Cybersecurity Incident Handling in the Context of NIS2 Regulation
NIS2 Directive takes effect today in the EU. We highlight key incident handling elements, enhancing detection, reporting and response under the new regulations.
Our S.O.S. line:
+49 89 262 025954
Our team of experts is ready to assist your organization in the event of a cyberattack.
detailsCyber Threat Intelligence + Incident Response + Security Operations Center White Hat todayJuly 8, 2025

Satellites are prone to different types of anti-satellite (ASAT) attacks, such as kinetic (e.g. co-orbital ASAT), non-kinetic (e.g. high-powered microwaves), electronic or natural. Damages related to space debris and solar storms could be categorized as natural. This article focuses on electronic attacks (EW) and within those cyberattacks.
Electronic warfare proves to be a growing threat due to its ability to affect systems anywhere without the need for space capabilities, additionally, it is considered cheaper, and most importantly – unlike physical attacks – EW offers deniability due to the nature of the attack’s traceability. The lack of need for existing space capabilities to attack space objects significantly raises the number of potential threat actors to these systems. The goal of these attacks could be reconnaissance, stealing sensitive data and causing damage either physically (by deterring targets from orbit or causing collisions) or internally (by compromising the software). This type of attack usually targets global navigation systems (GNSS) and satellite communication (SATCOM) signals.
Some of the most popular types of attacks include satellite jamming and spoofing. Jamming refers to the process of disrupting and/or blocking signals by creating noise and interference. Uplink jamming refers to the disruption of a signal going from the ground station to the satellite, while downlink jamming is the blocking or interference of signals going from the satellite to the ground station. These can cause the target object to partially or completely lose signals. As an example, in case a GPS satellite is corrupted, a loss of signal could cause end-users to not have access to navigation data in applications using GPS coordinates.

Spoofing is similar to jamming; however its main objective is to deceive the satellite or the user by falsifying the received signal. It does not stop the signal itself, instead acts like the original. In case it’s not noticed, attackers can steal confidential information by listening on the conversation between the receivers. It can also cause the satellite to abandon its mission and in-orbit position.
Space situational awareness (SSA) systems need to be protected as well. SSA refers to systems which track space traffic (satellites, asteroids, space debris) in order to prevent collisions from happening. If such a system is attacked, data can be manipulated in a way that a potential collision between a space debris fragment and a satellite is not visible, due to falsifying either the satellite’s or the debris’ coordinates.
Ground stations are strongly intertwined with the link segment. These stations are responsible for communicating with the satellites. In case an attack occurs, the target satellites’ trajectories can be modified, redirected or taken offline, causing great damage to the recipient.
Companies need to look out for other types of attacks as well, such as supply chain attacks, where compromised hardware or software is used to disrupt satellite services or to gain sensitive and confidential data relating to the mission – this usually “activates” after the satellite has been launched and is in-orbit. Satellites are sensitive to software changes, in case the malicious software is not noticed, it can be difficult to update it and mitigate damage that is already done.
Damages caused by electronic and cyberattacks are generally considered reversible as opposed to physical attacks, however some actions can cause the destruction of the target satellite (such as forcing collisions by deterring the target from its original orbit). It is important to build resilience against these types of attacks by encryption of satellite systems (such as SSL/TLS, IPSec and Quantum encryption), which help prevent the loss of data privacy and help secure the control of the satellite.
Attacks targeting the C2 link (command and control) are considered difficult, but not impossible, therefore the encryption of these systems is important as well. Intrusion Detection and Prevention Systems help monitor satellite systems for any malicious activity and isolate potential threats immediately. Network and component isolation and system diversification can help stop the spread of malware and ensure the safety of the other systems.
Other types of mitigation strategies include Cyberattack resilience training, where a test-environment is created to simulate potential cyberattacks and observe the resilience of the target and supply chain risk management programs, which help in identifying, assessing and creating mitigation strategies against potential vulnerabilities.
It is important to keep in mind that both space and cybersecurity is a relatively new domain that experiences rapid technological development, therefore it is crucial for all space actors to be up to date with existing and upcoming threats in order to prevent potential attacks against their assets.
Sources:
Shadbolt, L. (2021). Satellite Cyberattacks and Security. HDI Global Specialty SE.
available at: hdis209_satellite-cyberattack_whitepaper_v8_05july21-1.pdf
Swope, Bingen, Young & LaFave. (2025) Space Threat Assessment 2025. Center for Strategic and International Studies
available at: 250425_Swope_Space_Threat.pdf
Global Counterspace Capabilities 2025 by Safe World Foundation (2025)
link: SWF_Global_Counterspace_Capabilities_2025.pdf – Google Drive
Skowyra & Ingols (2019) Guidelines for Secure Small Satellite Design and Implementation: FY18 Cyber Security Line-Supported Program. MASSACHUSETTS INSTITUTE OF TECHNOLOGY
available at: ll.mit.edu/sites/default/files/publication/doc/guidelines-secure-small-satellite-design-ingols-lsp-249.pdf
What is Quantum Encryption, How Does It Work, and Will It Save Us From Cybercriminals? (2024) Retrieved from Arcserve
available at: https://www.arcserve.com/blog/what-quantum-encryption-how-does-it-work-and-will-it-save-us-cybercriminals
Pavur, J. (2021). Securing New Space: On Satellite Cyber-Security. Wolfson College University of Oxford
available at: ora.ox.ac.uk/objects/uuid:11e1b32a-8117-46b1-a0ce-9c485221d112/files/d02870w18z
Written by: White Hat
Tagged as: cybercrime, jamming, satellite, space, spoofing.
Governance, Risk and Compliance Csaba Krasznay / October 18, 2024
NIS2 Directive takes effect today in the EU. We highlight key incident handling elements, enhancing detection, reporting and response under the new regulations.
Penetration Testing WhiteHat / August 28, 2026
This week’s CVE of the Week is CVE-2026-24301, also known as CoSnitch, an exfiltration method in Microsoft Copilot that could allow an unauthorized attacker to steal sensitive information and data. With a CVSS score of 8.8, deserves serious attention. It is a combination of three different vulnerabilities that could allow an attacker to pull data ...
Cyber Threat Intelligence WhiteHat / August 6, 2026
What is Cyber Threat Intelligence, and why does it matter? Learn the CTI lifecycle, intelligence types, and how threat intelligence helps prevent cyberattacks.