Space systems support the operation of many critical infras- tructures and are often considered critical infrastructure them- selves. However, the cybersecurity of space remains poorly measured, inconsistently governed, and inadequately protected. This thesis investigates the gap between the actual cyber risk exposure of space-sector organisations and the governance frameworks designed to address it, combining technical anal- ysis, empirical measurement, legal assessment, and compar- ative policy research. The research first assesses the vulnerability landscape of satel- lite communication systems through a technical survey and the analysis of the 2022 Viasat KA-SAT attack, complemented by original reconnaissance of internet-exposed space assets using network scanning tools. The findings show that ground and user segment security is systematically neglected despite being the primary attack vector in documented incidents. Building on this threat landscape, the thesis then evaluates the cybersecurity governance frameworks of the United States, United Kingdom, Germany, and the European Union, high- lighting a consistent gap between regulatory ambition and operational effectiveness. To support the measurement of security posture, a structured set of cybersecurity metrics is developed and validated for the space domain, mapping existing metrics against the NIST Cybersecurity Framework 2.0 and proposing new space-specific indicators introduced in a realistic satellite network architec- ture. xxiii The Risk Exposure Framework is then introduced as a repro- ducible, data-driven methodology that quantifies the cyber exposure of space organisations by combining internet scan- ning data with vulnerability intelligence. Applied to eight major space organisations, it finds that approximately four percent of their combined internet-facing assets carry known, unpatched vulnerabilities, with risk concentrated in outdated web server stacks, legacy cryptographic libraries, and insuf- ficient patch management. Finally, a systematic discourse analysis of official policy docu- ments from China, the United States, and the European Union reveals that the three actors operate from structurally incom- patible governance models, producing divergent strategic pos- tures and practices in space security that make international convergence unlikely in the near term. The findings demonstrate that the space sector’s attack sur- face is large, exposed, and exploitable, and that existing gov- ernance frameworks lack the technical specificity and enforce- ment capacity to produce measurable security outcomes. Cre- ating a connection between technical vulnerability assessment and policy analysis, the thesis maps the actual threat land- scape, assess whether current policy responses are adequate, and identifies what additional measures are needed to move from the recognition of risk to its meaningful reduction.
Space Cyber Risk: A Hybrid Analysis of Threats, Policies, and Governance / Casaril, F.. - (2026 Jul 13). [10.13118/francesco-casaril_phd2026-07-13]
Space Cyber Risk: A Hybrid Analysis of Threats, Policies, and Governance
Francesco Casaril
2026
Abstract
Space systems support the operation of many critical infras- tructures and are often considered critical infrastructure them- selves. However, the cybersecurity of space remains poorly measured, inconsistently governed, and inadequately protected. This thesis investigates the gap between the actual cyber risk exposure of space-sector organisations and the governance frameworks designed to address it, combining technical anal- ysis, empirical measurement, legal assessment, and compar- ative policy research. The research first assesses the vulnerability landscape of satel- lite communication systems through a technical survey and the analysis of the 2022 Viasat KA-SAT attack, complemented by original reconnaissance of internet-exposed space assets using network scanning tools. The findings show that ground and user segment security is systematically neglected despite being the primary attack vector in documented incidents. Building on this threat landscape, the thesis then evaluates the cybersecurity governance frameworks of the United States, United Kingdom, Germany, and the European Union, high- lighting a consistent gap between regulatory ambition and operational effectiveness. To support the measurement of security posture, a structured set of cybersecurity metrics is developed and validated for the space domain, mapping existing metrics against the NIST Cybersecurity Framework 2.0 and proposing new space-specific indicators introduced in a realistic satellite network architec- ture. xxiii The Risk Exposure Framework is then introduced as a repro- ducible, data-driven methodology that quantifies the cyber exposure of space organisations by combining internet scan- ning data with vulnerability intelligence. Applied to eight major space organisations, it finds that approximately four percent of their combined internet-facing assets carry known, unpatched vulnerabilities, with risk concentrated in outdated web server stacks, legacy cryptographic libraries, and insuf- ficient patch management. Finally, a systematic discourse analysis of official policy docu- ments from China, the United States, and the European Union reveals that the three actors operate from structurally incom- patible governance models, producing divergent strategic pos- tures and practices in space security that make international convergence unlikely in the near term. The findings demonstrate that the space sector’s attack sur- face is large, exposed, and exploitable, and that existing gov- ernance frameworks lack the technical specificity and enforce- ment capacity to produce measurable security outcomes. Cre- ating a connection between technical vulnerability assessment and policy analysis, the thesis maps the actual threat land- scape, assess whether current policy responses are adequate, and identifies what additional measures are needed to move from the recognition of risk to its meaningful reduction.| File | Dimensione | Formato | |
|---|---|---|---|
|
Space_Cyber_Risk__A_Hybrid_Analysis_of_Threats__Policies__and_Governance___REVISION (1).pdf
accesso aperto
Tipologia:
Tesi di dottorato
Licenza:
Creative commons
Dimensione
2.13 MB
Formato
Adobe PDF
|
2.13 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


