CyberWire Daily - The hidden risks in space supply chains.
Episode Date: August 2, 2026As the space ecosystem continues to expand, the sector has become increasingly filled with new suppliers, manufacturers, and operators. However, while this development has led to the introduction of n...ew technologies, it has also greatly expanded space's cyberattack surface. In this week's episode, host Maria Varmazis sits down with Jen Sovada, General Manager of Public Sector at Claroty. During the conversation, the two explore how vulnerabilities within the space supply chain can impact mission assurance. They discuss how the expanding space supply chain ecosystem has expanded the attack surface. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is supported by Black Hat USA.
If you follow the research, you know a lot of it breaks on Black Hat stages.
Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history.
Six days to learn the skills you'll need tomorrow.
August 1st to the 6th.
Use code Cyberwire for $200 off your briefings pass,
at blackhat.com.
We'll see you in Vegas.
I actually think it is something that is lacking
in the space community.
I think they believe that if they're cybersecure
from an IT perspective, that they'll be fine.
But in reality, it's all of those little components
that are truly vital.
Welcome. I'm Maria Vermazes,
and you're listening to T-minus space cyber briefing.
In this show, we examine the evolution
of cybersecurity,
in the global and orbital infrastructure
that powers, protects, and connects our lives.
Hi, everybody.
Thanks for joining me.
Today's episode is an expert look at global space supply chain risk.
And we're not just talking about the hardware,
but spacecraft software is an increasingly important part of this conversation, too.
Jen Sovada at Clarity is my guest today,
and she sees space supply chain risk
as an accumulation of small vulnerabilities across tiers that includes counterfeit or tampered parts,
limited visibility into sub-tier suppliers, and software that can be altered during design,
development, or deployment.
We get into all of that in our conversation.
Here it is.
Thank you so much for having me on, Maria.
It is great to be here.
I am Jen Savata.
I'm the general manager of the public sector at Clarity.
which is an operational technology,
cyber physical systems company.
And what we do is we protect
all of the physical devices
that are out there.
And that could be your global supply chain.
It could be your space-based systems,
ground stations,
your building management systems,
IoT and the like.
And I'm just happy to be here.
Well, thank you, Jen, so much for joining me today.
And you have a very wide-ranging expertise,
and there are sort of a million questions
I wanted to pepper you with,
but I'll focus for the sake of our conversation
on something that I've been really curious about,
which is sort of the state of the space supply chain
and the risk present there.
I'm curious what comes to mind for you
when we talk about space supply chain risk.
Yeah, you know what's interesting
is that everybody thinks about the headline grabbing adversary,
but it's actually, I think, more important
to talk about the accumulation of really small weaknesses
across the tiers of the supply chain.
That includes counterfeit parts,
tampered components, dependencies between them, visibility, having lack of visibility between
sub-tier suppliers, those little mom-and-pop shops that they make one screw, but that one screw is
so important that you need it. And then understanding the firmware, software, and other
capabilities that can get altered anywhere across the design and development and deployment.
Often when I try to broach this topic, understandably, and sort of the space realm, we tend to focus a lot on the hardware side.
And selfishly, I'm also getting very interested in that the software and firmware side of things,
mainly because I feel like it hasn't gotten as much attention.
And that may be, and that could be wrong here because of how exquisite the systems have been historically one-offs per spacecraft.
But my understanding is that is changing at high speed.
And I'm wondering about the software-level supply chain risk also,
if you could talk to me a little bit more about that.
Sure.
So if we think about the fact that we now have companies
that are pumping out hundreds of satellites a year,
as opposed to one every five years,
the risks have changed from a software perspective.
There's always new software that's being developed.
When the U.S. government used to build space systems,
they developed the software, and they developed the hardware,
but it wasn't an iterative process.
It really was something like, okay, we have one space system.
We have one software package that we need to load.
But now because they're continually manufacturing,
they're continually updating, making them more sensitive,
making them more secure.
And as you continue to operate and develop and deploy software,
glitches can happen.
You can have a code problem.
You can have a deployment problem.
You can have insider threat that's actually,
something that you hadn't thought about before because it is so dynamic.
