Illustration -Cybersecurity and satellites.
Illustration -Cybersecurity and satellites. Credit: SpaceQ/AI-generated

Canadian cybersecurity firm Dominant Information Solutions Canada (DISC) is working on a new way to help protect satellites as part of a European Space Agency (ESA) program. 

The Ottawa-based company, which recently expanded its business on space security and satellite cyber defences, is the first Canadian company participating in the ESA’s Cybersecurity Makerspace program. It will be working alongside German space systems company OHB SE to create new methods and tools to help protect satellites from hacking and disruption by both non-state and state actors.

SpaceQ reached out to Marc Kneppers, Vice-President of R&D at DISC, to learn more about the company, space-based cybersecurity, and the ESA project.  

DISC and cyber threats

A glance at DISC’s somewhat sparse website conveys no small amount of mystery regarding the company and its services.

DISC describes itself as a “security company” that routinely helps companies in dire circumstances, saying that “in most cases, when you need us, something has occurred that is not good for your business.” A quick glance reveals very little information about their methods and tools, with references mostly to “cyber breach and incident response support”, along with some legal work in support of their clients. 

Notably, DISC is also very clear that they will never reveal who those clients are. Where other companies might have case studies, DISC only says “disclosure of our clients is something that goes against our corporate policies. We rely on referrals for business.” 

Kneppers said that, yes, that’s the policy, and that the sensitive situations that their clients find themselves in require that DISC “respect that privacy and the position they’re in at that time.” He confirmed that they do work like “incident response, forensics, hardware and software security assessments…and then niche work like legal support.”

The company is often called on to provide expert legal testimony, according to Kneppers, though again he couldn’t go into details. 

Most of DISC’s personnel are former members of Canadian security agencies, Kneppers said, like DND, CSIS or the CSE. The founder and CEO, Nicholas Scheurkogel, had a fourteen-year career focused on cybersecurity at the Department of National Defence before moving into the private sector. His team are no strangers to the idea of working quietly on serious problems. 

Kneppers, by contrast, came to DISC from a career at Telus, where he learned firsthand how much of a challenge cybersecurity can be. He joined Telus in the mid-1990s during the rise of the Internet, and said that he had to grapple with all manner of security issues: “3G/4G/5G, AI, Enterprise networks, acquired businesses, Quantum Key Distribution, ..  the whole show.” 

That time at Telus led to a hands-on education in cybersecurity, and Kneppers said that “what may be surprising to some people is that I don’t think I had any significant training in cyber security.” He said that he took some training courses during his time at Telus, but his hands-on education meant that “the training was more supplemental than foundational.” 

DISC and security in cyberspace

Kneppers’ does have an advanced degree, however: a Master’s in Astrophysics. And when Scheurkogel decided to expand DISC into space cybersecurity, Kneppers said he was brought in to “lead that space initiative” and to “see if we could commercialize it.” 

Cybersecurity in space is becoming an increasingly pressing concern. “Satellite companies aren’t talking about the specific breaches yet,” Kneppers said, but it is happening; not only with satellites as targets but with ground stations as well. Kneppers mentioned “the ViaSat hack by Russia at the start of the Ukraine war” as a prominent example, where the ViaSat ground stations were hacked to disrupt field communications during the opening of the war. 

Kneppers believed that this wasn’t unique to ViaSat, but was a straightforward exploitation of common VPN vulnerabilities that were “a basic IT problem…nothing fancy.” If it happened to ViaSat, it could happen to others, and could have devastating consequences for space-based communications. 

And, in turn, Kneppers said that he has “spoken to companies that gather industry specific intelligence about hacker activity” that have revealed “an increase of incidents in the space industry.” Space can often be seen as “a technology domain that feels a bit untouchable,” he said, yet is “becoming heavily interconnected and reachable”, and “with an increasing number of “new use-cases with minimal protection.” 

