The fragility of our space infrastructure

Space infrastructure is becoming increasingly important for the functioning of society. From Global Navigation Satellite Systems (GNSS) — supporting transportation, agriculture, logistics and finance, and on which around 10 % of the EU economy depends[1]— to telecommunications, Earth observation and monitoring and different military uses. The rising demand for space infrastructure is revealed by the steep increase in the global number of objects launched into space, mainly driven by the US, and by Starlink in particular, from 221 in 2016 to 2895 in 2023[2].

The European Union has long been almost completely dependent on the United States in this sector, but it is slowly constructing its own infrastructure with projects such as GALILEO, IRIS2 and GOVSATCOM. Nevertheless, expanding the space fleet is not enough to guarantee independence and resilience, as it also increases the number of targets, and presumably vulnerabilities, for hostile actors.

Space is vulnerable

Recent incidents have shown that attacks on a space service can result in cascade effects, and seriously disrupt the functioning of civil and military services. A space infrastructure is complex and vulnerable in each segment – in space, on the ground, for users and human resources. Attackers can, for example, hijack a satellite, jam or spoof or intercept its signal, seize control of the ground control system through computer network exploitation, insert malicious components during manufacturing or physically destroy the satellite[3]. Attacks can be launched at any stage of the satellite’s lifecycle, which highlights the importance of rigorous practices in all sectors and segments.

The Viasat KA-SAT incident is emblematic. In February 2022, Russian actors first launched a denial‑of‑service attack against modems used by Ukrainian authorities, then exploited a misconfigured VPN appliance to deploy wiper malware that erased the devices’ hard drives, disconnecting them from the KA-SAT network and rendering them inoperable. Although the satellite itself was not hit, the episode underlines the threats present in every segment of the network[4]. Likewise, several times it has become evident how jamming navigation satellites is a prime objective for military and sabotage operations. For example, the flightradar24 platform provides an interesting map with the current interferences of the GNSS signal and it is evident how important this practice is in disputed territories and during conflicts.

Direct attacks on satellites are also possible. Security exercises have demonstrated that an adversary can commandeer on‑orbit assets [5], while many countries are currently experimenting with anti-satellite weapons (ASAT)[6] to physically take them down.

Policy measures

Mitigation measures range from stronger encryption and anti‑jamming techniques to information‑sharing frameworks, “security‑by‑design/default” standards and tighter supply‑chain supervision [7]. However, what matters is the knowledge that no system is completely secure and that humans still represent a key weakness in every IT system. Therefore, a skilled workforce is essential, especially as the threat landscape evolves.  Thus, the European Union Agency for Cybersecurity (ENISA) has published a repository complete with many resources in the context of its Space Threats report.

The European Commission has recently stepped up its space-sector cybersecurity approach with a series of dedicated measures and communications centred around the EU Space Strategy for Security and Defence, adopted in 2023. The most important piece of legislation is currently the NIS2 Directive (2022), which classifies space as a critical sector and imposes common cybersecurity rules, particularly on supply‑chain security. A specific Space Act is also expected for late 2025, underlining the importance that the topic is gaining in the political landscape.

Nevertheless, while some discussion on the topic exists, it is confined to a few technical circles. A fundamental step that must now be taken is to make European citizens aware of how fragile the infrastructure which they critically depend on is.

[1] According to the European Commission. https://defence-industry-space.ec.europa.eu/eu-space/galileo-satellite-navigation_en

[2] United Nations Office for Outer Space Affairs (2025) – with major processing by Our World in Data, https://ourworldindata.org/grapher/yearly-number-of-objects-launched-into-outer-space

[3] For more and detailed information about space threats: ENISA Space Threat Landscape 2025 https://www.enisa.europa.eu/publications/enisa-space-threat-landscape-2025

[4] For a complete report on the attack: https://www.espi.or.at/wp-content/uploads/2022/10/ESPI-Short-1-Final-Report.pdf

[5] https://therecord.media/space-cybersecurity-satellite-hacked-esa-thales

[6] The Indian ASAT test is iconic. https://carnegieendowment.org/research/2019/04/indias-asat-test-an-incomplete-success?lang=en  and https://www.space.com/india-anti-satellite-test-significance.html

[7] As suggested by ENISA https://www.enisa.europa.eu/news/from-cyber-to-outer-space-a-guide-to-securing-commercial-satellite-operations

Related posts

Latest posts

Publication Announcement – Making the EU’s 2028-2034 Multiannual Financial Framework Work for Southern Europe

PromethEUs | 09/12/2025 The PromethEUs network of think tanks, consisting of IPP Institute of Public Policy – Lisbon (Portugal), I-Com the Institute for Competitiveness (Italy), Elcano Royal Institute...