CyberWire Daily - Space's cybersecurity policy problem. [T-Minus: Space-Cyber Briefing]
Episode Date: September 13, 2026As space becomes increasingly connected and autonomous, effective cybersecurity policy is struggling to keep pace. Host Maria Varmazis and Dr. Mac McGuire sit down to discuss the limitation...s of current approaches for managing space cyber risks and what the industry is lacking. The two discuss how the space incidents have the potential to significant impact astronauts by disrupting oxygen systems, thermal regulation, and telemetry. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Yes, you can have an enterprise network that's secure and reliable and high performance.
And no, you don't need to choose the best two out of three.
With Meter, you can get the end-to-end network built from the ground up, fast to deploy, and easy to manage.
That's because Meter is software-led for easy installation, maintenance, and control for everything running on your enterprise network.
Hardware, firmware, and software all working together from the start seamlessly on a unified platform that's secure by design.
You can't protect what you don't know exists, which is why meter gives you comprehensive visibility into wired and wireless routing, switching, firewalls, DNS security, and VPNs.
You'll really know what's running on your network down to the most granular client level.
Step off the hardware box upgrade treadmill and switch to the hardware.
to meter for a predictable fee and free up your team to spend time on all the other things that
keep your business running. Try it out for yourself and book a demo online at meter.com
slash cyberwire. That's M-E-T-E-R dot com slash cyberwire.
I mean, especially with something like spacesuits, you know, where I attack, let's call it in
cyber or in via a network. It doesn't, it's not simply.
just hand-waving data packets that, you know, to some people won't mean anything, but it's
someone's oxygen supply, right? It's someone's telemetry. It's someone's thermal regulation.
It's not, you know, it's not just numbers and values you're dealing with lives at that point.
Welcome. I'm Maria Vermazes, and you're listening to T-minus-based cyber briefing.
In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure
that powers, protects, and connects our lives.
Hi there, thanks for joining me.
In today's episode, we're going to take a look at space cybersecurity
within the bigger picture framing of risk management in space missions.
And to guide us through that, I'm speaking with Dr. Mack McGuire.
She's a researcher with a background in industrial energy processes,
chemistry, and astronomical engineering.
She recently successfully defended her dissertation, congratulations,
part of which covers extending spacesuit longevity by quantifying failure points.
Physical failure points in those suits rely on mostly unchanged decades-old technology, for
example. And now, no big surprise, those spacesuits are increasingly wired for connectivity.
So yes, cybersecurity concerns are also possible physical risks to humans in space exploration.
So how are we assessing those kinds of risks in what you might call?
an extraordinary edge case of a space suit.
How do you build in safety measures
and what kinds of regulations are or aren't in place?
What's still needed?
How much is or isn't cybersecurity even a part
of this entire conversation?
Well, Dr. McGuire will walk us through it.
My background spans a number of things,
including industrial energy processes,
alongside chemistry, astronomical engineering,
and that's the spacesuit work that was the focus of my dissertation that you're referencing.
And I'm currently doing some work with the Space Generation Advisory Council and their space law and policy groups.
Turns out those critical infrastructure risks look very similar, whether you're talking about refineries, spacesuits, or satellites.
So my dissertation focused on space suits and essentially just increasing their longevity.
A lot of those suits have been in use to some degree.
for,
there are about 40 years.
So that technology has,
you know,
there have been some updates,
but that technology
has remained largely the same
across that entire time.
So it was timely,
let's say,
with the recent Artemis missions
and things like that,
focusing on, like I said,
space suit longevity
and kind of extending
those capabilities that we have,
whether that was cooling line leaks,
glove abrasions,
clogged, ventilation ducts, things like that,
especially on the lunar surface with that lunar regolith that everyone loves.
Oh, yes.
Yes.
But, you know, kind of my own research on those long-duration,
lunar infrastructure and kind of expanding that,
you know, it runs into that question of,
we don't have a settled answer for things that,
who is responsible for things that happen when it's so far away.
You know, like whenever a space asset gets hacked, for example,
another cyber focus, you know, we don't have a clear answer
as to what entity is responsible for that at this point.
The policy still catching up, let's say.
Yeah, and that really is kind of what I was hoping we can dig into a little bit today
on the policy side.
If you can maybe give me a sense of the lay of the land of what does that look like right now
when we're talking about cyber risk, especially for space assets.
Like, you mentioned that there are gaps.
What's there right now and maybe we can get into the gaps after?
Sure.
Well, there's a couple of different policies and frameworks treaties.
They're in place right now.
There's the Outer Space Treaty, which I think everyone that lists is probably familiar
with in some way, shape, or form.
But it doesn't have any provisions for cyber, you know, like Article 6.
states that make states internationally responsible for space activities of their own companies.
And then Article 7 says, you know, it makes states liable for damage that their space objects
caused. But neither of those anticipated an attack that arrives over networks rather than a physical
object, right? That wasn't what that was written in mind.
