SALT LAKE CITY – Small satellites face growing threats because potential adversaries recognize their expanding role in providing communication, Earth-observation and navigation services, a panel of satellite and cybersecurity experts said at the 2026 Small Satellite Conference.
“What we’ve seen in the last three years is the operationalization of a lot of these systems turning into either national security capabilities or commercial capabilities that are revenue positive,” Brandon “BT” Cesul, Umbra senior business development manager, said Aug. 25 during a panel on threats to “the SmallSat Revolution.”
Growing revenues attract investors and help companies establish and expand constellations.
People should keep in mind, though, that “dense constellations concentrate capability as well as risk,” said Erin Miller, architect and executive director of the Space Information Sharing and Analysis Center (ISAC), a nonprofit that shares information on vulnerabilities, incidents and threats.
Threat vectors
As constellations grow, each satellite is a potential endpoint that an unauthorized user, seeking access to the constellation, can target, said Shawn Cozzolino, Deloitte commercial space cybersecurity lead.
Services that space companies rely on, like GPS, communications or open-source coding, are also potential threat vectors, said Cesul, a former intelligence analyst with a PhD in aerospace engineering from the Air Force Institute of Technology.
In addition, panelists cautioned satellite builders and operators to scrutinize their supply chains.
“We’re seeing a lot of automated constellation management systems with no little to no human in the loop,” said Catherine Venturini, Aerospace Corp. principal engineer. “You can upload software or a patch, and it can propagate something across your whole constellation. That’s something to be really careful about.”
Hardware components introduce risk as well. As companies concentrate on rapidly expanding space-based capabilities, they should pay attention to where their key components, “their crown jewels,” are manufactured, Cozzolino said.
For some companies, that means more vertical integration.
“Bringing the production in-house is one way to control costs and ensure security of components,” Cesul said.
No juicy targets
Before proliferated constellations, cybersecurity experts and government leaders warned potential adversaries were developing weapons to target exquisite satellites. Since the U.S. has largely shifted to a model of resilience through proliferated constellations, adversaries “have to start developing weapon capabilities that can take out multiple capabilities with a single attack,” Cesul said, noting rumors of a Russian nuclear anti-satellite weapon and wide-area jamming.
“Counterintuitively, by going to these megaconstellations, we may have made the job for the adversary easier,” Cesul said. “Now they don’t need exquisite space surveillance assets that can develop exquisite target sets to hit a bullet with a bullet.”
Instead, they can identify the altitude of an orbital shell and develop a weapon to affect everything passing through a zone in that shell, he added.
Information sharing
Satellite operators and government agencies are trying to address the growing threats through information sharing.
By sharing high-level information on attacks and responses, organizations “build that trust that everyone is working together for the same goal,” Venturini said.
The U.S. Space Force Joint Commercial Operations Cell gives companies access to high-quality threat data. Organizations also share information through the Space ISAC.
If these information-sharing initiatives are expanded, Cesul said, they could provide important early warnings of attacks, “like a canary in a coal mine,” Cesul said. “As soon as that first incident happens, everybody else can respond appropriately and ensure that if we don’t have 99% capability, then we have 95% capability.”
Related