industry shifted from nation-state control to commercial operators. Launch costs dropped below $100,000 for CubeSats. Over 11,000 commercial satellites now orbit. Companies like SpaceX and Rocket Labs increased launch cadence. Technology got cheaper. The barrier to entry dropped so low that YouTubers like Mark Rober launched CubeSats. More players mean a larger attack surface. The speaker noted that 90% of CubeSats launched in 2017 never turned on. Space is hard. Security in space is harder.

Ground, Comms, and Onboard: The Three Attack Vectors

▶ Watch (6:53)

The ground segment includes TT&C systems, mission software, and tracking control. This is where most vulnerabilities exist. Communication links cover uplinks, downlinks, and crosslinks between satellites. Constellations like Starlink route IP packets across nodes, expanding the attack surface. Onboard systems include firmware, buses, and sensors. Patching is rare because a failed patch can end the mission. The speaker compared space to ICS/OT on steroids.

Why Patching a Satellite Is Almost Never Done

▶ Watch (8:40)

Satellites cannot be touched after integration into the rocket. On orbit, a failed patch means losing the satellite. Operators choose to leave vulnerabilities unpatched rather than risk the mission. The speaker gave an example of a contractual obligation to maintain a Windows 95 system. The decision always favors mission operations over security. The cost of failure is hundreds of millions to billions of dollars.

First Commercial On-Orbit Red Team Exercise (June 2025)

▶ Watch (12:04)

In June 2025, Sixgen, Capella Space, and CT Cubed conducted the first known commercial on-orbit red team exercise. The satellite was degrading and had only six days before loss of contact. The team lost three orbital passes because the atmosphere heated up and the satellite arrived five minutes late. The exercise was only possible because the satellite was at end of mission. This highlights the extreme difficulty of on-orbit testing.

Adapting Red Team Methodology for Space

▶ Watch (20:21)

Red teaming space systems requires objective-based testing focused on mission-critical aspects. Time constraints are severe: a 10-minute window every four hours. Simulations using digital twins, RF test chambers, and NASA’s NOS3 are essential. Analysts must understand CCSDS and custom protocols. Legal constraints require licensing and coordination with satellite operators. Planning takes months, not weeks.

Defend Before Orbit

▶ Watch (23:35)

The new space race brings speed and risk. Most organizations lack space red teamers. The speaker urged the audience to skill up and test like an attacker before launch. Defending before orbit is easier than patching after. Responsible disclosure and ethical testing are critical. The goal is to make it easier for the next generation of space red teamers.

Notable Quotes

90% of cubats that launch never turned on. Tim Fowler · ▶ 4:07

I don’t care what you designed it to do. I care what I can make it do. Tim Fowler · ▶ 7:32

The first time this is it is 2025. We’ve been in flying in space since 1958 as a country and this is the first time we’re doing it. Tim Fowler · ▶ 12:30

If we patch it and it’s unsuccessful, we lose the satellite. End of mission. Tim Fowler · ▶ 14:17

We’re never patching. Tim Fowler · ▶ 14:30

Key Takeaways

  • Space red teaming requires understanding orbital mechanics and limited communication windows.
  • Patching a satellite on orbit is rarely done due to risk of total loss.
  • The first commercial on-orbit red team exercise occurred in June 2025.