WASHINGTON, D.C. – U.S. Senator Gary Peters (MI), Chairman of the Homeland Security and Governmental Affairs Committee, reintroduced bipartisan legislation that would require the Cybersecurity and Infrastructure Security Agency (CISA) to help protect commercial satellite owners and operators from disruptive cyber-attacks. Commercial satellites provide data and information used for navigation, agriculture, technology development, scientific research, and more. Critical infrastructure systems involved in operating networks that control pipelines, water, and electric utilities are also heavily reliant on commercial satellites. Peters’ legislation would help ensure these systems are secure from cyber-attacks that could significantly impact services that are essential to our national and economic security. Peters introduced similar legislation last Congress that advanced in the Senate.
“We’ve already seen the impacts of attacks on satellite systems by our adversaries abroad, and the potential effects on our lives and livelihoods could be catastrophic if American systems were similarly attacked,” said Senator Peters. “This bipartisan bill will ensure that commercial satellite owners and operators have the tools and resources they need to strengthen their cybersecurity defenses.”
“Nearly every industry uses commercial satellite networks to provide essential services, but the destruction or disruption of these networks could be used against our national security interests,” said Senator Cornyn. “This bipartisan piece of legislation directs CISA to publish voluntary cybersecurity best practices for companies that own these satellites and ensure our most critical infrastructure is secure against foreign cyber threats.”
Experts have shown increasing concern that commercial satellite hacks could have dire economic and security consequences. The Department of Defense has also raised concerns about this threat and recently sponsored a competition for white hat hackers to attempt breaching an active satellite. Last year, it was reported that the Russian government was behind a cyber-attack on an American-based satellite company, which provides broadband services to Europe, in order to disrupt Ukrainian military communications at start of the invasion. As commercial satellites become more pervasive, hackers could shut satellites down, denying access to their service, or jam signals to disrupt electric grids, water networks, transportation systems, and other critical infrastructure. Peters’ legislation will ensure the United States is prepared to address these threats as malicious hackers increasingly target commercial satellite systems.
The Satellite Cybersecurity Act will require CISA to consolidate voluntary satellite cybersecurity recommendations – including guidance specifically for small businesses – to help companies understand how to best secure their systems. Additionally, the bill requires CISA to develop a publicly available, online resource to ensure companies can easily access satellite-specific cybersecurity resources and recommendations to secure their networks. The legislation will also require the Government Accountability Office to perform a study on how the federal government supports commercial satellite industry cybersecurity. It will ensure a better understanding of how network vulnerabilities in commercial satellites could impact critical infrastructure. Finally, the bill also requires the National Cyber Director and the National Space Council to develop a strategy to increase coordination across the federal government to address cybersecurity threats to these systems.