September 7, 2022 By Jennifer Gregory 2 min read

In April 2022, a bipartisan group of congressmen introduced the Satellite Cybersecurity Act. Senators Gary Peters (D-MI) and John Cornyn (R-TX) authored the bill, and Congressman Andrew R. Garbarino (R-NY) joined with Congressman Tom Malinowski (D-NJ) to introduce the bill to the U.S. House of Representatives.

“We depend on satellites for everything from driving to work to defending our country, yet our space systems are vulnerable to cyberattack, and the commercial satellite industry has been asking for help to protect Americans against this threat,” said Rep. Malinowski in a statement. “Our bill directs the U.S. government’s primary cyber-defense agency to provide that help.”

Satellite cybersecurity act requires resources and study

The congressmen created the Satellite Cybersecurity Act in response to recent threats and current processes and measures. Here are the two main components:

  • Consolidating resources and best practices. Because different companies own the satellites, they have different processes and best practices. The act requires that the Cybersecurity and Infrastructure Security Agency (CISA) create a commercial system cybersecurity clearinghouse within 180 days of the act becoming law. By creating a public hub and uniform best practices that companies can follow if they choose, the act aims to create more consistent protocols for all satellites. The resources will also include recommendations for network security used to manage and operate the satellites. In addition, some of the resources will be geared to small businesses that have different resources and processes than enterprises.
  • Directs CISA to perform a study on federal government support of commercial satellite industry cybersecurity. Within two years of the act becoming law, CISA must study how the federal government supports commercial satellite systems. The study must also include how the government has addressed critical infrastructure cybersecurity.

“Commercial satellites are an integral part of our infrastructure network and must be protected from cyberattacks by bad actors that would compromise our national security,” said Sen. Cornyn in a statement.

Risks of satellite cyberattacks

An attack conducted through a satellite in February shows the risks and impact of this type of attack. Cyber criminals deployed data wiper malware called Acid Rain onto a KA-SAT satellite. This type of malware wipes data from routers and modems, which leave them inoperable. By targeting the satellite that provided broadband service to SATCOM modems, the attack impacted thousands of modems in Ukraine and tens of thousands in Europe. Because the attack rendered the modems inoperable, the damage spilled to over 5,800 wind turbines in Germany.

“It’s clear the government must provide more cybersecurity support to small businesses and other companies that own and operate commercial satellites before it’s too late. This bipartisan bill will help ensure these organizations — who often do not have enough resources — are able to protect their own networks,” said Sen.Peters in a statement.

More from News

DOD establishes Office of the Assistant Secretary of Defense for Cyber Policy

2 min read - The federal government recently took a new step toward prioritizing cybersecurity and demonstrating its commitment to reducing risk. On March 20, 2024, the Pentagon formally established the new Office of the Assistant Secretary of Defense for Cyber Policy to supervise cyber policy for the Department of Defense. The next day, President Joe Biden announced Michael Sulmeyer as his nominee for the role.“In standing up this office, the Department is giving cyber the focus and attention that Congress intended,” said Acting…

CISA releases landmark cyber incident reporting proposal

2 min read - Due to ongoing cyberattacks and threats, critical infrastructure organizations have been on high alert. Now, the Cybersecurity and Infrastructure Security Agency (CISA) has introduced a draft of landmark regulation outlining how organizations will be required to report cyber incidents to the federal government. The 447-page Notice of Proposed Rulemaking (NPRM) has been released and is open for public feedback through the Federal Register. CISA was required to develop this report by the Cyber Incident Reporting for Critical Infrastructure Act of…

Recent developments and updates in Biden cyber policy

3 min read - The White House recently released its budget for the 2025 fiscal year, which supports the government’s commitment to cybersecurity. The cybersecurity funding allocations line up with the FY 2025 cybersecurity spending priorities released last year that included the following pillars: Defend critical infrastructure Disrupt and dismantle threat actors Shape market forces to drive security and resilience Invest in a resilient future Forge international partnerships to pursue shared goals. In 2023, the White House released a 35-page document detailing the new…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today