CyberWire Daily - Defending Space as Critical Infrastructure. [T-Minus: Space-Cyber Briefing]

Episode Date: September 20, 2026

Space infrastructure has become an increasingly important part of everyday life, which has also made it an increasingly attractive target for exploitation. Host Maria Varmazis and Sean MacKirdy, Are...a Vice President for the National Security vertical at Elastic Government Solutions, sit down to discuss how space stakeholders need to reevaluate their approach to securing space systems. As space systems continue to grow more important, malicious actors are going to look to target them more often. By adopting a stronger universal framework and a consistent way to interpret data across all spacecraft, space cybersecurity practitioners will be able to standardize their practices and create more effective and timely responses. Key Sources: SPARTA v4.0 Maria Varmazis interviews Brandon Bailey about Space Attack Research and Tactic Analysis, or SPARTA matrix. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: ⁠⁠⁠⁠⁠⁠⁠https://thecyberwire.com/newsletters/signals-and-space⁠⁠⁠⁠⁠⁠⁠ Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to ⁠⁠⁠⁠⁠⁠⁠space@n2k.com⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠. You can also fill our our audience survey: ⁠⁠⁠⁠⁠⁠⁠https://www.surveymonkey.com/r/NJYCN2P ⁠⁠⁠⁠⁠⁠⁠ T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. ⁠⁠⁠⁠⁠⁠⁠N2K⁠⁠⁠⁠⁠⁠⁠ is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at ⁠⁠⁠⁠⁠⁠⁠n2k.com⁠⁠⁠⁠⁠⁠⁠.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. So what happens when an AI agent isn't malicious, but still does something it shouldn't? I recently sat down with Cal Al-Dubabe, principal technologist at Rubrik, to talk about why agentic AI is challenging the way security teams think about detection, permissions, and recovery. If your organization is deploying AI agents, this conversation will help you think differently about where the risks are and how to prepare when things go wrong. Listen to our full conversation at explore. thecyberwire.com slash rubric. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call, but Dopple sees through the disguise. Their AI-native platform detects and disrupts attacks across every channel, trains employees to
Starting point is 00:01:05 recognize deep fakes and deception and investigates every fish to take down the campaign behind it. They fight relentlessly to protect your business, brand, and people. Dopple, outpacing what's next in social engineering. Learn more at doppel.com. That's do p-p-e-l.com. One of the various ways an adversary can compromise a spacecraft so that as a defender, one can start to look at the inventory of assets one has and the technologies that are deployed
Starting point is 00:01:48 and start to map those various compromises against your inventory. And where I think we've got a real opportunity as a holistic cybersecurity industry supporting the space function and the space domain as a whole, whether it's commercial or it's federal, is to take those legacy devices
Starting point is 00:02:07 and start to map the way they communicate into human-readable messages that can then in turn be mapped to the Sparta framework. Welcome. I'm Maria Vermazes, and you're listening to T-minus Space Cyber Briefing. In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. Hi, everyone. Welcome. It is perhaps hard to believe if you're a frequent listener to this show,
Starting point is 00:03:02 but even with all of our modern infrastructure's reliance on position navigation, and timing systems like GPS, space is still not technically classified as critical infrastructure by the U.S. federal government. Yeah, it's wild, right? And that is where we'll start my conversation today with Sean McCurdy, who is the area vice president for national security at Elastic Government Solutions. He says that when it comes to keeping space secure, it can help to frame space as an operational technology ecosystem, one that is analogous to terrestrial critical infrastructure, and he breaks it down into four segments, not two, all of which have their own distinct cybersecurity considerations and maintenance timelines. Let's learn more.
