ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The next cyber-battleground is space: what must organisations do to prepare?

Michael Freeman at Armis examines how the rapid expansion of space-connected infrastructure is reshaping the enterprise attack surface

Linked InXFacebook
bookmark_borderSave to Library

Space: the final frontier. 

 

An iconic line that’s transcended popular culture and feels more relevant given the recent success of the Artemis II mission. But in cyber-security terms, space isn’t the final frontier; it’s the current one. Satellites, ground-to-orbit infrastructure and mission control systems are embedded within the same digital ecosystem as cloud platforms, enterprise networks and industrial operations we depend on daily.

 

Of course, most enterprises don’t build or launch satellites, and few would consider themselves part of this domain. Yet the reality is that many of the services underpinning everyday operations – from financial transactions and communications to logistics and navigation – rely heavily on space-based infrastructure. These connections are deeply embedded, but rarely considered.

 

What this means is we’re operating with a fundamentally different attack surface. Organisations are no longer confined to defined perimeters or physical environments; it’s distributed, interconnected and increasingly three-dimensional, stretching all the way up to low-Earth orbit.

 

And yet, many organisations still don’t fully realise what this means for their exposure.

 

The hidden risks in a connected orbit

The Artemis II mission marked an exciting chapter in space exploration, but it also signals something else: space is becoming more strategically important again. And with that, it becomes a target for nation-states and bad actors looking to disrupt, destabilise and deny capabilities to their foes – particularly as critical services such as low-latency connectivity, mobile back-haul and direct-to-device communication increasingly rely on satellite infrastructure.

 

A recent report from several national intelligence agencies, including the US, Australia and Canada, already warns of growing cyber-attacks on low-Earth orbit satellite systems. And when combined with incidents such as the breach at the European Space Agency (ESA), it’s clear that space infrastructure sits firmly within the scope of modern cyber-conflict. 

 

At the same time, AI is accelerating both the speed and accessibility of these attacks. Threat actors are using large language models to analyse satellite communications, interpret telemetry and identify vulnerabilities in space systems, dramatically reducing the expertise required to target them and shortening the time to exploitation. And now, a compromise in orbit no longer stays in orbit.

 

Interference with satellite-based timing signals, for example, can disrupt financial transactions and telecom networks in seconds. Disruptions to satellite communications can degrade logistics visibility or interrupt coordination between systems on the ground. What begins as a localised incident can quickly affect multiple industries and hundreds of organisations. But the risk lies in how these services are relied upon.

 

For most organisations, satellite-enabled services are treated as external services rather than part of the core environment. This creates a significant blind spot, especially when 75% of cyber-warfare threats now target unmanaged or supply chain assets that fall beyond the reach of conventional security tools. 

 

When those services are disrupted, however, the impact is immediate and systems fail. Yet, many organisations don’t have a clear view of how these systems connect, or how disruption in one layer could affect another. Without that understanding, it becomes difficult not only to detect where risk exists, but to anticipate how it might unfold. Or how to respond when it does.

 

Understanding exposure across systems

Addressing this challenge requires a shift in how organisations understand and manage risk across their environments. Resilience must reflect how infrastructure actually operates: as a chain of interdependent technologies spanning satellite networks, ground systems, deep-sea cables, communication links and enterprise platforms.

 

Organisations need to move beyond simply identifying assets to instead understanding how those assets connect across IT, OT, cloud and space-linked systems. This includes mapping every connection, identifying trust boundaries and recognising where external services introduce potential pathways for disruption. Because in this environment, risk is defined by relationships.

 

Consider a nation-state actor who’s looking to disrupt supply chains or a specific logistics company during a period of heightened tensions between two nations. Rather than targeting the logistics company directly, the attacker focuses upstream, exploiting weaknesses in satellite communication links or ground station infrastructure that support real-time tracking systems. The attacker doesn’t need to “move into” the enterprise system directly; they influence the systems the enterprise depends on instead and cast a larger net of disruption that impacts more organisations.

 

This is why understanding exposure requires more than surface-level awareness. Organisations need to understand how systems, assets and devices connect across environments – particularly where space-based services and external infrastructure feed into core operations – and where a weakness in one layer could introduce risk into another.

 

From there, the focus shifts to prioritisation because not every vulnerability carries the same level of risk. In these environments, the most critical exposures are those that create pathways between systems, particularly where external infrastructure connects into core operations. Identifying those pathways allows organisations to focus on what matters most, rather than attempting to address every issue in isolation.

 

This becomes even more important as bad actors continue to accelerate their capabilities with AI. In this context, resilience is no longer defined by how quickly an organisation can respond to an incident, but by how clearly it understands its exposure before that incident occurs.

 

A new kind of frontier

The systems that support everything from navigation to communication are not simply confined to the stars, and neither are the risks that come with them. And as space becomes more integrated into critical infrastructure and enterprise operations, organisations must treat it as an extension of their own ecosystem. The challenge, therefore, is to understand what they already rely on and how exposed they may be.

 

In this three-dimensional attack surface, security is defined by how well the connections between systems are understood, not just what’s protected in isolation. After all, this is not the final frontier imagined by Star Trek, nor the voyages of the Starship Enterprise. It’s simply the reality of modern cyber-conflict. Resilience will depend on how well organisations understand that exposure before it’s tested.

 


 

Michael Freeman is Head of Threat Intelligence at Armis from ServiceNow

 

Main image courtesy of iStockPhoto.com and Inok

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543