September 7, 2022 By Jennifer Gregory 2 min read

In April 2022, a bipartisan group of congressmen introduced the Satellite Cybersecurity Act. Senators Gary Peters (D-MI) and John Cornyn (R-TX) authored the bill, and Congressman Andrew R. Garbarino (R-NY) joined with Congressman Tom Malinowski (D-NJ) to introduce the bill to the U.S. House of Representatives.

“We depend on satellites for everything from driving to work to defending our country, yet our space systems are vulnerable to cyberattack, and the commercial satellite industry has been asking for help to protect Americans against this threat,” said Rep. Malinowski in a statement. “Our bill directs the U.S. government’s primary cyber-defense agency to provide that help.”

Satellite cybersecurity act requires resources and study

The congressmen created the Satellite Cybersecurity Act in response to recent threats and current processes and measures. Here are the two main components:

  • Consolidating resources and best practices. Because different companies own the satellites, they have different processes and best practices. The act requires that the Cybersecurity and Infrastructure Security Agency (CISA) create a commercial system cybersecurity clearinghouse within 180 days of the act becoming law. By creating a public hub and uniform best practices that companies can follow if they choose, the act aims to create more consistent protocols for all satellites. The resources will also include recommendations for network security used to manage and operate the satellites. In addition, some of the resources will be geared to small businesses that have different resources and processes than enterprises.
  • Directs CISA to perform a study on federal government support of commercial satellite industry cybersecurity. Within two years of the act becoming law, CISA must study how the federal government supports commercial satellite systems. The study must also include how the government has addressed critical infrastructure cybersecurity.

“Commercial satellites are an integral part of our infrastructure network and must be protected from cyberattacks by bad actors that would compromise our national security,” said Sen. Cornyn in a statement.

Risks of satellite cyberattacks

An attack conducted through a satellite in February shows the risks and impact of this type of attack. Cyber criminals deployed data wiper malware called Acid Rain onto a KA-SAT satellite. This type of malware wipes data from routers and modems, which leave them inoperable. By targeting the satellite that provided broadband service to SATCOM modems, the attack impacted thousands of modems in Ukraine and tens of thousands in Europe. Because the attack rendered the modems inoperable, the damage spilled to over 5,800 wind turbines in Germany.

“It’s clear the government must provide more cybersecurity support to small businesses and other companies that own and operate commercial satellites before it’s too late. This bipartisan bill will help ensure these organizations — who often do not have enough resources — are able to protect their own networks,” said Sen.Peters in a statement.

More from News

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

CISA and FBI release secure by design alert on cross-site scripting 

3 min read - CISA and the FBI are increasingly focusing on proactive cybersecurity and cyber resilience measures. Conjointly, the agencies recently released a new Secure by Design alert aimed at eliminating cross-site Scripting (XSS) vulnerabilities, which have long been exploited to compromise both data and user trust. Cross-site scripting vulnerabilities occur when a web application improperly handles user input, allowing attackers to inject malicious scripts into web pages that are then executed by unsuspecting users. These vulnerabilities are dangerous because they don't attack…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today