← All news

Cybersecurity of the Space Segment under the NIS2 Framework

The NIS2 Directive, transposed into the national legal orders of EU Member States, establishes network and information systems security obligations for operators of essential sectors, which include space services with a critical function. For a satellite system, the attack surface is not limited to the space segment in orbit, but encompasses the ground control and mission segment, the uplinks and downlinks, the remote user stations, and the hardware and software supply chain for onboard equipment. This systemic view is the starting point for any security posture analysis aligned with NIS2. From a defence-in-depth perspective, the security architecture of a satellite system must be structured in independent functional layers: authentication and encryption of telecommand and telemetry links, logical segmentation between the ground segment operations networks and the corporate networks, and integrity controls over the flight software and in-orbit updates. Network segmentation between the primary control centre and the backup centres contributes to limiting the lateral propagation of a compromise and to preserving operational continuity, which NIS2 treats as an explicit resilience requirement for essential operators. The supply chain represents one of the most significant risk vectors in long-lifecycle systems such as satellite systems. Flight electronics components, payload management software, and ground processing platforms may incorporate third-party dependencies with varying levels of cybersecurity maturity. NIS2 requires operators to assess and manage the risks arising from their suppliers, which in the space context implies extending security requirements throughout the entire system lifecycle, from design through to final disposal. At the governance level, NIS2 introduces obligations to notify significant incidents to the competent authorities within defined timeframes, as well as the designation of risk management responsibilities at the directorial level of the organisation. For satellite infrastructure operators, this requires having detection and response procedures adapted to the particular characteristics of the space environment, where link latency and the autonomy of the platform in orbit condition reaction times and remote intervention capabilities. The regulatory approach of NIS2 does not prescribe specific technical controls, but rather establishes a risk management framework based on proportionality and the adoption of technical and organisational measures appropriate to the level of exposure. For operators of SATCOM systems with an essential function, this implies integrating cybersecurity as an engineering discipline from the early phases of system design, and not as an additional layer applied to an already consolidated architecture.

NASSAT - Network Satellite Systems