This “reinforces the need for multiple layers of cyber security,” Kneppers added, one that “requires peer support and input from critical infrastructure oversight organizations.” He mentioned Space ISAC as a key point of collaboration, and one that DISC has already joined. 

While this is a problem, it also presents an opportunity for cybersecurity companies like DISC. So when when DND put out an IDEaS challenge (Innovation for Defence Excellence and Security) intended to find ways to “defend and protect satellites from natural and artificial threats,” Scheurkogel and DISC seized the opportunity to help build defenses against these threats to space-based infrastructure and brought Kneppers on board.

DISC, Kneppers, and Scheurkogel were ultimately successful, and DND agreed to fund the project in 2020. DISC ended up getting their chance to develop a space cybersecurity tool. 

Space security eClypse

That IDEaS-funded tool that DISC developed is called eClypse

Kneppers said that part of this effort to deal with threats to space-based infrastructure needs to be “detecting space events to contribute to collaborative information sharing.” That’s the role of eClypse. eClypse is designed to be integrated at a hardware level with a satellite, and to carefully watch out for signs of intrusion. The system will perform “cyber intrusion detection on the actual satellite,” Kneppers said, and then “sends security-specific telemetry to the ground where it can be analyzed by the ground station.” 

According to DISC, some of the signs it looks for can include “alteration of onboard software,” “hijacking of processors,” “installation of covert software or command & controls” and “changes to critical firmware or onboard software. This is, Kneppers said, “the kind of information that a collaborative group might exchange as early-warning indicators of breach.”

Kneppers did not give further details on eClypse, but said that these kinds of tools have to be flexible; that “the defender’s job is to build very broad defenses that may not be focused on a specific type of attack.” But though the challenges are somewhat similar to terrestrial cybersecurity—Kneppers said “the differences between space and terrestrial are relatively small” in terms of the defenses, there are unique constraints that they face when developing systems like eClypse.  

Kneppers noted that “every satellite has a finite limit of power, space, and cooling,” and that you always “have to make the case that the benefit justifies the extra cost and launch weight” for hardware solutions like eClypse. Even with software solutions, a satellite “cannot afford to be doing a lot of extraneous calculations” owing to compute and bandwidth restraints. 

The still-in-development eClypse technology received a TRL 6 space readiness rating in early 2024, as well as winning the Airbus Challenge for “Boosting Responsible Commercialization of Space” in October of 2024. In the announcement at that time, DISC said in their release that it will be “working towards bringing eClypse to a TRL 8 to demonstrate its effectiveness in space.” 

DISC in the ESA Cybersecurity Makerspace

The ESA’s Cybersecurity Makerspace project is intended to “provide a platform for industry, research institutions, and new entrants to implement, and test small-scale technical activities relevant to the space and Satcom cybersecurity domain.”

The project is focused on “the practical evaluation of emerging technologies and methods in areas such as secure communications, AI-assisted analysis, vulnerability assessment, software security, and anomaly detection.” Kneppers said that the goal was “to create a contract structure that allowed new ideas and new vendors to enter their procurement system.”

(Kneppers added that any opinions or statements he’d made to SpaceQ were his own, and did not reflect the positions of the ESA.)

This is a solid fit for DISC, and it isn’t a surprise that they sought to get involved. As Canada isn’t part of the European Union, however, some work had to be done in order to have DISC participate in the makerspace. 

Part of it was through their collaboration with OHB SE. Kneppers said that OHB will be “acting contractor and project manager,” as well as “providing some material related to a production satellite of theirs” that will be useful for threat assessment. OHB will be the actual ESA contractor, and will in turn subcontract to other companies, including non-EU ones like DISC. Kneppers said that they are “excited to work with OHB” on this project, as “it gives us access to their expertise and…high-end knowledge about satellites.” 

The other key player was the Canadian Space Agency(CSA). Kneppers explained that the biggest reason why DISC was able to participate in the Makerspace was the CSA’s investment in the ESA Advanced Research in Telecommunications Systems (ARTES) program, which allows Canadian organizations to bid on ESA work. So, Kneppers said, they needed to get “an explicit letter of support from the CSA indicating that they approved the use of the money towards the cybersecurity makerspace program.” Kneppers briefed the CSA on their idea, they evaluated it, and then approved it and sent their approval to the ESA. 

