Low Earth orbit (LEO) satellites are reshaping global communications because they enable fast internet connections with very low latency, operating at altitudes generally below 2,000 km. This infrastructure, however, remains surprisingly exposed to high-intensity cyber threats. The result is a very concrete political push towards stricter obligations on encryption, authentication, and risk management across the entire value chain.
LEO does not simply mean “more satellites”, it means a different architecture
A satellite system transfers signals between transmitters and receivers through a ground segment, user terminals or ground stations, an uplink to the satellite, and a downlink back to Earth. Modern LEO networks add direct links between satellites within the same constellation (inter-satellite links). This architectural choice reduces dependence on ground stations, lowers latency, and increases overall network efficiency.
LEO constellations require a large number of satellites because each satellite covers a smaller area compared to MEO or GEO systems, and service continuity depends precisely on the density of the constellation. Proximity to Earth makes LEO particularly suitable for high-speed internet services and latency-sensitive applications such as video conferencing. The same feature explains their relevance in areas where terrestrial networks are absent or unreliable, including remote regions and conflict zones.
The geopolitical race is already underway, and Europe starts from behind
The global satellite ecosystem shows a striking concentration in LEO, with the majority of active satellites in 2024 operating in this orbit. The United States dominates the sector through SpaceX’s Starlink, which accounts for roughly two thirds of active LEO satellites, and through Amazon’s Kuiper project. China has announced the Guowang constellation and related initiatives, while Russia is planning the Rassvet system.
Europe currently relies on a single operational LEO constellation, Eutelsat OneWeb, with roughly 659 satellites. At the same time, the Union plans, through the IRIS² programme, to deploy 290 LEO satellites by 2030 to support secure communications. The European challenge is therefore not limited to closing a quantitative gap. It also concerns the availability of genuinely sovereign alternatives in a sector where technological dependence very quickly turns into strategic dependence.
Cyber threats to LEO satellites are not theoretical, they form an operational catalogue
The main threats include jamming (frequency saturation), spoofing (replacement of legitimate signals with false ones), hijacking (malicious alteration or substitution of legitimate signals), and the compromise of ground-segment IT networks for espionage, surveillance, or attack. Each threat targets a different layer of the system, radio frequencies, signal authenticity, payload control, or command-and-control networks. Together, they underline how fragmented and vulnerable the attack surface of space-based connectivity has become.
EU law is trying to catch up with orbit, with a new and more sector-specific layer
Existing EU frameworks on cybersecurity and resilience already affect space-related infrastructure, in particular the ground segment operated by public or private entities. The NIS2 Directive and the Critical Entities Resilience (CER) Directive have strengthened requirements for cybersecurity and physical resilience. The Cyber Resilience Act adds binding obligations across the lifecycle of products with digital elements, including components used in space infrastructure.
Against this background, the proposed EU Space Act introduces a dedicated sectoral regime aimed at significantly increasing the resilience of European space infrastructure. It requires preventive and response measures such as encryption, secure authentication, and backup protocols, mandatory notification of significant incidents, and cooperation within a dedicated European Space Resilience Network. It also mandates risk assessments and risk-management plans covering the entire mission lifecycle, together with robust supply-chain risk management, including controls on software integrity and authenticity.
The proposal qualifies these rules as lex specialis vis-à-vis NIS2 for space operators that would otherwise fall under the category of essential or important entities. This choice avoids a dual compliance track that would generate more paperwork than actual security. The proposal also adds enhanced physical-resilience obligations beyond those in the CER framework, including access controls, perimeter protection, system segregation and monitoring, and geographic redundancy for critical ground assets.
The uncomfortable yet persuasive issue is cost, and cost is itself an argument
Some estimates suggest that operators may need to allocate up to 10% of their IT budgets to risk management in order to comply with the new framework. The European Commission, however, assesses the cost of a cyberattack as being roughly five times higher than the cost of the measures needed to prevent or absorb it.
This ratio shifts the debate away from formal compliance towards operational continuity. It also makes a stricter regulatory approach politically easier to justify, even if, at first glance, it appears as little more than an additional regulatory burden.