The European space sector faces growing cybersecurity risks driven by complex supply chains, geopolitical uncertainty and increasing regulatory requirements. PwC-experts Sachi Chakrabarty en Ewout Stoops explain how to build a resilient and secure space infrastructure.
As the 2022 cyberattack on Viasat's KA-SAT network demonstrated, Europe's sovereignty increasingly depends on securing the space frontier. This incident laid bare the exposure of critical national infrastructure: with thousands of customers disconnected and more than 5,000 German wind turbines stripped of remote monitoring and control, it underscored our reliance on space and the pressing need to secure this environment.
The space sector relies on a complex supply chain involving organisations of all sizes. By learning from similar incidents and adopting security best practices from highly regulated, security-sensitive industries, we've defined six principles to embed security-by-design across this supply chain.
The European space ecosystem is a complex, multinational network shaped by several distinct players. The European Space Agency (ESA) leads at the programme level—defining mission requirements, designing procurement structures, and managing execution through a chain of prime contractors and subcontractors spanning multiple tiers of specialised suppliers. National agencies such as France's CNES (French National Centre for Space Studies), Germany's DLR (German Aerospace Center), and Italy's ASI (Italian Space Agency) strengthen domestic capabilities while remaining aligned with European missions. A new wave of private space companies brings speed, innovation and new commercial models to the sector. Together, these actors form a dynamic yet deeply interdependent supply chain, each facing its own distinct cybersecurity challenges.
The KA-SAT cyberattack demonstrates how a weakness in a single service provider, supplier or operational component can ripple across an interconnected ecosystem, triggering consequences far beyond the original target. Drawing on experience with complex, security-critical supply chains, we have identified four critical challenges facing the European space industry.
A disruption at an upstream supplier can reverberate through multiple downstream production lines. Supplier concentration increases this risk, as essential space components often come from a limited pool of specialised vendors. Qualifying an alternative supplier can take months or years, so any quality issue, insolvency, or geopolitical upheaval at one supplier can trigger a chain of delays, cost overruns, and significant setbacks.
Lower-tier suppliers often operate beyond direct oversight, creating blind spots for cybersecurity compliance. Hidden risks like unpatched software vulnerabilities, poor incident response capabilities, and weak authentication practices can easily go unnoticed in lower tiers.
Regulatory measures such as export controls, sanctions, and foreign investment screening can disrupt supply lines or block technology transfers, creating immediate availability challenges. Meanwhile, foreign acquisitions of small but critical suppliers raise serious intellectual property (IP) concerns, risking exposure of sensitive designs and loss of control over proprietary technologies.
Europe's space supply chains combine legacy operational systems, specialised manufacturing tools and commercial off-the-shelf (COTS) components. This mix creates a broad attack surface with uneven security maturity. A single weak link, such as an outdated protocol or insecure integration, can enable ransomware or credential theft, disrupt production and delay critical deliveries.
Closing these gaps requires a proactive, security-by-design approach across the entire supply chain. By applying the following principles, stakeholders across the European space industry can address the maturity gap between tiers and significantly reduce the likelihood of security incidents.
Standards are an effective lever for raising security across a fragmented supply chain. The precedent already exists in other critical sectors: nuclear installations operate under the strict regimes of the International Atomic Energy Agency (IAEA) and the International Electrotechnical Commission (IEC).
The space sector must take the same approach. Frameworks such as the European Cooperation for Space Standardization (ECSS), the European Space Components Coordination (ESCC), and the EU's Network and Information Security Directive (NIS2) should be embedded from the earliest programme stages and reinforced through contractual cybersecurity requirements. Applied uniformly, they establish a common baseline that uplifts even the least mature suppliers—and periodic independent verification ensures that baseline holds over time.
Security must be embedded across the ecosystem, not treated as a contractual requirement alone. Small and medium-sized enterprise (SMEs) need practical knowledge, tools and training to strengthen their security capabilities. The semiconductor industry offers a proven model: sector-wide collaboration that raises capability rather than simply raising the bar. Space sector stakeholders should unite to build industry-specific programmes that make strong cybersecurity achievable for suppliers of every size.
Resilience in space begins with accepting that no single control is sufficient against a determined adversary. Security must be layered deliberately across hardware, software, and operations—clear network segmentation, hardware roots of trust, signed software updates, and a broader set of resilience measures working in concert. Designed this way, the failure of one control becomes an inconvenience rather than a mission-ending event.
The window between vulnerability disclosure and exploitation is narrowing. This makes rapid, transparent patching a baseline requirement for ground systems and mission-critical software. This demands secure update distribution, verification mechanisms to guarantee integrity, and contingency plans for applying patches where connectivity or access is limited.
Security validation is too often treated as a box to tick rather than a discipline to sustain. Continuous, integrated testing across the entire lifecycle—from mission design through to decommissioning—shifts the balance, surfacing vulnerabilities early enough to mitigate them before they become exploitable.
A satellite launched today may still be flying in the 2050s—long after the public-key cryptography now protecting it has been rendered obsolete by quantum computing. Because in-orbit systems are difficult to update, post-quantum thinking must be designed in from the start rather than retrofitted later. That means designing for crypto-agility, using hybrid approaches during the transition and putting robust quantum key management in place.
Space security is no longer a matter of good practice alone—it is a legal obligation. The deadline for transposing NIS2 into national law passed on 17 October 2024, placing space explicitly among the EU's essential sectors and imposing binding cybersecurity requirements, mandatory incident reporting, and meaningful penalties on operators and their suppliers alike.
Yet across much of the European space supply chain, and especially among agile commercial entrants and lower-tier suppliers, a substantial gap persists between current capability and what is needed. Closing that gap will take sustained effort: embedding standards, establishing verification mechanisms, strengthening incident response and mapping deep-tier dependencies.
The Viasat KA-SAT attack made the stakes clear: one vulnerable supplier, service provider, or operational component can propagate failure across an entire supply chain. Now is the time to assess NIS2 readiness, map critical supplier dependencies, validate cybersecurity controls beyond direct suppliers and strengthen overall resilience across the entire ecosystem.
Partner Cybersecurity, PwC Netherlands
Ewout is a Partner in the Advisory practice at PwC Netherlands. He specialises in Cyber, Data and Technology Risk. Following a career at the Dutch General Intelligence and Security Service (AIVD), he now helps public-sector organisations strengthen their resilience in a world shaped by technological and geopolitical developments.
Director Cybersecurity, PwC Netherlands
Sachi specialises in cyber, data and technology risk. He has led large teams responsible for protecting information in the telecommunications and semiconductor sectors. With more than twenty years’ experience, he helps organisations combine technological innovation with effective cyber, data and information governance, enabling them to remain compliant and manage risk more effectively.