With both the CSA and OHB on board, as well as the ESA, DISC could get started on their project. 

DISC’s satellite security framework

That Makerspace project isn’t eClypse, however, but a “satellite threat assessment framework.” According to DISC’s announcement, their project “focuses on creating a principles-based threat assessment framework that can be applied across satellite types, from commercial off-the-shelf small satellites to bespoke mission-critical platforms.” 

The framework, DISC said, “analyzes information flows, identifying potential corruption points in data streams including GPS positioning, command telemetry, and sensor imagery.” 

Kneppers gave more details. 

He said that DISC wanted “to threat-model a series of satellites and then see if we could create a generalized framework that would streamline the assessment of security for newly procured satellites.” To do that, Kneppers said, DISC will “take two satellites that represent, somewhat, two bookends of satellite maturity and capability”: one purchased from the open market, and one that’s a customized OHB satellite. “Our work,” he said, “is to do a threat assessment of each and determine what we think are the top areas of weakness.” 

While these initial assessments will largely be manual, Kneppers is hoping that it can be both automated and standardized to at least some extent, as “we think that there are similarities across the ecosystem despite the high level of customization.” He believes that they can create a framework that “is semi-automated” and that “gets you to an 80% evaluation of the risk of some new satellite.” That would benefit a wide variety of builders and operators, and would “open up satellite procurement to a larger swath of the market” by minimizing cybersecurity risks. 

“This Makerspace project,” Kneppers said, “will cover the satellite assessment and framework creation and maybe some of the automation, which we can then finish on our own.” He added that “we’ve got the program for a year,” and that “we’re taking about 6 months per satellite roughly speaking.” 

The two open source frameworks that they’re drawing on for the evaluations are the American “Sparta” framework and the ESA’s “Space Shield.” Each is a “catalog of attacker techniques and objectives” that are somewhat different in how they approach the threats at various phases of a satellite’s life cycle, and (Kneppers discovered) very different in how they model an attacker’s desired outcome. 

Sparta is more focused on the threat of destruction and degradation, while Space Shield includes data corruption and integrity attacks that could be used for (say) a ransomware attack. Nevertheless, DISC is aiming to incorporate both their framework, so as to provide more effective defences.  

The final framework, Kneppers said, could ideally become a report that says “here are the five areas of weakness, and here are the six things you can do about it.” But he acknowledged that it may become quite a bit more complex than that—especially as the current documentation for the satellites they’re studying feature “a lot of detailed descriptions about voltages and how things work, but very few descriptions about how to authenticate a command.” There may be a lot more work to be done, and a lot of needed detail to be added.

Once they’ve finished the year of ESA work, whatever shape it takes, Kneppers said that they’ll “have the framework,” and will do verification with OHB engineers “that we’re on the right track and we have some confidence in it.” Then they’ll present their results to the ESA, along with some analysis on frameworks like Sparta and Space Shield.

After that’s done, the goal is to “take that result and create the automated tool that might simplify the entire process and enable new entrants into space to make good security decisions as they build.” 

How that tool works, and exactly what it does, is something that the rest of us may never learn. In turn, the proof of its effectiveness may be in the intrusions and corruptions that we don’t experience. An appropriate outcome for this quiet cybersecurity company with its secret client list, where every one of those events that didn’t happen may be the best possible proof of a job well done.


From the archives: The Emerging Space Cyberwarfare Theatre – Space Quarterly Magazine, March 2013

Craig started writing for SpaceQ in 2017 as their space culture reporter, shifting to Canadian business and startup reporting in 2019. He is a member of the Canadian Association of Journalists, and has a Master's Degree in International Security from the Norman Paterson School of International Affairs. He lives in Toronto.

Leave a comment