{"id":48775,"date":"2025-07-25T00:16:16","date_gmt":"2025-07-24T16:16:16","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/three-years-post-ka-sat-attack-viasat-exec-talks-lessons-learned-on-cybersecurity-posture\/"},"modified":"2025-07-25T00:16:16","modified_gmt":"2025-07-24T16:16:16","slug":"three-years-post-ka-sat-attack-viasat-exec-talks-lessons-learned-on-cybersecurity-posture","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/three-years-post-ka-sat-attack-viasat-exec-talks-lessons-learned-on-cybersecurity-posture\/","title":{"rendered":"Three Years Post KA-SAT Attack, Viasat Exec Talks Lessons Learned on Cybersecurity Posture"},"content":{"rendered":"<\/p>\n<p><strong>Viasat<\/strong> continues to be in the news when it comes to cybersecurity. Last month, the company confirmed a report of \u201cunauthorized access\u201d after&nbsp;Bloomberg reported&nbsp;the company was one of the victims in the Salt Typhoon hack against telecommunications providers.<\/p>\n<p><em>Space Security Sentinel<\/em> (<em>S3<\/em>) recently interviewed Phil Mar, VP\/CTO of Engineering for Viasat Government, about the company\u2019s cybersecurity posture. This interview was conducted before the reports of Viasat being impacted by Salt Typhoon, so there are no extra details related to this. However, it offers insight into how the operator is adapting its strategy to emerging cyber threats, three years after the attack on the KA-SAT ground network.<\/p>\n<p><em>[This feature was published exclusively for Space Security Sentinel, a new cyber newsletter from the teams at Via Satellite and CyberSat. Learn more and subscribe here]<\/em><\/p>\n<p>After the Salt Typhoon report, Viasat said in a statement the operator and a third-party cybersecurity partner investigated a report of unauthorized access through a compromised device. \u201cNo evidence was found to suggest any impact to customers,\u201d Viasat said.<\/p>\n<p>The Salt Typhoon hack last year involved Chinese state-sponsored hackers infiltrating U.S. telecommunications companies, including internet service providers. Viasat said it is engaged with government partners in its investigation and not able to provide more details at this point. \u201cViasat believes that the incident has been remediated and has not detected any recent activity related to this event,\u201d the company said.<\/p>\n<p>Mar told <em>S3<\/em> that threats are continuing to evolve and change, both in terms of the sophistication of attacks and the overall strategies and methods being used. Adversary capabilities are becoming more advanced, but more traditional cyberattack methods are still being used as well, he said.<\/p>\n<p>Mar described Viasat\u2019s approach as pursuing security by design, meaning it continuously evaluates the network technologies and solutions it uses and deploys through the lens of how they fit together to achieve a secure systems design.<\/p>\n<p>\u201cAs we continue to face attackers and see new attack methods or strategies, we\u2019re not only able to continue exercising or practicing our cybersecurity response capabilities but we\u2019re also able to use the insights from our experience. The ability of our security team to engage as active cybersecurity practitioners across our networks is also what allows us to continue to enhance our secure by design foundation, effectively improving network hygiene to protect against the latest attacks,\u201d Mar says.<\/p>\n<h3><strong>AI and New Cyber Threats <\/strong><\/h3>\n<p>While AI is playing an increasing role across the technology landscape, Mar says there is no evidence that attacks to Viasat\u2019s network have used generative AI at this point. He says AI is likely used by adversaries to identify security issues and vulnerabilities.<\/p>\n<p>\u201cAn attacker could use AI tools to conduct an analysis of the target network to identify or uncover potential vulnerabilities and potentially understand how effective or ineffective different attack methods are likely to perform against that network,\u201d he says.<\/p>\n<p>From a cybersecurity standpoint, Mar believes AI will impact both attackers and defenders. He says attackers will still have an asymmetric advantage in that they often only need to find one way in, while defenders will have to defend all methods against attack.<\/p>\n<p>\u201cAI does not change this but instead speeds up the pace of both sides with this same challenging asymmetry. For an attacker, AI could be used to identify vulnerabilities and service as a faster roadmap for outlining an attack strategy,\u201d he says.<\/p>\n<p>One notable challenge Mar sees is the rapid increase of AI features into software tools. \u201cWhile these tools can certainly be helpful, users can unknowingly exercise AI features that cause sensitive data to be stored in less than secure cloud infrastructure.&nbsp;Some of the sensitive data could even include discussion of a network architecture\u2019s potential vulnerabilities. Sophisticated adversaries can intrude such cloud infrastructure to learn about those vulnerabilities,\u201d he says.<\/p>\n<p>Viasat continues to see different attack methods, but Mar says that recognizing the trends in adversary strategies is just as important.