![The hidden risks in space supply chains. [T-Minus: Space-Cyber Briefing] — CyberWire Daily cover](https://megaphone.imgix.net/podcasts/16101210-8cf6-11f1-afa1-6708074dce89/image/637ef5fa089ca3dbceebd7bda30c7eb8.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress)
Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th. Use code CYBERWIRE for $200 off your briefings pass@BlackHat.com we'll see you in Vegas.
C
I actually think it is something that is lacking in the space community. I think they believe that if they're CyberSecure from an IT perspective that they'll be fin. But in reality it's all of those little components that are truly vital. T minus.
A
Welcome. I'm Maria Varmazes and you're listening to T minus Space Cyber Briefing. In this show we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects and connects our lives.
C
Three, two, one.
A
Hi everybody, thanks for joining me. Today's episode is an expert look at global space supply chain risk. And we're not just talking about the hardware, but spacecraft. Software is an increasingly important part of this conversation too. Jen Sovatta at Clarity is my guest today and she sees space supply chain risk as an accumulation of small vulnerabilities across tiers. That includes counterfeit or tampered parts, limited visibility into sub tier suppliers and software that can be altered during design, development or deployment. We get into all of that in our conversation. Here it is.
C
Thank you so much for having me on, Maria. It is great to be here. I am Jen Savada. I'm the general manager of the public sector at Clarity, which is an operational technology cyber physical systems company. And what we do is we protect all of the physical devices that are out there and that could be your global supply chain, it could be your space based systems, ground stations, your building management systems IoT and the like. And I'm just happy to be here.
A
Well, thank you Jen so much for joining me today. And you have a very wide ranging expertise and there are sort of a million questions I wanted to pepper you with.
C
But I'll focus for the sake of
A
our conversation on something that I've been really curious about, which is sort of the state of the space supply chain and the risk present there. I'm curious what comes to mind for you when we talk about space supply chain risk.
C
Yeah, you know what's interesting is that everybody thinks about the headline grabbing adversary, but it's actually I think more important to talk about the accumulation of really small weaknesses across the tiers of the supply chain. That includes counterfeit parts, tampered components, dependencies between them, visibility having lack of visibility between sub tier suppliers, those little mom and pop shops that they make one screw, but that one screw is so important that you need it. And then understanding the firmware, software and other capabilities that can get altered anywhere across the design and development and deployment.
A
Often when I try to broach this topic understandably and sort of the space realm, we tend to focus a lot on the hardware side. And selfishly, I'm also getting very interested in the software and firmware side of things, mainly because I feel like it hasn't gotten as much attention. And that may be, and I could be wrong here because of how exquisite the systems have been historically, one offs per spacecraft. But my understanding is that is changing at high speed. And I'm wondering about the software level supply chain risk also, if you could talk to me a little bit more about that.
C
Sure. So if we think about the fact that we now have companies that are pumping out hundreds of satellites a year as opposed to one every five years, the risks have changed. From a software perspective, there's always new software that's developed. It's not when. When the US government used to build space systems, they developed the software and they developed the hardware. But it wasn't an iter iterative process. It really was something like, okay, we have one space system, we have one software package that we need to load. But now because they're continually manufacturing, they're continually updating, making them more sensitive, making them more secure, and as you continue to operate and develop and deploy software glitches can happen. You can have a code problem, you can have a deployment problem, you can have insider threat. That's actually something that you hadn't thought about before because it is so dynamic.
A
I was just reading recently that the FCC is trying to open up, for example, more spectrum to direct a device for communicating with satellites. And something that's been talked about in the cyber realm a little bit is how directed device sort of opens up a brand new part of the threat landscape in a way that maybe hadn't been present for satellites historically. And I'm wondering your thoughts on that and what maybe directed device might be as an opportunity for risk.
C
Yeah, I think if we think about how things have been going just even in the Ukraine war, and how satellite technology has been affected by very simple basic types of threats, jamming, for example, GPS jamming, so when we think about opening it up more broadly to a larger spectrum, as we know the spectrum, depending on the spectrum you're in, is more or less vulnerable. So as we continue to develop and change, we have to think about the threat vector differently. Because now that enables a larger threat vector and possibly a different threat vector than what we had originally thought. And being able to adapt to that is something that we're going to need to be able to think through and also build too.
A
What are your recommendations there for that adaptation?
