OTSecurity

Satellite communications growth expands cybersecurity attack surface across IoT, utilities, critical infrastructure


Rapid expansion of satellite communications is creating new cybersecurity exposure as more than 18,000 active satellites orbit Earth and direct-to-device services extend connectivity to cars, farms and remote communities, Manar Alohaly, senior RDI executive at the Saudi Information Technology Company (SITE), detailed in a recent World Economic Forum (WEF) post. This comes as the growth of low-Earth-orbit constellations and satellite-enabled devices is making satellite networks an increasingly important part of global digital infrastructure while also creating new dependencies and potential points of failure.

Starlink’s low-Earth-orbit constellation has now reached over 160 markets, providing broadband access to rural communities and maritime routes where conventional fiber and mobile infrastructure falls short. “As a result, the satellite communication market is on an aggressive growth trajectory. It is projected to rise from $14.56 billion in 2025 to $33.44 billion by 2030, representing an 18.1% compound annual growth rate.”

Alohaly noted that this rapid expansion of satellite communication is also introducing systemic cybersecurity exposure that governments and businesses must consider and address as this technology becomes even more embedded in everyday life.

Expanding satellite ecosystem is also widening cybersecurity attack surface, with direct-to-device services connecting satellites, ground gateways, network services and endpoints such as smartphones and IoT sensors. 

Alohaly said satellite-enabled IoT is expanding across logistics, agriculture and utilities, where compromised links or manipulated sensor data could disrupt operations, affect safety or damage infrastructure. Software-defined satellites and in-orbit reconfiguration introduce additional risks, including remote manipulation, unauthorized access and malicious or compromised software updates.

Satellite systems architecture comprises three interconnected segments that deliver end-to-end connectivity, including user segment (ground-based terminals like satellite dishes), space segment (orbiting satellites deployed across different orbital bands), and ground segment (terrestrial network connections). Satellites operate across three primary orbital ranges with the LEO (below 2,000km), MEO (2,000–35,786km), and geostationary orbit (approximately 35,786km), each suited to different mission requirements and coverage patterns.

“These satellites are connected, with each receiving uplink signals from ground stations or adjacent spacecraft, performing onboard processing and retransmitting data to designated coverage areas on the ground,” according to Alohaly. “The ground segment includes gateway Earth stations and control facilities that oversee satellite operations, support telemetry and command functions, and maintain bidirectional communication with the satellites in orbit. This architecture enables near-global coverage and infrastructure-independent connectivity. It positions satellite networks as a critical complement to terrestrial infrastructure, or ground-based communication networks and facilities, particularly in remote, underserved or disrupted environments.”

The post acknowledges that satellite communications have undergone rapid transformation in recent years, driven by geopolitical pressures, commercial expansion and technological innovation. This shift has elevated satellite systems to critical importance for national resilience, making it essential to understand the four major trends currently reshaping the sector.

The proliferation of commercial low-Earth-orbit constellations has delivered significant economic and connectivity benefits, unlocking new opportunities from orbital data centres to in-space manufacturing. However, this growth has introduced systemic concentration risk. As of March 2026, a single commercial operator controls the majority of active satellites in orbit—a single point of failure that could cascade across sectors and borders if compromised by cyberattack, service disruption or policy change.

Satellite direct-to-device connectivity represents a fundamental shift in how communications reach end users, enabling seamless connection to mobile handsets and IoT devices across terrestrial and independent satellite layers. While this expands coverage and resilience, it also widens the attack surface dramatically. The ecosystem now encompasses satellites, Earth gateway stations, diverse endpoint devices and complex interdependencies that complicate visibility, attribution and incident response across space and ground-based environments.

Satellite connectivity is embedding itself across critical industries, as automotive systems incorporate positioning and emergency SOS, while logistics and utilities deploy IoT monitoring and control. Automotive sector alone is projected to reach $25.8 billion by 2034, while an estimated 2.5 billion to 3 billion IoT devices now have satellite addressability. This expansion elevates cyber-physical risks beyond data loss, where compromised sensors or manipulated connectivity could disrupt operations, compromise safety or damage infrastructure in sectors previously less exposed to space-based vulnerabilities.

The shift toward software-defined satellites is dissolving the traditional boundary between space and ground systems, replacing static ‘bent pipe’ repeaters with flexible, reconfigurable architectures. This operational efficiency comes at a cost, introducing new attack vectors, including remote manipulation, unauthorized access and malicious software updates that threaten system integrity and increasingly control critical infrastructure worldwide.

Alohaly expects these emerging trends to have implications for satellite communication development, but it is also important not to lose sight of the well-established threats associated with satellite technologies. This includes jamming, eavesdropping and unauthorized access to telemetry.

“All of these evolving developments warrant a closer look at where current security and regulatory measures may fall short,” she observes. “Governments and businesses must examine how new dependencies could affect global communications resilience. They should also consider whether regional regulatory requirements and geopolitical factors should affect procurement decisions and how collaboration could support resilience.”

She concludes that as space-based networks become foundational to global communications, they create a highly interconnected attack surface, raising critical cybersecurity challenges that require ongoing evaluation.



Source link