A cybersecurity workshop convened at London's Park Plaza Victoria hotel on October 1, 2026, carried a title that would have sounded out of place at a ground segment conference a decade ago: Hardening the Ground Segment, Cybersecurity for Next-Generation Gateways. Organized by the Global Satellite Operators Association's security interest group for the Strategies in Satellite Ground Segment conference, the session addressed what the industry now treats as settled fact. Ground stations have become shared, software-defined, multi-tenant infrastructure, and that shift changes who can attack them and how.
Renting Antennas Instead of Building Them
Ground-station-as-a-service, or GSaaS, lets a satellite operator uplink and downlink through someone else's antenna network instead of building its own. Amazon Web Services expanded its GSaaS partnership with Kongsberg Satellite Services in July 2025, giving AWS Ground Station customers access to KSAT's network of more than 200 multi-mission antennas spread across over 40 sites worldwide, from Svalbard to Antarctica. Leaf Space runs a comparable network of more than 40 antennas across 17-plus locations, and Michigan-based ATLAS Space Operations operates 51 antennas spanning 34 ground stations, marketed as a federated network that a mission integrates with once and then draws on everywhere. Microsoft took the opposite path. It retired its own Azure Orbital ground station service in October 2024 and sold ten S-band and X-band tracking antennas to Space Leasing International, which leased them on to ground station operator RBC Signals, a sign that even a hyperscaler decided it would rather buy ground segment capacity than run it.
One Dish, Many Missions, One Weak Link
The commercial pitch is that a shared antenna network can cut a satellite operator's ground infrastructure costs by as much as 80 percent compared with leasing dedicated dishes or building new ones, according to AWS. The security picture is harder to sell. Kratos' industry analysis of the GSaaS model notes that pooling antennas and control software across customers turns a single ground station into shared, cloud-connected infrastructure, more exposed to ransomware crews and state-backed intrusion than a single operator's private site ever was. Providers respond with layered isolation. Leaf Space says customer traffic is encrypted before it reaches its network and segregated end to end under a zero-trust model built around ISO 27001 and NIST 800-171, with no cryptographic key ever shared between missions. Whether that architecture holds depends on a detail outside any single customer's control: who else is sharing the dish, and how well they patch their own systems.
Supply Chain, Not the Satellite, Worries the Defenders
Oystein Thorvaldsen, KSAT's chief information security officer, told Help Net Security in December that the ground segment, not the spacecraft, is the practical way in for most adversaries, and that supply chain weaknesses are the risk his team worries about most, precisely because the industry still underestimates it. A February 2026 report from the Bloomsbury Intelligence and Security Institute on North American ground segments reached a similar conclusion from a different angle. It found unpatched legacy software, commercial off-the-shelf hardware, unsigned firmware and weak network segmentation still common across ground stations, and it modeled the threat in tiers, from Tier 5 ransomware crews targeting a single commercial site for a payout to Tier 6 state actors capable of exploiting ground infrastructure the way Russia-linked hackers exploited an unpatched Fortinet VPN to take down Viasat's KA-SAT network in 2022. BISI's own near-term forecast judged it likely that a criminal group would ransom a small North American ground station within three months of publication.
The Rulebook Is Still Catching Up
Formal guidance exists but predates the GSaaS boom. NIST published IR 8401, mapping its Cybersecurity Framework onto satellite command-and-control ground systems, in December 2022, and CISA followed in 2024 with recommendations to space system operators that treat ground infrastructure as the likeliest entry point into any satellite mission. Neither document anticipated a ground segment where the antenna, the network and the orchestration software might belong to three different companies serving dozens of customers at once, which is the gap the GSOA workshop in London was convened to address. Participants discussed supply chain assurance and interoperability risk for gateways that increasingly serve multiple orbits and multiple operators through the same hardware.
Government ground segments are moving the same direction. The U.S. Space Development Agency issued a 369 million dollar sources-sought notice on September 22, 2026, for a Performance Enhanced Real-time Ground Environment, or PEREGRINE Sentry, that would turn the ground segment supporting its missile-tracking satellites into a modular, multi-tenant development environment shared across contractors, with industry responses due October 23.
The ground segment's standing as satellite security's soft underbelly was first reported by Help Net Security in its December 2025 interview with KSAT's Oystein Thorvaldsen.