C
Yeah, I think one of the things that we need to be thinking about is not just software, but also the hardware that goes into it. So if we think about operational technology systems, we have a space segment, we have a launch segment, we have a ground segment, and you've got the payload and the bus, and you've got servos and gyros and all sorts of things that move the spacecraft. Well, if the controller gets modified through software, then you could send the spacecraft into an orbit that was not planned from a launch segment. You have the rocket itself and the ground support and the ground systems, and all of the things that control that functionality of what you're doing in space, whether it's taking images, whether it's listening to things, whether it's providing communications. And if you are able to impact the ground segment by changing some of the hardware, programmable logic, control and other things, you might be able to impact the space segment. And then finally, if we think about other components of the entire space system, it's really the design and the assembly and IT all working as an ecosystem. So everything is interactive, it's linked and is vital to the operation of that system.
A
How would you describe the maturity of that ecosystem right now in terms of recognizing the risk that's there or maybe trying to proactively get in front of it?
C
I actually think it is something that is lacking in the space community. I think they believe that if they're CyberSecure from an IT perspective, that they'll be fine. But in reality, it's all of those little components that are truly vital. And if we think about how long space ground systems have been around besides the more modern companies like SpaceX and United launch and other things. But the legacy systems that the US Government operates have legacy firmware, have legacy operational technology devices. And those devices you can't just rip and replace because it impacts the entire ecosystem. You can't take it all down because that'll impact operations like we do with IT systems. So figuring out how to work with those systems differently is important and understanding how to secure them is important.
A
This feels like a good place to take a break. We'll be right back.
C
Foreign
A
let's get back to my conversation with Jen Sovata at Clarity about space supply chain risk. As you say, all that. Also, I'm wondering about when we think of the supply chain, it being more globalized and I don't know if actually that's necessarily a correct assertion that it is becoming more globalized. Sometimes I think it is, sometimes I'm thinking it's much more localized. Thoughts on the global supply chain? I'm just, I'm just curious, do you agree with the assertion?
C
I totally. I totally agree with you. And, and you know, believe it or not, the White House agrees with you. They actually released an executive order yesterday that's about securing America's defense supply chain and ensuring domestic acquisition of critical materials. And so this isn't just a critical minerals issue. This is a, hey, we have a reflective mirror that's only built in China. It is critical to our satellite, but the only place that develops it in China. But that's a country that we have restrictions on buying certain things from certain companies, from certain, you know, so if we think about it from that perspective, it's huge. I mean, it's a huge problem. It's bigger than people think. And it's not about entire components. It's not about buying an aircraft. It's about buying the small little widget that we don't have everywhere.
A
Right. So I guess how do we get to there from here? I mean, there are. Aerospace is so fascinating. The more I've learned about it with these, with all these really tiny suppliers that do make that one exquisite screw for a thing. And they've been doing it for decades and they're really good at it. But you know, it might be just two people running that shop. I mean, how do we safely keep them in the fold but also make sure that they are doing what they need to do on the risk side of things? I mean, we don't want to be burdensome, but at the same time, the risks are present and growing. So how do we get there?
C
Yeah, I think we have to think about resilience in the supply chain. If we have just one mom and pop doing it, I think that's a problem we need to be thinking about how do we make four mom and pops doing it? Because the scale of satellite build, development and manufacturing has increased. That one mom and pop is no longer making one widget for one satellite a year. They can now make hundreds of widgets for the hundreds of satellites a year. So being able to create that redundancy is not as much of a problem today as it would have been previously.
A
That's a great point. And I'm wondering also, are there areas of this discussion around supply chain risk in the space industry that you feel are usually under discussed? I'm just curious if there's something that you'd really like to make sure that we discuss, because I bet there is.
C
I think one of the biggest things that isn't really discussed is how variable the space ecosystem really is. We think about the satellites mostly, but as I mentioned before, it's the ground stations, it's the launch pads, it's all of the communication between the satellite and those things. And so looking at it as an entire ecosystem is just as important as looking at it from did that satellite get to the orbit then need to get to. If we think about the recent blue origin explosion that happened on the launch pad, yeah, it was huge because it didn't just impact the launch of that satellite, it impacted the entire supply chain because they had to rebuild their launch pad. They have to rebuild the satellite. They have to think about, is it a structural problem, was it a software problem, is it a cybersecurity problem? What is the issue within that entire ecosystem that caused that explosion to happen? Yes, we have the technical reason, but is there something else behind that technical reason? So understanding how that all plays together is important.
