As space networks become prominent and have increased in scale, the security and protection of these systems has become more multi-layered than at any time. While space is not technically classed as critical infrastructure (CI), it is widely seen as critical infrastructure, given its importance both in everyday life and in defense. Add to that, with space now becoming more of a contested domain, the issue of space security is in the spotlight like never before.
With the pace of cyber-attacks on the increase, and attackers looking more to AI to attack valuable network assets, the onus will be on technology providers to provide the solutions to help keep space networks secure, both on the ground and the space side. Comtech has long been a key player in this area. However, as the landscape has become more nuanced, it means technology providers like Comtech need to provide solutions that adapt to this rapid pace of change. Via Satellite interviews Daniel Gizinski, president of Comtech’s Satellite & Space segment about space security and what a company like Comtech needs to do in order to provide next-generation security architectures.
VIA SATELLITE: In terms of cybersecurity, how are near-peer adversaries reshaping SATCOM vulnerability assumptions? Given what we have seen recently with AI model attacks, how is this threat landscape starting to change when it comes to space assets?

Gizinski: The threat environment has changed substantially over the last several years — not only in the number of attacks, but in their sophistication, scale, and speed. Satellite systems are increasingly attractive targets, and adversaries are looking across the entire architecture, from the space segment to gateways, terminals, management systems, and the terrestrial networks that connect them.
SATCOM also has a particular challenge because much of the infrastructure in service today was designed years or even decades ago. There are legacy protocols and architectures that were developed for a very different threat environment, often with an implicit assumption that access to the network itself established some level of trust. That is no longer a safe assumption.
AI further changes the economics of cyber operations. It can dramatically reduce the time and resources required to conduct reconnaissance, map networks, identify potential vulnerabilities, and adapt attacks. Activities that once required significant expertise and manual effort can increasingly be performed at machine speed and much greater scale.
That compresses the defensive timeline. We need architectures that can detect anomalous behavior, make decisions, isolate threats, and adapt in near real-time. The fundamental challenge is no longer simply building a strong perimeter. It is building systems that can continue to operate securely in an environment where we assume the network is being actively observed, probed, and potentially attacked.
VIA SATELLITE: Given some of the cyberattacks we have seen recently, how do you quantify the importance of real-time intrusion detection and zero-trust frameworks in deployed environments?
Gizinski: They are increasingly fundamental to mission assurance. If an attack can develop in seconds or minutes, discovering it 24 or 48 hours later means you aren’t protecting your network – you are just conducting a forensic analysis of an attack.
We need to be able to operate defenses at the speed of the threat. That requires better real-time detection & automated responses where appropriate, plus an architecture designed to contain a compromise rather than allowing it to propagate.
Zero-trust principles are an important part of that transition. Least privilege, continuous authentication and authorization, segmentation, and explicit verification can significantly reduce the ability of an attacker to move laterally through a network after compromising an individual component.
That is particularly important for satellite networks because many legacy architectures were designed around a perimeter-security model: once a device or user was inside the trusted network, it was implicitly given considerable freedom to communicate with other parts of the system. Moving toward zero trust changes that assumption. Trust becomes something that must be continuously established rather than something permanently granted based on where you sit in the network. That is both a technology transition and a mindset transition, and helping customers work through that evolution is an important part of what we are doing.
VIA SATELLITE: What is Comtech’s perspective on integrating layered cybersecurity directly into modems, terminals, and network architectures?
Gizinski: Cybersecurity cannot be something you add after the system has already been designed. It has to be an architectural requirement from the beginning and extend through every layer of the system.
At the hardware level, that means capabilities such as secure boot, signed software, authenticated updates, and mechanisms that establish confidence that the device operating on the network is actually the device you believe it to be. At the system level, it means designing around segmentation, identity, access control, encryption, monitoring, and the ability to update security capabilities throughout the product lifecycle.
Ultimately, the modem or terminal is part of the security architecture. It cannot simply be treated as a transport device sitting behind somebody else’s cybersecurity perimeter. In a modern network — particularly one supporting national security missions — every node has to contribute to the overall security posture.
VIA SATELLITE: How does this more digitized approach improve security posture?
Gizinski: There are several advantages. First, next-generation digital architectures can be designed around modern cybersecurity principles from the outset rather than inheriting assumptions from legacy analog or proprietary architectures.
That has been an important consideration in the development of our Digital Common Ground, or DCG, architecture. We have the benefit of lessons learned across the broader cyber ecosystem over the last decade, and we can incorporate those principles directly into the architecture. The transition toward digital intermediate frequency, or digital IF, is also important. It allows portions of the SATCOM infrastructure that historically relied on specialized interfaces and proprietary architectures to take advantage of mature Ethernet and IP-based networking technologies. That means we can increasingly leverage a much broader ecosystem of proven networking technology and security capabilities rather than reinventing those functions specifically for satellite ground systems.
Digitization does not automatically make a network secure — it can also create new interfaces that have to be protected — but it gives us a much stronger foundation for observability, automation, segmentation, orchestration, and ultimately a more adaptable security architecture.