<\/p>\n<p>\u201cWe\u2019ve seen cyber attackers going through certain types of tactics and our cyber operations team is now able to recognize many attacks as part of a pattern in a bigger, sometimes longer-term strategy we\u2019ve seen before, then we\u2019re able to use that insight to reinforce our network defenses,\u201d he says. \u201cWhen an adversary shows their hand, we have seen their strategy and multiple tactics behind them. As we\u2019ve seen this occur with more frequency, we have increased our ability to recognize those strategies and, in turn, our ability to effectively counter and mitigate those tactics.\u201d<\/p>\n<p>Mar says as a result of this, those adversaries can no longer use those longer-term strategies because Viasat has taken control by implementing the procedures and network mitigations to counter those things.&nbsp;\u201cAlso, it\u2019s likely because of our ability to counter and mitigate the effectiveness of these cyber-attacks that we\u2019re also seeing adversaries revert to more ad-hoc, brute force approaches to disruption, such as engaging in RF interference or jamming attacks. These types of attacks require different mitigations, and our team has effectively mitigated these efforts,\u201d he adds.<\/p>\n<p>In terms of a concern going forward, Mar highlights false attribution \u2014 where adversaries frame other adversaries for harm.<\/p>\n<p>\u201cWe\u2019ve already heard speculation that this has occurred in certain cases, but with all of the interest and news coverage around cyber attacks, it can be very difficult to confidently attribute with ground truth,\u201d he says. \u201cI suspect we will likely see increasingly more ambiguity around attribution in the future.\u201d<\/p>\n<h3><strong>Three Years Post KA-SAT Attack <\/strong><\/h3>\n<p>Of course, the recent news regarding Viasat and Salt Typhoon is not the first time the company has made news in cybersecurity. In 2022, Viasat was famously the subject of a targeted denial of service attack on the KA-SAT satellite network in Europe just ahead of Russia\u2019s invasion of Ukraine. Mar says that the main lessons Viasat identified from KA-SAT event weren\u2019t all technical. One of the first lessons learned was that organizations need to practice incident response and the need to go beyond technical simulations and table-top exercises.<\/p>\n<p>\u201cIncident response tends to be a neglected area of preparedness, often only including a smaller technical team and not incorporating the other departments\/parts of the organization that would truly be involved in a holistic response situation. Ideally, simulations should be designed to engage all relevant stakeholders, allowing for a shared understanding of roles, responsibilities, and communication protocols for every part of an organization\u2019s response effort,\u201d he adds.<\/p>\n<p>The attack also showed the importance of information-sharing with U.S. Department of Defense, intelligence and global government agencies and industry groups like the Commercial Integration Cell, National Defense ISAC and the Space ISAC, as well as the importance of actively maintaining network security hygiene. Having the foundational security hygiene in place is a way of forcing adversaries to seek out and be able to execute something more sophisticated, he admits.<\/p>\n<p>After the KA-SAT attack, the most significant change Viasat made was taking full network operations control from the third-party partner that was operating the network at the time under a transition agreement. This shift to take control of network operations has allowed Viasat to directly implement several updated security protocols\/applications that are now in place.<\/p>\n<p>Viasat also strengthened segmentation on the network. The network already had segmentation among users, but it has identified ways to reinforce the segmented structure to enhance protection, especially for government services.<\/p>\n<p>\u201cAnother significant thing we did was replace the entire network ground segment \u2013 as that was a key area of vulnerability that allowed the adversary to gain access to network. We\u2019ve also taken additional measures to implement stronger controls\/restrictions to safeguard administrative access to the modem management areas of the network,\u201d adds Mar.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Viasat continues to be in the news when it comes to cybersecurity. Last month, the company confirmed a report of \u201cunauthorized access\u201d after&nbsp;Bloomberg reported&nbsp;the company was one of the victims in the Salt Typhoon hack against telecommunications providers. Space Security Sentinel (S3) recently interviewed Phil Mar, VP\/CTO of Engineering for Viasat Government, about the company\u2019s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":46668,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-48775","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/48775"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=48775"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/48775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/46668"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=48775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=48775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=48775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}