I was just reading recently that the FCC is trying to open up, for example, more spectrum to
directed device for communicating with satellites.
And something that's been talked about in the cyber realm a little bit is how directed device
sort of opens up a brand new part of the threat landscape in a way that maybe hadn't
been present for satellites historically.
And I'm wondering, your thoughts on that and what maybe directed device might be as an
opportunity for risk. Yeah, I think if we think about how things have been going just even in the
Ukraine war and how satellite technology has been affected by very simple, basic types of threats,
jamming, for example, GPS jamming. So when we think about opening it up more broadly to
a larger spectrum, as we know, the spectrum, depending on the spectrum you're in, is more or less
vulnerable. So as we continue to develop and change, we have to think about the threat vector
differently because now that enables a larger threat vector and possibly a different threat vector
than what we had originally thought. And being able to adapt to that is something that we're
going to need to be able to think through and also build to. What are your recommendations there
for that adaptation? Yeah, I think one of the things that we need to be thinking about is not just
software, but also the hardware that goes into it. So if we think about operational technology systems,
we have a space segment, we have a launch segment, and we have a ground segment, and you've got
the payload in the bus, and you've got servos and gyros and all sorts of things that move the spacecraft.
Well, if the controller gets modified through software, then you could send the spacecraft into an orbit
that was not planned. From a launch segment, you have the rocket itself and the ground support and the
ground systems and all of the things that control that functionality of what you're doing in space,
whether it's taking images, whether it's listening to things, whether it's provided communications.
And if you are able to impact the ground segment by changing some of the hardware, programmable logic
controllers and other things, you might be able to impact the space segment. And then finally,
if we think about other components of the entire space system, it's really the design and the assembly
and it all working as an ecosystem. So everything is interactive, it's linked, and is vital to the
operation of that system. How would you describe the maturity of that ecosystem right now in terms of
recognizing the risk that's there or maybe trying to proactively get in front of it?
I actually think it is something that is lacking in the space community.
I think they believe that if they're cyber secure from an IT perspective, that they'll be fine.
But in reality, it's all of those little components that are truly vital.
And if we think about how long space ground systems have been around, besides the more modern companies like SpaceX and, you know, I've launched and other things.
But the legacy systems that the U.S. government operates have legacy.
firmware, have legacy operational technology devices. And those devices, you can't just work and replace
because it impacts the entire ecosystem. You can't take it all down because that'll impact
operations like we do with IT systems. So figuring out how to work with those systems differently
is important. And understanding how to secure them is important. This feels like a good place
to take a break. We'll be right back. Let's get back to my conversation with Jen Savada at
clarity about space supply chain risk.
I'm, as you say all that also, I'm wondering about when we think of the supply chain,
it being more globalized.
And I don't know if actually that's necessarily a correct assertion that it is becoming
more globalized.
Sometimes I think it is.
Sometimes I'm thinking it's much more localized.
Thoughts on the global supply chain.
I'm just curious, do you agree with the assertion?
I totally, I totally agree with you.
And, you know, believe it.
or not, the White House agrees with you. They actually released an executive order yesterday that's
about securing America's defense supply chain and ensuring domestic acquisition of critical
materials. And so this isn't just a critical minerals issue. This is a, hey, we have a reflective
mirror that's only built in China. It is critical to our satellite, but the only place that develops
it in China, but that's a country that we have restrictions on buying certain things from certain
companies, from certain, you know. So if we think about it from that perspective, it's huge.
I mean, it's a huge problem. It's bigger than people think. And it's not about entire components.
It's not about buying an aircraft. It's about buying the small little widget that we don't have
everywhere. Right. So I guess how do we get to there from here?
I mean, there are, aerospace is so fascinating the more I've learned about it with all these really tiny suppliers that do make that one exquisite screw for a thing and they've been doing it for decades and they're really good at it.
But, you know, it might be just two people running that shop.
I mean, how do we safely keep them in the fold but also make sure that they are doing what they need to do on the risk side of things?
I mean, we don't want to be burdensome, but at the same time, the risks are present and growing.
So how do we get there?
Yeah, I think we have to think about resilience in the supply chain.
If we have just one mom and pop doing it, I think that's a problem.
