2021/02/18 by Berenike Vollmer, Vollmer, Berenike
Engineering · Social Sciences · #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #Cybersecurity and Cyber Warfare Studies #FOS: Computer and information sciences #Military Strategy and Technology
paper · pdf · doi:10.48550/arxiv.2102.09674
openalex publication_date 2021/02/18 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
The North Atlantic Treaty Organizations (NATO) public-private Space Asset\nSupply Chain (SASC) currently exhibits significant cybersecurity gaps. It is\nwell-established that data obtained from space assets is fundamental to NATO,\nas they allow for the facilitation of its missions, self-defence and effective\ndeterrence of its adversaries. Any hostile cyber operation, suspending control\nover a space asset, severely impacts both NATO missions and allied Member\nStates national security. This threat is exacerbated by NATOs mostly\nunregulated cyber SASC. Hence, this thesis answers a twofold research question:\na) What are current cybersecurity gaps along NATOs global SASC; and b) How can\nNATO and its allied Member States gain greater control over such gaps to\nsafeguard the supply of NATO mission-critical information? An ontological field\nstudy is carried out by conducting nineteen semi-structured interviews with\nhigh-level representatives from relevant public, private and academic\norganizations. This research was undertaken in collaboration with the NATO\nCooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn, Estonia.\nThis thesis concludes that current cybersecurity gaps along NATOs SASC are\ncaused by cyber vulnerabilities such as legacy systems or the use of\nCommercial-Off-the-Shelf (COTS) technology. Inadequate cyber SASC management is\ncaused by hindrances such as misaligned classification levels and significant\nunderstaffing. On this basis, NATO should consider two major collaboration\ninitiatives: a) Raising Awareness throughout the whole of the NATO system, and\nb) Pushing forward the creation of regulation through a standardized security\nframework on SASC cybersecurity. Doing so would enable NATO and its Member\nStates to recognise cyberthreats to mission-critical data early on along its\ncyber SASC, and thus increase transparency, responsibility, and liability.\n