Yeah, it became official in 1967, if I remember the year correctly.
So it was quite a time ago.
Yes.
So it is very foundational, let's say.
Maybe that's the kind way to froze it.
Very foundational documents.
You know, and then we have space policy directive 5 that was established in 2020.
And that was the first, you know, U.S. cybersecurity policy, specifically for space systems.
But it's principles level guidance.
It doesn't have any binding regulation, right?
doesn't have any teeth to actually, like, enforce things.
It's just guidelines.
It's more guidelines than the actual rules.
That's kind of where that fits in.
And then we have a couple of other, you know, things that kind of govern in the space.
The NIST IR 827 document, which was established for 2023.
You know, that translates the NIST cybersecurity framework into space-specific terms.
but again, it's voluntary, right?
A quote from the abstract, you know, quote,
it is meant to present basic concepts,
generate discussions, and provide sample references,
in a quote.
So not regulatory.
Yeah, I'm noticing a trend there
with the idea of guidelines, suggestions.
Yeah, okay.
That feels like quite a gap.
You know, I know there's understandable
push back from people who go listen, the job is hard enough as it is. I don't want regulation
making it harder. At the flip side, if there's no sense of consequences, I suppose, no teeth,
as you say, I mean, what are we doing here? Sure. Yeah. Absolutely. I mean, especially with
something like spacesuits, you know, where I attack, let's call it in cyber or in via network.
It doesn't, it's not simply just hand-waving data packets that, you know, to some people won't mean anything, but it's someone's oxygen supply, right?
It's someone's telemetry. It's someone's thermal regulation. It's not, you know, it's not just numbers and values.
You're dealing with lives at that point.
Yeah. Yeah, that's exactly it. I mean, I know a lot of times when shorthand we talk about, you know, hacking in space, a lot of the default assumption is we're talking about satellites.
Cool, yes, understandable, but I mean, that's not it.
Sure.
There are other assets, and certainly there are humans in space,
and their well-being is paramount.
And, yeah, and truly their lives are very much at risk.
And the cyber vector, so to speak, is, I feel like, underappreciated,
not with this audience, but in general.
So sort of a general frustration I've had,
and I'm sure I'm not alone in this,
is everything has been, like, suggested guidelines
and that's just not enough.
We've seen that it's not enough.
People are sort of being left out hanging to dry a little bit here.
I mean, how do we move past this and get to a place where, again, to use your phrase, we have things with teeth?
Absolutely.
I mean, I want to preface that there are some things that exist or trying to exist.
So the EU Space Act, that was pros of 2025.
That is the most significant regulatory move that we've seen yet.
that would require cybersecurity risk assessments across full life cycles of satellites mandating, you know, onboard cybersecurity for those new satellites and create, you know, like a resilience network across the union space for those member states.
But the kicker with that is it's still being negotiated to death in parliament.
So we have, you know, those lofty ideals.
I think we're kind of getting in our own way when it comes to a lot of that.
And I think in my mind, again, coming up, this as somebody who's not necessarily a cyber expert, you know, make that caveat.
But one thing kind of off the top of my head, you know, you could implement almost immediately, I won't say immediately, because we know how fast government moves.
But that would start to put things on the right track.
You know, making cybersecurity mandatory at the point of a.
contract or license, right? It's not, it can't be optional at that point. Right now, like you said,
almost everything is voluntary or a guideline. You know, we've already, we already know how to fix
this. We've seen this happen in other circumstances with the energy grid, pipelines, et cetera,
you know, drawing from other experiences that I've had. But the actual fixes physically is
writing cybersecurity required into a procurement process rather than kind of, you know,
after an incident forces that to happen.
Time for a quick break now.
When we return more with Dr. McGuire
on risk management for space applications.
We're back now.
Let's dive back in to my conversation
with Dr. Mac McGuire.
This is maybe a bit of a woo-woo question,
but what do you attribute to sort of the resistance
that there has been to getting more serious
about cybersecurity in space?
Sure.
I think there's a couple of things.
One, I think it's exactly like you said earlier.
The more perceived hurdles there are in the way, the more difficult it makes a process,
the less likely people in the sciences are to want to push and do that,
especially if it's not directly related to the cool flashing parts of science.
I'm calling out myself there as well.
Some scathing combination of the science field as a whole.
But I think it's more, I don't want to say, mundane, but it is very, you know, you have to get that done, right?
It's not maybe fun for everyone.
I'm sure there are people that find it fascinating and engaging.
But, you know, I think that is a big part of it.
It's not super flashy.
And I think because the infrastructure, like the mechanical infrastructure is growing so rapidly, the commercial space in this area is.
growing exponentially.
I think you have a lot of just simply lagging policies.
Like you simply have a lot of, oh, we didn't foresee this happening in, like you said, 1967.
Like we had no point of conceptualizing this or things getting to this point.
And so I think a lot of it is we are simply playing catch up.
