Securing the Orbital Layer: What Joint LEO SATCOM Guidance Means for Defense
Back to Signal
SpaceCybersecurityAIDefenseISRInfrastructure

Securing the Orbital Layer: What Joint LEO SATCOM Guidance Means for Defense

April 5, 2026Jess Loban

Follow the service from orbit to the user

On March 24, the NSA announced joint guidance developed with Australia's Signals Directorate and partners including the Australian Space Agency, Canadian Centre for Cyber Security and New Zealand's National Cyber Security Centre. The full guidance addresses a growing reliance on low Earth orbit satellite communications for government, commercial and emergency services.

The architecture matters because the customer receives a service assembled from several connected parts. A spacecraft may be functioning normally while a ground network, management account or user application is compromised. Conversely, an outage can arise from interference or an ordinary equipment problem without an intrusion into the satellite itself.

The guidance's categories provide a useful way to organize the review:

  • Space segment: satellites and their onboard systems.
  • Ground infrastructure: control facilities, gateways and user terminals.
  • User segment: the connected devices, applications and interfaces consuming the service.
  • Communications links: the connections joining those elements, including radio-frequency links.
  • Supply chain: the hardware, software, services and providers supporting the whole arrangement.

This is more useful than treating the terminal as the complete security boundary. A terminal on a ship or at a remote installation sits inside a larger network of administrative and technical dependencies. Its compromise may expose connected systems where access controls permit that movement; it should not be assumed to grant access to the entire constellation.

Scale creates a coordination problem

LEO services can involve many satellites, distributed gateways and changing connections as spacecraft move. Security teams need to understand which aspects the provider manages and which remain with the customer. The number of satellites alone does not establish security quality, and geostationary services also have ground, management and user dependencies.

For a defense program, the critical questions are concrete. Who can change terminal settings? How are updates authenticated and scheduled? What information about an outage or security event reaches the customer? What happens when the normal management path cannot be reached?

Those questions should be answered for the purchased service tier and intended deployment. A commercial capability suitable for a routine office connection may need additional controls, support arrangements or operational limitations before it supports a mission with different consequences of failure.

Separate radio interference from network compromise

Jamming, spoofing and interception pose different problems from compromised credentials or malicious software. A robust response process needs evidence that helps distinguish them. Otherwise, teams may spend an outage investigating the wrong part of the service or make a configuration change that complicates recovery.

As an engineering practice, preserve relevant terminal, network and service-health observations and establish a path for joint investigation with the provider. Document what information is available locally during disconnection and what can be recovered afterward. Define who may change the configuration, isolate a component or switch to an approved alternate service.

Resilience also depends on the application. If a connection slows or fails, users need to know which functions remain dependable, which data may be stale and which work must wait. Connectivity recovery should include checking the integrity and freshness of the information carried over it.

AI-assisted reconnaissance is a documented concern

The threat is not hypothetical, but the evidence deserves precision. In February 2024, OpenAI reported that Forest Blizzard used its services for open-source research into satellite communications protocols and radar imaging, as well as scripting support. Microsoft's accompanying account described attempts to augment existing activity and said that the monitored research had not identified significant attacks employing those LLMs.

That is evidence of adversarial use for research and assistance. It does not establish an AI-enabled compromise of a LEO constellation. The practical implication is to assume that technical complexity alone will not keep system details obscure and to prioritize controls against the underlying intrusion paths.

Defenders can evaluate AI-assisted analysis where it improves triage or correlation, but they should measure that benefit. Useful tests include missed events, false alarms, analyst workload and behavior during incomplete telemetry. Automated recommendations still need appropriate safeguards before they can change a service supporting a consequential mission.

Questions to resolve before procurement or renewal

  1. Responsibility: identify the provider and customer owner for each component and security function.
  2. Access: establish how privileged accounts, terminals and connected user systems are controlled.
  3. Maintenance: document update support, vulnerability handling and end-of-support conditions.
  4. Visibility: agree on logs, incident notification, service-health information and retention.
  5. Continuity: test approved fallback arrangements and restoration procedures with actual users.
  6. Evidence: retain the configuration and test results supporting the intended mission use.

Commercial providers can play an essential defense role while operating under different service agreements and regulatory obligations. The customer should make those obligations explicit rather than assume that use by a defense organization automatically supplies the required controls or certifications.

Sources and further reading

Spartan X's cybersecurity and engineering work connects the orbital service to the mission on the ground: clear trust boundaries, usable monitoring and continuity plans that account for the customer's actual operating conditions.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.