We need to be thinking about how do we make four mom and pops doing it.
Because the scale of satellite build, development and manufacturing has increased,
that one mom and pop is no longer making one widget for one satellite a year.
They can now make hundreds of widgets for the hundreds of satellites a year.
So being able to create that redundancy is not as much of a problem today as it would have been previously.
That's a great point.
And I'm wondering also, are there areas of this discussion around supply chain risk in the space industry that you feel are usually under discussed?
I'm just curious that there's something that you'd really like to make sure that we discuss because I bet there is.
I think one of the biggest things that isn't really discussed is how variable the space ecosystem really is.
We think about the satellites mostly, but as I mentioned before, it's the ground stations, it's the launch pads, it's all of the communication between the satellite and those things.
And so looking at it as an entire ecosystem is just as important as looking at it as looking at it.
from, did that satellite get to the orbit that it needed to get to?
If we think about the recent Blue Origin explosion that happened on the launch pad,
it was huge because it didn't just impact the launch of that satellite.
It impacted the entire supply chain because they had to rebuild their launch pad.
They have to rebuild the satellites.
They have to think about, is it a structural problem?
Was it a software problem?
Is it a cybersecurity problem?
What is the issue within that entire ecosystem that caused that explosion to happen?
Yes, we have the technical reason, but is there something else behind that technical reason?
So understanding how that all plays together is important.
And I'm curious also if there's something that a cyber professional who's listening to this,
who maybe is not in the space realm, maybe is interested in moving into it, but what would you want them to know?
about the space industry supply chain risk that maybe they haven't thought about?
Yeah, I think that there's a couple of things.
One, defense in depth is important.
We need to have more robust resilient systems from a cybersecurity perspective.
We need to have continuous monitoring.
So we need to have, in those manufacturing plants,
continuous monitoring of all of the robot arms that are building all of the components
to make sure that they're doing what they need to be doing
and that all of the pieces are manufactured to the precise materials that they are.
We need integrity in our software, and that's not just IT software, that's also the firmware that goes into those operational technology devices.
And then we need to have visibility into the supply chain so that we can understand how to continually protect and evolve the protection of that supply chain.
Well, Jen, it has been an absolute pleasure speaking with you.
You are a fount of knowledge, and I've learned a ton from you today.
I want to make sure if there's any sort of concluding thoughts you want to leave our audience with that I give you that opportunity.
Sure, I would love to.
And thank you for chatting with me today.
It's been really fun.
I think one of the biggest things I want to bring up is that in space, we can't treat the supply chain resilience as just a procurement problem.
In space, cybersecurity and supply chain integrity are really, really important, as well as mission assurance.
So cyber security and cyber attacks can affect spacecraft, the link, the ground segment, and the risks of all of that is no longer limited to the one layer of what we talk about.
And so understanding, as I mentioned earlier, sort of the ecosystem is really important as we look at space, supply chain, and our capabilities across the globe.
Jen, thank you so much for joining me today.
I really appreciate it, and thank you so much for sharing your expertise with me.
Thank you.
And that's T-minus space cyber briefing brought to you by N2K CyberWire.
If you like what you heard today, you'll also enjoy our newsletter called Signals and Space.
In it, you'll get research and notes pulled together by our producer Ethan Cook and me,
along with this week's top space cyber news stories.
You can subscribe by visiting thecyberwire.com slash newsletters.
We'd love to know what you think of our podcast, your feedback,
ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape.
If you like our show, please share a rating and review in your podcast app.
Please also fill out the survey in the show notes or send an email to space at n2K.com.
We're proud that N2K Cyberwire is part of the daily routine of the most influential leaders
and operators in the public and private sector, from the Fortune 500 to many of the world's
preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals grow, learn, and stay informed.
As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation.
Learn how at N2K.com.
Thanks again for listening to T-minus.
I am your host, Maria Vermazes.
This show is produced by Ethan Cook and Liz Stokes.
We're mixed by Elliot Peltzman and Trey Hester with original music by Elliot Peltzman.
Our executive producer is Jennifer Ibin, with Content Strategy by Mayon Plout.
Peter Kilby is our publisher.
See you next week.
