As the interconnectivity and prominence of the space domain increases, so too does the collective exposure to cyber risk facing organisations within what is a vast supply chain. A modern space mission may involve hundreds of organisations across multiple countries. Some are major primes with sophisticated cyber operations centres, while others are specialist SMEs with comparably limited cyber security resources and expertise.
This has led to the rise of a Cyber Poverty Gap between what security demands and what organisations can sustain – creating systemic risk that extends well beyond any individual company. In the current landscape, two key factors are compounding this gap at a time when maintaining cyber resilience has never been more important.
Challenge 1: The democratisation of space
Space has historically been protected, in part, by exclusivity. Very few entities could afford to build spacecraft, launch and operate them, or assemble the specialist expertise needed to interfere with them. But this is no longer the case.
Access to space has changed profoundly. A small spacecraft can now be built around trusted, widely available components, launched at a price within reach of universities, start-ups and increasingly capable hobbyist communities.
This increased accessibility is undoubtedly a good thing for the industry, but it also increases the risks in terms of resilience. Those same commodity components, familiar software stacks and accessible ground platforms make the target environment more knowable to threat actors. The same parts are bought, tested and understood by everyone – from major states to small engineering teams and a wider range of would-be hackers.
Similarly, the broader range of organisations involved in space deployments presents more routes in for attackers. They need only find one potential chink in the armour: a supplier, an operator account, a cloud-hosted tasking portal, an exposed development environment, a poorly protected cryptographic key.
And they don’t need to compromise the biggest or ‘strongest’ participants. They will look for the weakest pathway into the ecosystem, as vulnerabilities propagate across dependencies rather than remaining isolated. A such, they can target smaller organisations that are generally more likely to have cyber security gaps not through negligence, but through limitation. The democratisation of space presents more opportunities for them to do exactly that.
Challenge 2: The democratisation of vulnerability
Then we come on to vulnerability and threat. Vulnerability research used to demand rare expertise, expensive laboratories, privileged intelligence and teams of specialists. A technical flaw on its own was often not enough. Turning it into an operational effect required chaining together multiple weaknesses across ground systems, people, interfaces and spacecraft behaviour.
Today, access to capable AI-assisted analysis, inexpensive test environments and readily available components is reducing that burden. A threat actor can reproduce parts of a ground or spacecraft environment, explore how systems behave under unusual conditions, and use AI to help connect what previously looked like separate technical observations.
That does not mean a language model can simply press a button and seize control of a satellite. But it does mean that the research, correlation and planning effort which once belonged almost exclusively to the best-resourced intelligence services is becoming cheaper and more widely available.
AI also comes with a defensive dimension. Well-resourced organisations can use AI to detect, understand and respond to threats faster than ever before. Those without access to the same tools may find themselves increasingly exposed.
The cyber poverty gap
These factors are driving the cyber poverty gap in space. Launch is a capital event: a programme raises the money, builds the platform, gets it into orbit, and celebrates success. But cyber resilience is not a one-off purchase. It is an enduring operational commitment.
It means maintaining identity and key management, monitoring ground and space telemetry, testing assumptions, responding to anomalies, updating systems, and having the expertise to decide when a strange event is an engineering fault, an operator mistake, or an attack.
The best-resourced states and organisations can afford that continuing tax. They can sustain security operations, threat intelligence, specialist engineering teams and contingency capability over the life of the mission.
A smaller operator may be able to afford a capable CubeSat, a launch opportunity and a ground-service subscription, but not necessarily the long-term defensive ecosystem around it. They may be limited by legacy technology, skills shortages, limited budgets, competing priorities and increasing compliance burdens – or a combination of all.
That is where the gap opens: access to space is democratised, but access to persistent protection is not. While large primes are certainly not immune to vulnerabilities, they are simply more able to meet the level of ongoing rigour required.
Why this affects everyone
That does not only matter to the owner of the smaller platform. Space is a shared environment with highly connected space ecosystems, which means that local weaknesses become shared vulnerabilities.
A compromised or poorly controlled platform may not directly compromise a highly protected national-security satellite. But it can still create consequences for others: interference with spectrum or communications, misleading observations, hostile proximity activity, compromised shared ground or cloud services, or simply uncertainty that forces more capable operators to spend time and manoeuvre fuel protecting themselves.
A weakly defended platform can therefore become a problem in an ecosystem that contains far more critical ones – with the cyber poverty gap acting as a risk amplifier, converting uneven capability into systematic risk exposure.
Again, scale alone does not guarantee resilience, but resource constraints can make sustained cyber operations particularly challenging for smaller organisations.
Closing the gap
The answer is not to make space exclusive again – maintaining the breadth and depth of the space supply chain is vital for leveraging innovation. But we must recognise that this comes with disparities in capability, resources and governance in terms of cyber security. As such, cyber defence must be designed into the business model and the mission model, not treated as a luxury after launch.
We need proportionate, shared and scalable defence: secure-by-design platforms, assured ground-service providers, common monitoring standards, threat information sharing, and ways for smaller operators to consume serious cyber protection without having to build a national-security SOC of their own.
Resilience needs to be engineered across the entire ecosystem to provide shared visibility into risks and dependencies, trusted participation through security architectures that accommodate varying maturity levels, and capability uplift through industry-wide collaboration.
Because the real risk is not simply that vulnerability is becoming democratised. It is that defence remains a privilege. The cyber resilience of any ecosystem is only as strong as its weakest participant and, in a shared orbital environment where the stakes are higher than ever, the consequences of a cyber poverty gap extend to everyone.
If we truly want secure and resilient space-enabled services, we must move beyond protecting organisations and start protecting systems. That’s a strategic imperative we should all be able to get behind.