A
And I'm curious also if there's something that a cyber professional who's listening to this, who maybe is not in the space realm, maybe is interested in moving into it. But what would you want them to know about the space industry supply chain risk that maybe they haven't thought about?
C
Yeah, I think that there's a couple of things. One, defense in depth is important. We need to have more robust, resilient systems. From a cybersecurity perspective, we need to have continuous monitoring. So we need to have in those manufacturing plants continuous monitoring of all of the robot arms that are building, all of the components to make sure that they're doing what they they need to be doing and that all of the pieces are manufactured to the precise materials that they are. We need integrity in our software. And that's not just IT software, that's also the firmware that goes into those operational technology devices. And then we need to have visibility into the supply chain so that we can understand how to continually protect and evolve the protection of that supply chain.
A
Well, Jen, it has been an absolute pleasure speaking with you. You are a fount of knowledge and I've learned a ton from you today. I want to make sure if there's any sort of concluding thoughts you want to leave our audience with that I give you that opportunity?
C
Sure, I would love to. And thank you for chatting with me today. It's been really fun. I think that one of the biggest things I want to bring up is that in space we can't treat the supply chain resilience as just a procurement problem. In space, cybersecurity and supply chain integrity are really, really important as well as mission assurance. So cyber security and cyber attacks can affect spacecraft. The link, the ground segment and the risks of all of that is no longer limited to the one layer of what we talk about. And so understanding, as I mentioned earlier, sort of the ecosystem is really important as we look at space supply chain and our capabilities across the globe.
A
Jen, thank you so much for joining me today. I really appreciate it and thank you so much for sharing your expertise with me.
C
Thank you.
A
And that's T Minus Space Cyber Briefing brought to you you by N2K CyberWire. If you like what you heard today, you'll also enjoy our newsletter called Signals and Space. In it, you'll get research and notes pulled together by our producer Ethan Cook and me, along with this week's top Space Cyber news stories. You can subscribe by visiting TheCyberWire.com newsletters We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like our show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to space2k.com we're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector. From the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies, N2K helps cybersecurity professionals grow, learn and stay informed. As the nexus for discovery and connection, we bring you the people, the technology and the ideas shaping the future of secure innovation. Learn how@n2k.com thanks again for listening to T Minus. I am your host Maria Varmazes. This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester with original music music by Elliot Peltzman. Our Executive producer is Jennifer Ibin with content strategy by Mayan plout. Peter Kilby is our publisher. See you next week. T minus, sam.
Date: August 2, 2026
Host: Maria Varmazes (A), N2K Networks
Guest: Jen Sovata (C), General Manager Public Sector, Clarity
In this episode, host Maria Varmazes sits down with Jen Sovata, General Manager of the Public Sector at Clarity, to discuss the evolving risks in the global space supply chain. The conversation dives deep into how small, often overlooked vulnerabilities—in both hardware and software—can accumulate across tiers of the supply chain, raising significant cybersecurity and resilience concerns for space systems. The episode covers everything from the changing nature of supply chain risks (hardware, software, and global logistics) to supply chain resilience strategies, regulatory shifts, and actionable advice for industry professionals.
Not Just About Big Threats:
"Everybody thinks about the headline grabbing adversary, but it's actually I think more important to talk about the accumulation of really small weaknesses across the tiers of the supply chain."
— Jen Sovata [03:18]
Risk Across the Board:
Supply Chain Attention Historically on Hardware:
Maria notes the industry’s traditional focus on hardware, while software is increasingly vital and under-discussed.
Changing Software Supply Chain Dynamics:
"If we think about the fact that we now have companies that are pumping out hundreds of satellites a year as opposed to one every five years, the risks have changed."
— Jen Sovata [04:33]
This episode shines a spotlight on the underappreciated vulnerabilities in the modern space supply chain, illustrating how even minor oversights can cascade into mission-critical failures. Jen Sovata underscores the need for holistic, ecosystem-level thinking; continuous monitoring; integrity in both hardware and software; and policy-driven as well as technical approaches to resilience. The episode is essential listening for anyone involved in space systems, supply chain management, or cybersecurity in critical infrastructure.