# Space OT cybersecurity

> Ground stations, mission and satellite operations centers, telemetry and command links, and launch range systems for commercial and government space programs. Every spacecraft is flown from a network on the ground.

Canonical: https://blackbirdcyber.com/sectors/space  
Blackbird Cyber · https://blackbirdcyber.com/ · sales@blackbirdcyber.com

## The exposure — The satellite is only as secure as the ground station.

Command and telemetry pass through antenna controllers, modems and mission software that were built for availability, not adversaries. Ground segments often share vendors, remote access paths and flat networks with the corporate side.

Regulations and guidance: NIST IR 8401, Space Policy Directive-5, IEC 62443.

- Command and telemetry link integrity
- Ground station and antenna controller access control
- Segmentation between mission operations and enterprise networks

## Typical topology

A representative control network for space operators, by Purdue level:

- L3.5 · DMZ: Ground segment DMZ
- L2 · HMI: Mission control HMI
- L2 · SCADA: Satellite ops / C2
- L2 · Historian: Telemetry archive
- L1 · PLC: Antenna controller
- L1 · RTU: RF modem
- L1 · Safety: Range safety
- L0 · Process: Antennas · RF chain · spacecraft link

Exposed path: vendor VPN → L2 · Historian (Telemetry archive).

## Where we start — Recommended engagements for space operators.

- [OT Cyber Audit](https://blackbirdcyber.com/capabilities/ot-cyber-audit): A site-level assessment of control system exposure, ranked by consequence.
- [OT Cyber Consulting](https://blackbirdcyber.com/capabilities/ot-cyber-consulting): Fractional OT security leadership for operators without a full-time ICS team.