Starting point is 00:03:54 My name's Sean McCurdy. I'm the area vice president for our national security vertical at Elastic Government Solutions, which is a subsidiary of Elastic. I've been in the IT industry a little over 30 years and started on the software development side, first in the web 1.0 era, doing web development and front-in user interfaces, then in high-performance computing, then moved over into the side of being a technology consultant and spent about 17 years with Cisco systems before venturing off into the cyber world about 10 years ago. So today, we're going to be chatting about somehow a controversial opinion, or fact, truly about space being critical infrastructure, which I almost can't believe that even that's considered
Starting point is 00:04:37 somewhat controversial. I don't even understand why it is, but in some cases it is. But walk me through to you why space is so critical. Let's start there. Space is critical infrastructure. Why is it critical? I couldn't agree more with that comment, Maria. Space is critical infrastructure because every day we use space-based technologies pretty much without thinking about them in the modern world, right? We use GPS so that we can tell where we took that picture of our kids on the phone app, right, when we start scrolling through photos and we post it on a map. We use it every day when we navigate to where we're going because different maps providers, whether it's Apple Maps or Google Maps, pick your map provider, gosh, they've integrated so nicely with GPS that we can get from point A to
Starting point is 00:05:24 point B way more efficiently than we ever could before, right? And so we take for granted these space-based technologies. And, you know, when we look at the kinds of connected environments that we see today, whether it's, you know, somebody camping out in the middle of the Utah desert in a beautiful national park, but with Starlink so they can keep up with world events or other things that are going on, or we look at some of the conflicts that are happening around the globe, where those new commercial satellite constellations are coming into play as a critical part of how communications are kept up and an otherwise denied degraded, intermittent, limited environment, Gosh, it's all space technology that's doing that, right?
Starting point is 00:06:05 And so the space domain, I think, very rightly back in 2019, was acknowledged by then the Department of Defense as being a true domain of conflict, right? So we've got land, sea, undersea, cyberspace. Well, guess what? Space deserved that recognition. So, you know, I think that the DOD at the time was really leaning into the thought process that space assets are critical. asset. So just go back to that GPS example. Yep. You know, gosh, jamming technologies,
Starting point is 00:06:37 dazzling technologies, spoofing technologies, our adversaries have gotten to a place where those are all quite effective. And when we don't have precision navigation and timing, right, PNT, which is what GPS falls in the family of, right? It's a constellation of satellites that are made to give us precision navigation and timing. We don't have the ability to get places or to to connect with people or to, you know, meet our loved ones where we want to meet them. So if you think just for a second about what would it be like today in 2026 if GPS were shut off for a day or a week or a month, how can one not think that is a critical infrastructure component of our daily lives? Yeah, I completely agreed.
Starting point is 00:07:22 Yeah, and there was a sort of a positioning paper from the U.S. Space Force saying that from this point on, we need to assume that space is a contested environment by default, as opposed to potentially contested. Sometimes for me, when I think about the space environment as an OT environment, it feels like the wrong path to be going down, but also the parallels are there. Can you walk me through that at all? Yeah, absolutely. So, I think the way we have to think about space, and you said it perfectly, it is an operational technology environment, right? It's an OT environment. I think the parallels we have here on Earth are maybe the easiest paradigm to start with, right? We all want our drinking water supply to be clean and reliable. We all have some kind of heating need at some point in the year, no matter where you live in the United States or elsewhere, right?
Starting point is 00:08:10 If you're listening from abroad, we all have energy needs, right, for transportation, whether you have an electric car or a traditional ice vehicle. Gosh, an internal combustion engine still relies on gasoline or diesel. Sure does. Those are all distributed by legacy industrial control systems, ICS, right? And to your point, those fall in the broad category that we IT or information technology people call O-T or operational technology. And no, I have heard a couple people say, oh, other technology. No, not quite. Operational technologies, right?
Starting point is 00:08:43 Yeah. O-T is an essential part of every day, right? We're talking right now across the Internet, right? the internet is a series of operational technologies as well as IT technologies, right? Information technologies. Because, you know, if the power transmission line between you and I goes down some segment in that wide area network that's connecting us, we're relying then on a diesel generator to keep that link running, right?
