Case study

Building the Space Cyber Range with the European Space Agency

As a Key Technology Partner of the European Space Agency, CybExer is building a dedicated Space Cyber Range where satellites and ground systems can be tested against realistic attacks before they reach orbit.


esa-space-cyber-range-1

Critical infrastructure increasingly depends on satellites. Communication, navigation, financial transactions, weather forecasting and the coordination of essential services all rely on space-based assets, and that dependence is deepening. It also makes them a target. As satellites and ground systems become more digitised, they face the same cyber threats as any other network, but with a crucial difference: a live mission cannot simply be patched and rebooted the way a corporate server can. The safest place to find and fix a weakness is before a system reaches orbit.

That need is driving the development of the Space Cyber Range, a project that brings CybExer together with the European Space Agency and a consortium of Estonian partners to build a dedicated environment for testing the cybersecurity of space systems. Signed in early 2025 and scheduled to open in Tallinn in 2026, it is one of the most ambitious steps yet to carry the discipline of cyber-range testing into the space domain.

A Key Technology Partner for the European Space Agency

CybExer, a NATO-awarded deep tech cyber range company, has been named a Key Technology Partner of the European Space Agency, leading the development of the new Space Cyber Range. The wider effort is delivered by an Estonian consortium that also includes Spaceit, CGI Estonia, Foundation CR14 and the University of Tartu, and it falls under ESA’s ARTES 4.0 programme, specifically its programme line for Space Systems for Safety and Security, known as 4S.

The contract was signed in Tallinn on 23 January 2025 by Laurent Jaffart, ESA’s Director of Connectivity and Secure Communications, and Silver Lodi, Management Board Member of Spaceit, which holds the agreement with ESA. Within the consortium, CybExer leads the cyber range development while the other partners bring satellite operations, systems integration, national cyber range experience and academic research.

The Space Cyber Range consortium. From left: Aare Reintam, Silver Lodi, Laurent Jaffart, Paul Liias, Kristiina Orm, Sille Kraam, Martin Hunt and Antti Tamm.

“Over the past five years, there has been a significant increase in cyberattacks, emphasising the growing risks for sectors such as energy grids, emergency responders, and other critical infrastructure dependent on satellite connectivity. Estonia’s proven leadership in cybersecurity makes it the ideal home for this facility.”

Laurent Jaffart, ESA Director of Connectivity and Secure Communications

From SatOpSim to the Space Cyber Range

CybExer already had a track record in the space domain before this project. In cooperation with Spaceit, the company had built a satellite operations simulator called SatOpSim, a fully virtual environment in which participants can simulate both attacking and defending a satellite mission. It is a real, delivered capability that predates the ESA partnership.

The Space Cyber Range is designed to expand that foundation: from a single satellite simulator towards an integrated, multi-purpose environment that draws on digital twins of the systems being protected, open to space operators, developers and cybersecurity teams across Europe.

The range and its users

When it opens, the Space Cyber Range is designed to provide a realistic, controlled and advanced simulation environment. In it, space operators, cybersecurity professionals and technology developers will be able to train, test and validate their solutions before cyber threats can affect a live mission, working against reproductions of satellite communications, ground-control interactions and the attack scenarios that could target either.

What that means in practice is easier to picture through the people who would use it. A satellite manufacturer could test the command-authentication controls on a new spacecraft design. A mission operator could rehearse the loss of telemetry from a satellite and practise recovering control. A security team could investigate a simulated intrusion through a ground station. A developer could validate a new secure communication component before it flies. A regulator or auditor could watch a standardised resilience assessment run from end to end. None of these rehearsals would touch a real mission.

By pulling capabilities that are usually scattered across separate tools into one integrated platform, the range is also set to offer something the sector lacks: a shared, repeatable way to gauge how ready a space system is, rather than a one-off test. Defining that shared benchmark, and building agreement around it, is part of what the project sets out to achieve. It is set to be the first dedicated facility of its kind, combining training and technology validation for space systems.

Threats specific to the space domain

Space has always been tied to critical infrastructure. Financial systems, military communication, telecommunications and power grids all lean on satellite services, so a successful attack in orbit can ripple far across everyday life. The threats are specific to the domain: attackers may jam signals, send unauthorised commands to guide or control a spacecraft, or inject malicious code to trigger denial-of-service conditions. At their most serious they can mean lost data, a shortened lifespan for a spacecraft, or the loss of positive control of a vehicle altogether.

Because none of this can be rehearsed on a live mission, an isolated range is essential. A dedicated environment lets operators and developers subject space systems to realistic attacks, safely and repeatedly, and share what they learn across the sector.

Regulation adds a further reason. Cybersecurity in space is a young field and its legal frameworks are still forming. A common environment in which systems can be assessed against recognised expectations has value well beyond any single mission. The range gives the sector a practical way to test and demonstrate resilience against those expectations, and to raise its security bar as the rules take shape.

Value across the space sector

For the space sector, the value is direct. Operators gain a place to rehearse incidents they cannot safely stage in orbit. Manufacturers and developers can prove new designs and components before launch. ESA and national programmes gain a common environment for raising security across the systems they depend on. And regulators and researchers gain a neutral setting in which resilience can be examined and compared. For CybExer, the partnership extends a track record that spans more than 60 countries and includes work with NATO into one of the most demanding frontiers in cybersecurity.

“This marks a major breakthrough in securing the future of space operations. With the increasing digitisation of space assets, cyber threats are no longer a theoretical risk, they are a real and immediate challenge.”

Andrus Kivisaar, CEO, CybExer

Securing space by design

The Space Cyber Range shows how the approach that has long protected terrestrial networks can be carried into orbit. By giving operators and developers a safe place to test space systems against realistic attacks, the project aims to make security a design principle rather than an afterthought. Scheduled to open in Tallinn in 2026, it gives Europe a shared foundation for keeping the systems societies depend on secure, before the threats ever reach the mission itself.