A White House champion for space cybersecurity has been missing for eight years, leaving commercial satellite vendors serving the U.S. government without enforceable standards.
Sam Visner, chair of the Space Information Sharing and Analysis Center, put it plainly at a recent George Washington University symposium: "If everyone's in charge, no one's in charge."
What's missing isn't a single cybersecurity standard for the commercial satellite operators that provide critical services to the U.S. government — communications, imagery, and position, navigation, and timing data. It's the convening authority that can force the agencies who buy those services to sit at the same table.
That authority used to live in the vice president-chaired National Space Council. The Council lapsed. With it, the interagency pull that produced Space Policy Directive 5, a September 2020 presidential memo and the first comprehensive policy on satellite cyber threats, has not been replicated.
Visner, a former senior U.S. official who now chairs Space-ISAC, the industry-government coordination body for space system threats, described the working gap at a panel hosted by GWU's Space Policy Institute and the Aerospace Corporation, a federally funded research and development center. His point, supported by two other former White House officials on the panel, was structural: cybersecurity standards for the commercial vendors serving federal agencies require someone with the standing to call those agencies together and resolve the turf disputes that arise when equally powerful players disagree.
"Interagency" here is the operative word. It means cross-agency policymaking, the kind of work that routinely gets stuck on bureaucratic turf disputes or personality clashes between equally senior officials. It cannot be done by a single department acting alone.
Under the first Trump administration, Vice President Mike Pence chaired the National Space Council and stood up the White House Space Cybersecurity Working Group, an interagency body tasked with aligning agencies that buy satellite services with the commercial vendors that supply them. The working group's first concrete product was Space Policy Directive 5, signed in September 2020, which directed agencies to work with commercial providers on threat information sharing, cybersecurity best practices, and the security of space-based positioning, navigation, and timing services.
Jaisha Wray, who worked on space policy at the State Department and the White House from 2018 to 2020 and is now at the National Telecommunications and Information Administration, described the working group on the panel as "a great collaboration" whose first win was "bringing together space people and cyber people." That cross-discipline convening is what she and others say the government has not replaced.
The National Space Council lapsed during the Biden administration. The working group's interagency pull dissipated with it, leaving no White House-level champion to do the work the working group had been doing.
Lauryn Williams framed the consequence more bluntly: "There is power in being able to bring [everyone] together. You need a champion in the interagency."
Pentagon-level work has not stood still. The Space Force's Space Systems Command has stood up the IA-Pre program, a commercial satellite communications cybersecurity assessment effort, as a step toward evaluating the security of vendors serving the military. But IA-Pre can grade a vendor's network; it cannot convene the National Oceanic and Atmospheric Administration, the Federal Aviation Administration, and the State Department into a single standards-setting body for a vendor base that serves all of them. That work requires a White House-level convening authority.
The new administration has not yet nominated a National Space Council chair or stood up a successor working group. As a result, the commercial satellite operators that provide critical services to the U.S. government continue to navigate roughly eight years of deferred standards work on a per-agency basis.
The precedent exists: a vice-presidential convening body with cross-agency standing, a dedicated cybersecurity working group, and a directive that gave agencies a shared playbook. The job is naming a sponsor with the authority to do it again.