Starting point is 00:09:13 All of those links in the chain that provide the infrastructure that makes IT work have to be secured. And I think as a nation, we have really started to put some emphasis on critical national infrastructure and defense critical infrastructure. So CNI or CI critical infrastructure and defense critical infrastructure, DCI. As we think about space, we're now taking that same set of problems, which is technologies that maybe were invented 50 to 100 years ago that are still in use, require constant updates, but don't have the benefit of, for example, being able to put advanced malware detection. on them because they just weren't designed with that in mind in many cases, right? And when you think of the life cycle of things that are in orbit, the majority of satellites we have put on orbit as a species in the last 50 years are still up in orbit. And while some are not, some have gracefully declined and burned up or falling into the ocean
Starting point is 00:10:09 or falling in a cornfield somewhere, most of that stuff, to use a technical term, that's on orbit, is still on orbit, right? So when one thinks about designing for space, you know, the whole ecosystem thinks in a different timeline. And I think that's been one of the traps that we've fallen into as an industry supporting space is it takes so long to build a satellite. And there's so much involved in the beautiful thing that is launching a satellite or launching humans, right, into orbit that we neglect to think about the maintenance tale of that. that spacecraft and what's involved in that. And as you look at that OT infrastructure, you have the very obvious, right, the space segment.
Starting point is 00:10:57 So we've got the actual birds in orbit, things that are rotating around the Earth performing various functions, whether they're telecommunications or intelligence collection or other functions, right? You have the link, which is the actual communication from that spacecraft to the ground. You have the ground segment,
Starting point is 00:11:16 which is the antenna, you know, the antennas and receivers of that content. And again, traditionally, those are huge devices or maybe three-meter devices or one-meter devices. Now, you know, we've got Starlink where the miniaturization of the capability to communicate with a space-based object is just incredible in my mind, right? Yeah. But on the ground segment, we also have all of the mission control component, right? So it's not just the receiving of data. It's the attitude and altitude adjustments of the spacecraft, right?
Starting point is 00:11:46 It's the care and feeding of that device that's up in orbit. It's that mission control center, if you will, right? If you think about it, I think all of us or many of us are familiar with NASA, right? You know, you think about mission control and, you know, hey, Houston, right? Yeah, yeah. That's all a very complex infrastructure. And then you have the last link in the chain, right, which is the user, which is that last mile. It's the human that's actually benefiting from those services, right?
Starting point is 00:12:14 And again, whether that's somebody carrying a GPS receiver or it's a person that's leveraging a data connection to perform their mission for the United States or, again, one of our partner nations, over that satellite communications, right? And so when you think about those four segments, right, space, the link, ground, and the user, there is so much complexity there. And you have so many different technology life cycles that are all in play at the same time. it is again just like generating power and transmitting it or or pumping clean drinking water to your house it's a complex ecosystem that has to be protected yeah the four segments that you listed out space link ground and user i i found that very interesting because a lot of times in sort of the general space industry parlance people just say oh there's two segments ground in space but when we're talking about specifically space cyber i mean we have to pull out specifically the link and
Starting point is 00:13:13 user segments as well. I think it's noteworthy and I wanted to make sure I called it out. We're separating things out and not just going ground in space because there's so much more going on than just that, especially when we're thinking about cyber context. And you had mentioned sort of that the maintenance tale, which I thought was such a really interesting point. And I just wanted to ask, what would it look like if we were better about that maintenance tale for satellites, especially in sort of a space cyber context? What would that look like? Yeah, I think one of the most of the most. important things right now is a rationalization of the assets that are on orbit and understanding
Starting point is 00:13:49 what assets are and aren't protected against various threats in the threat landscape, right? And there are many different threats in the threat landscape, right? One of those threats is someone hijacking the internet protocol-based or TCPIP communication to and from a satellite, right? So a modern satellite might have things like a software-defined radio on it. It might have other software-defined functions. And when we say software-defined in the IT industry, really what that means is it's reprogrammable or upgradable, right? It is something that can be manipulated from the ground to function differently than it did when it launched.