VIA SATELLITE: We are seeing increased government spend globally when it comes to defense capabilities. The U.S. and Allied Forces’ are going to have a stronger need for secure satcom across land, air, sea, and space domains. How will Comtech’s systems support resilience, anti-jamming, and high-assurance links, as well as ensure mission continuity?
Gizinski: This is an area where Comtech has deep experience. The fundamental question is: how do you maintain communications in the most congested, contested, and operationally difficult environments? For U.S. and Allied Forces, assured communications means being able to exchange mission-critical information anywhere in the world, including when an adversary is actively attempting to disrupt or deny those communications.
There is no single technology that solves that problem. Resilience comes from layering capabilities. That includes waveform diversity, anti-jam techniques, multiple frequency bands, multiple satellite constellations and orbital regimes, and increasingly the ability to incorporate terrestrial communications paths alongside SATCOM. The objective is to eliminate single points of failure. If one satellite, constellation, frequency, gateway, or communications path becomes degraded or unavailable, the network needs alternatives.
We are increasingly seeing multi-path networking become central to that architecture. The system should understand what communications resources are available, select the appropriate path based on mission requirements, and dynamically move traffic when conditions change. That is defense-in-depth applied not just to cybersecurity, but to communications resilience itself.
VIA SATELLITE: How do you view the challenge of integrating terrestrial and satcom networks to maintain connectivity in denied environments?
Gizinski: A significant part of the challenge is architectural. You need to understand what traffic is mission-critical, what level of latency and bandwidth it requires, what security policies apply, and which communications paths are available at any given moment. From there, you need intelligence in the network that can evaluate those paths, prioritize traffic appropriately, and dynamically route it based on mission requirements and changing network conditions.
The challenge is that modernization does not happen overnight. Government and defense customers have enormous installed bases of equipment, much of which will remain operational for another five, 10, or 15 years. New architectures therefore have to coexist with legacy infrastructure while the transition occurs.
That makes interoperability and backward compatibility extremely important. The goal is not simply to design the ideal future architecture. It is to create a practical migration path that delivers new capabilities while preserving mission continuity throughout what will inevitably be a multi-year modernization process
VIA SATELLITE: We have been talking about software-defined satcom architectures for quite a while now. Where are we exactly when creating those architectures for major customers like the US government?
Gizinski: Software-defined capabilities are already operational and relatively mature in a number of areas. The more significant transition we are seeing now is the broader digitization and virtualization of the ground architecture.
That transition has accelerated over the last several years, but we should be realistic about the scale of the installed infrastructure. There are hundreds of millions of dollars — and in aggregate considerably more — of ground equipment deployed around the world on legacy architectures. Those systems are not going to disappear overnight.
What we are seeing is a progressive transition. Customers increasingly want architectures that are more software-defined, more interoperable, and less tightly coupled to a particular satellite or constellation. The technology is increasingly capable of supporting that vision, but deployment will happen incrementally as existing infrastructure reaches natural modernization points.
So I would characterize the industry as clearly moving in that direction, with meaningful deployments already underway, but still relatively early in what will ultimately be a significant architectural transformation.
VIA SATELLITE: How do you assess the movement toward software-defined radio (SDR) and virtualized ground systems?
Gizinski: Software-defined radio is quite mature for us. The majority of the systems we field today incorporate SDR principles, which gives us considerable flexibility to add waveforms, support new constellations, and adapt capabilities through software rather than requiring hardware replacement.
Virtualization is at a somewhat earlier stage. There is significant customer interest, and there are applications where it provides clear advantages, particularly in terms of scalability, orchestration, and the ability to deploy capabilities more dynamically.
For government customers, however, flexibility is only one part of the equation. Cybersecurity requirements, certification and accreditation, deterministic performance, latency, hardware dependencies, and operational repeatability all have to be addressed.
So I expect virtualization to continue expanding, but the transition will be workload-dependent rather than universal. The objective should not be virtualization for its own sake. It should be putting each function in the environment that provides the right combination of performance, security, resilience, and operational flexibility.
VIA SATELLITE: In our Thursday Morning Conversation, you spoke about how you can’t keep changing ground systems every time there are new types of constellations and satellites. Where is Comtech with this vision of providing more interoperable, more flexible technology solutions?
Gizinski: One of the principles that has guided Comtech for a long time is that we build systems to be deployed and operated, not technology demonstrations. In many cases, our products remain in the field for 10, 15, or 20 years or longer.
That means we have to design with enough processing capability, architectural flexibility, and software extensibility to accommodate requirements that may not even exist when the hardware is initially deployed.
The SLM-5650 family is a good example. That platform has been in the market for more than 15 years, but we have continued to expand its capabilities through software, waveform, and security enhancements. More recently, we added support for SES’s mPOWER system while maintaining the installed base and the capabilities our customers already rely on.
We have carried that philosophy forward into the DCG product family. The goal is to decouple the lifecycle of the ground infrastructure from the lifecycle of any individual satellite constellation. Customers should not have to replace their ground architecture every time a new space architecture emerges.