And I don't want to say that it's almost like too late to play ketchup.
up at this point, but it feels like, you know, we need to really develop those frameworks
and we really need to invest in communication. That's a very big part of it, communication between
agencies, communication between government and the public and private and all of the different
sectors that are now playing in this space. And, you know, like we all want essentially the same
things, maybe getting to it in different ways. But if we want that to happen, we all need to play
nice, right? Yeah, absolutely. And I'm wondering if almost I'm asking the wrong question about,
you know, does the regulatory hammer need to come down, or is this something where maybe the
industry can lead first? And I don't know if it's relevant, but I'm just, I'm remembering that
recently there was the CMMC requirement. I'm trying, I'm hoping I'm not misremembering this,
but there was a CMMC requirement for cybersecurity
that kind of got dropped at the last minute rather recently.
And I'm just thinking, okay, that was a regulatory thing.
A lot of people were hoping was sort of help move the needle.
And I guess it was considered too burdensome.
So maybe this becomes a thing, should it,
or maybe it will become a thing,
that industry can try and lead first
before a regulation becomes a more burdensome thing.
I don't know where I'm...
Sure.
I'm just kidding.
I definitely think that if we want things to actually be implemented, we want industry, we want to make it easy for industry to say yes, right?
We want it to be easy for them to actually feasibly implement these things.
You know, policy can hand wave.
It's, you know, declare all of these things that they want.
But in reality, somebody has to go out and actually make those things happen.
It's engineers, technicians.
It's, you know, it's not just a, and so it is done.
Yeah, yeah, I know.
That happens, right?
That has to be put in place for those things that actually happen.
And I do think industry can make more clear maybe to policy creators.
Here are things that are actually feasible for industry to implement.
And maybe that's a five-year or a 10-year plan.
You know, like here's things that are a little more feasible for us to physically.
implement now. Here are things in the future that we can build towards. And I think that there also
needs to be kind of that overlap between policy and industry of policy offering incentives, you know,
or like at least saying, hey, this is, you know, if we encourage you to go in this direction and you do
and it makes everything safer and more secure, you know, like here are some benefits that can be
had by all parties involved.
And again, I don't know exactly what those would be.
I don't want to speak beyond my area of expertise there.
But I do think there are ways that industry can lead and it can be effective, right?
And then it is up to the policy people to listen and pay attention.
Not just saying, yeah, that sounds good.
But actually listen for comprehension, I guess, is a part of that.
Yes, listening and understanding. Yes, exactly, instead of just simply hearing. Yes, completely understood.
Yeah, I want to make sure that I give you the last word. I always like to make sure I give guests an opportunity to address anything before we wrap up, like anything we missed or any concluding thoughts that you have since I recognize we're coming to the end of our time.
So yeah, anything at all that you want to mention to the audience by all means.
I think essentially to end this off, you know, like I want to kind of make a mention of who these things actually affect and who is missing from the table when these decisions are being made.
You know, every framework that we kind of discussed up to this point, the, you know, EU Space Act, the NIST framework.
You know, it's built by and for incumbent space-faring states and large operators as those increase in the industry.
you know, global South nations are disproportionately exposed.
You know, they're more reliant on those aging ground station infrastructures,
and they typically have the least capacity to absorb a cyber incident,
but they have the least voices in bodies like the United Nations Committee on the Peaceful Use of Matterspace,
for example, where those rules are currently being negotiated.
You know, and I think they're doing that, you know, a system hundreds of thousands of miles away is autonomous by,
necessity and who owns the risk. Is it necessarily just a liability question? It's a design question,
right? You have to, resilient has to be engineered in from the start. There's no fallback of a
human fixing it. It's a million thousands of miles away. That's a great question. Well, I think
it's a wonderful place to leave the conversation as well. I give everyone something to really think about.
Dr. McGuire, thank you so much for joining me today and for sharing your expertise with the audience.
I greatly appreciate it. Absolutely. Thank you for having
And that is T-minus space cyber briefing brought to you by N2K CyberWire.
If you like what you heard today, you will also enjoy our newsletter, Signals in Space.
You'll get research and notes pulled together by our producer Ethan Cook and me,
along with this week's top space cyber news stories.
Subscribe by visiting thecyberwire.com slash newsletters.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead
in the rapidly changing cybersecurity landscape.
If you like this show, please share a rating and review in your podcast app.
Please also fill out the survey in the show notes or send an email to space at n2K.com.
We are proud that N2K Cyberwire is part of the daily routine of the most influential leaders and operators
in the public and private sector from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals grow, learn, and stay informed.
As the Nexus for Discovery and Connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation.
Learn how at N2K.com.
Thank you for listening to T-Min.
I am your host, Maria Vermazas.
This show is produced by Ethan Cook and Liz Stokes.
We're mixed by Elliot Peltzman and Trey Hester with original music by Elliot Peltzman.
Our executive producer is Jennifer Ibin, with Content Strategy by Myon Plout.
Peter Kilpy is our publisher.
See you next week.