Starting point is 00:14:30 That's on the most modern side. And where we've got software-defined capabilities in orbit, and you look at, again, some of the modern commercial constellations that are on orbit now in low Earth orbit that we're using. Again, I've mentioned Starlink, just as one brand name, everybody might be familiar with out in the audience. Those assets have a different threat profile or different cyber landscape than something that's been on orbit like the GPS constellation since the 1970s, 1980s, right? Those aren't reprogramable in the sense that you can do some minor software upgrades along the way. That was always intended.
Starting point is 00:15:07 But you're not going to reprogram the whole function of that bird, right? They just were never designed architecturally in terms of the way the software that's running on them works and the processors that run on them were built. They were built to be very specific about their purpose and their function. And so those have a different threat profile, right? And in some cases, they might actually have a more exposed threat profile because they aren't upgradable, right? You know, we're all familiar with getting a Windows update or a Mac OS update when something goes wrong on our computer. you know, if you think about those devices that are in orbit that aren't software defined, they don't have that luxury, right?
Starting point is 00:15:46 That OS, that operating system for that spacecraft, it's kind of hardwired, right? So if there's a vulnerability, it's up to the cyber defenders, it's up to those space cyber defenders to be very specific to figure out the mitigations that are going to keep the adversary from taking control of that craft, right? And that's just a different type of tradecraft. And I think that inventory, that rationalization of things is really important. And we'll take a quick pause now as we think about the why of that space tradecraft. And when we get back to my chat with Sean McCurdy, he will get into the how.
Starting point is 00:16:28 Be right back. We return now to my conversation with Sean McCurdy, Area Vice President for National Security at Elastic Government Solutions, all about how we classify common attacks on space architecture and map to common paths. for mitigation. And I know on your show the Sparta framework has been talked about before. Yeah, it's been a while, admittedly,
Starting point is 00:17:06 but yeah, I want to say three or four years ago, I spoke with Brandon Bailey when he had just, he and the Aerospace Corporation had sort of just launched the Sparta framework. We'll make sure to link it
Starting point is 00:17:17 in the show notes for the audience. Yeah, so just a quick highlight. For traditional cybersecurity wonks like me, many of us are familiar with the minor attack. framework, right? Which is a way to lay out, hey, is the adversary doing recon against my infrastructure? Have they exploited my infrastructure and gotten into it and have started to execute,
Starting point is 00:17:36 say, a command and control function? Or are they actively exfiltrating data from me? Right. And the MITR attack framework gives us a way to bucket the various stages of an attack so that we have a common dictionary of how things are happening in the infrastructure, how adversaries are moving, and how we detect various adversarial action. The SPARTA framework, which was developed by the Aerospace Corporation, which is a federally funded research and development center. I know that's weird, right? It's a corporation, but it's a federally research. Yeah.
Starting point is 00:18:04 They're cool, right? Aerospace does some really, really neat things. And with some support from the Department of Homeland Security, they have built out a space parallel to the Mider Attack Framework called SPARTA, the Space Attack Research and Tactics Analysis Framework. What does that really mean, right? So what the SPARTA framework is trying to do, very similar to the attack framework, work on the IT side is define the various ways an adversary at a broad and kind of philosophical
Starting point is 00:18:33 level, if you will, or theoretical level. What are the various ways an adversary can compromise a spacecraft so that as a defender, one can start to look at the inventory of assets one has and the technologies that are deployed and start to map those various compromises against your inventory, right? And where I think we've got a real opportunity as, as a holistic cybersecurity industry supporting the space function and the space domain as a whole, whether it's commercial or it's federal, is to take those legacy devices
Starting point is 00:19:07 and start to map the way they communicate into human readable messages that can then in turn be mapped to the SPARTA framework. And where I think that really has the opportunity as we move into an agentic world that all of us are starting to learn to live with, we can start to look at how an operator in the loop system where large language models and other AI
Starting point is 00:19:32 and machine learning-based tools can bring data about what's happening in the space control infrastructure into human-readable terms and provide a direct translation between potential attacks and anomalies and their potential root causes based on the SPARTA framework.