That requires interoperability, open interfaces, software-defined functionality, and sufficient compute and networking headroom to evolve over time. Ultimately, we want the ground system to become an adaptable platform rather than a collection of vertically integrated systems tied to individual satellites

VIA SATELLITE: What is Comtech’s strategy of embedding security, flexibility, and software updates in its hardware/software product lines? How do software-defined modems and waveforms improve survivability and ease security patching?
Gizinski: We increasingly view adaptability and cybersecurity as elements of the same resilience strategy. Software-defined modems allow customers to support different waveforms, constellations, and operating modes across LEO, MEO, and GEO without necessarily changing the underlying hardware. That creates communications diversity and gives operators alternatives when a particular link, constellation, or operating environment is degraded or denied.
But survivability also depends on the integrity of the platform itself. In a modern conflict, a communications system without the right security architecture is ultimately not fit for purpose. Capabilities such as secure boot, authenticated software, controlled access, secure update mechanisms, and security-first system architecture have to be fundamental product requirements.
The software-defined model also changes how we think about the product lifecycle. A product is not finished the day it ships. Threats evolve, new vulnerabilities are discovered, new constellations become available, and adversaries develop new techniques.
We therefore need the ability to continuously improve deployed systems—adding capabilities, addressing vulnerabilities, updating waveforms, and adapting security controls without requiring customers to replace the underlying hardware every few years. That ability to evolve the installed base is becoming an increasingly important component of mission resilience.
VIA SATELLITE: What do you see as the importance of blending GEO, MEO, LEO, and commercial satcom services for military missions? How can you support both legacy and next generation satellite systems simultaneously?
Gizinski: It comes back to eliminating single points of failure. If a mission becomes dependent on a single orbit, constellation, frequency band, or service provider, you have created something an adversary can potentially target or deny.
A multi-orbit architecture provides diversity. GEO, MEO, and LEO systems each have different performance characteristics and different strengths. Commercial and government-owned capacity can also play complementary roles. The objective is to make those resources available as part of a broader communications architecture rather than forcing the operator to think about them as isolated networks. Our role is to make the ground infrastructure as flexible as possible so customers can take advantage of that diversity.
Comtech has products deployed in more than 100 countries and decades of experience supporting systems that remain operational for long periods of time. That has taught us that backward compatibility matters enormously. You cannot introduce a next-generation capability in a way that suddenly makes a large installed base obsolete.
We design with that reality in mind: enable new constellations, waveforms, and architectures while preserving interoperability with the systems customers already have in the field.
VIA SATELLITE: Given the trends we are seeing in the development of multi-orbit networks, how will Comtech help secure multi-orbit networks, key management, and data integrity across disaggregated systems?
Gizinski: Multi-orbit and disaggregated architectures force the industry to reconsider where the security boundaries actually exist.
Historically, cybersecurity was often built around a relatively well-defined perimeter. You protected the network boundary and placed a considerable amount of trust in the devices and users operating inside it.
That model becomes much harder to sustain when the architecture spans multiple satellite operators, orbital regimes, gateways, cloud environments, terrestrial networks, and geographically distributed terminals.
Zero trust provides a much more appropriate model for that environment. Instead of assuming that something is trusted because it is inside a particular network boundary, identity and authorization have to be established at the device, user, application, and transaction level.
That affects how we think about modems, terminals, satellites, key management, data integrity, and the interfaces between systems. Security has to persist as traffic moves across those boundaries.
We are working closely with customers on that architectural transition because it is not simply a matter of adding another security appliance. It requires reconsidering the trust model of the network itself and designing each component to participate in that model.
VIA SATELLITE: Finally, the world is changing dramatically. Most now see space as a contested domain. The launch of AI-based attacks on space assets seems only a matter of time. How is Comtech adapting and evolving to provide secure, flexible ground systems that military customers will need going forward?
Gizinski: For us, it starts with the way products are conceived and engineered. Several years ago, we began restructuring our engineering approach to put cybersecurity much earlier in the product-development process. Historically, space and communications systems were primarily driven by disciplines such as RF engineering, signal processing, mechanical design, power, and networking. Cybersecurity was sometimes treated as a downstream requirement—something addressed once the fundamental architecture had already been established.
That approach is no longer sufficient. We now treat cybersecurity as a fundamental mission requirement alongside RF performance, availability, reliability, and usability. Cybersecurity needs a seat at the table when the architecture is being defined, not after the product has been designed. That changes engineering decisions throughout the system: how devices establish trust, how software is authenticated, how updates are delivered, how interfaces are exposed, how systems are monitored, and how a compromised component can be isolated without unnecessarily disrupting the mission.
There is also an important human dimension. The most secure system in the world has limited value if it is so difficult to operate that users circumvent its protections. We have to balance strong security with usability and operational realities. Ultimately, that is the transition we have been making at Comtech: moving from thinking about cybersecurity as a feature or compliance requirement to treating cyber resilience as an inherent element of mission performance. In the threat environment our customers are preparing for, secure communications and resilient communications are increasingly the same thing.