Starting point is 00:19:49 So for example, if you've got an asset that's in lower orbit and it starts, to decline, is that because of an adversarial action? Is it because a command was sent, logged or unlogged, to the spacecraft? Or did we miss a maintenance window, right? Or did somebody fire a thruster that didn't get logged? All of those things can be discerned from the data that's already being collected. If that telemetry is being normalized and brought into a single framework
Starting point is 00:20:17 where we can start to look at root cause rather than the cryptic, old school signals that that we were able to accommodate in computing systems in the 70s and 80s. Yeah, I was at the, that sort of signals intelligence, magic. Sorry, for me, it seems like it's indiscernible from magic. When I, when I've learned about it, I go, whoa, that is, that is fascinating stuff, but a bit of a barrier for a lot of people. I mean, if you want to learn, you can go for it. But, I mean, I'm just imagining when you're trying to ingest all that data in all these
Starting point is 00:20:50 different formats for lack of better terminology. I mean, all these systems also, especially the older ones, they are often called exquisite because they're pretty one-off. I would imagine this makes just reacting in a meaningful timeline very challenging for the average operator. It absolutely does. And let's not overlook the fact that when we talk about the average operator in a defensive context, for example, inside of the Department of War, we're talking about young men and women that are maybe in their 20s, right? Some of them weren't alive when some of these spacecraft were put on orbit. Oh, yeah.
Starting point is 00:21:28 So there's that other component of the knowledge base, right, of the knowledge, the institutional knowledge in these ecosystems that are looking after the space domain where, you know, bringing this normalization or, you know, a common schema for how data is transmitted, how telemetries transmitted, how we record and log the activities of a spacecraft, where that normalization actually also then has the benefit of up-leveling those operators, right? By bringing it into human readable terms and being able to apply context engineering, which is, again, a very forward-leaning term that we're starting to use across industry to say, you know, by powering an agent with a large language model and its reason,
Starting point is 00:22:18 but then also securely adding our institutional knowledge that's proprietary, right? Yeah. And whether that's strictly, you know, just industrial secrets in the commercial space or that's classified data in the military space, irrelevant, right? What we want to do is fuse our internal institutional knowledge with the power of the large language model in a private way that allows the operator to uplevel their capability to understand what's happening with the spacecraft, right? And we are on that precipice where we can take the SPARTA framework and directly map it to the signals that are coming out of the infrastructure.
Starting point is 00:22:53 It's about, you know, again, normalizing to a common schema for how we collect that telemetry, how we process that telemetry. And then providing the operator a single pane of glass, not 50 different systems to look at where that agenetic capability is providing them the inputs on what's happening in the infrastructure. It's fascinating you hear about. And honestly, it's a, the opportunity there is massive. You know, Maria, I just come back to the beginning. Space is critical infrastructure, right? We have such amazing opportunities every day in our lives because of the space domain. It's an asset we have to protect.
Starting point is 00:23:28 And I appreciate your show, providing it a venue for those of us that are in the industry and concerned about this topic to let our voice be heard. Thank you. And that's T-minus space cyber briefing brought to you by N2K Cyberwire. If you like what you heard today, you will also enjoy our newsletter, signals in space. You'll get research and notes pulled together by our producer, Ethan Cook, and me, along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com slash newsletters. As always, we would love to know what you think of our podcast. Your feedback ensures
Starting point is 00:24:09 we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like the show, please share a rating and review in your podcast app. Please also fail out the survey in the show notes or send an email to space at n2k.com. We're proud that N2K Cyberwire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at N2K.com. Thank you for listening to T-Minis.
Starting point is 00:24:52 I am your host, Maria Vermazas. The show was produced by Ethan Cook and Liz Stokes. We are mixed by Elliot Peltzman and Trey Hester with original music by Elliot Peltzman. Our executive producer is Jennifer Ibin, with Content Strategy by Myon Plout. Peter Kilphe is our publisher. See you next week.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.