
“If someone ever claims they’ve finished implementing all the cyber, it’s nonsense – it’s a continually evolving problem.” That clear-eyed honesty runs through this entire conversation, recorded live at SmallSat Europe in Amsterdam, where Torsten Kriening sits down with Roger Patrick, Director of Sales and Business Development at TERMA.
TERMA sits right at the core of the operational chain – building satellite control and test systems that integrate with manufacturers and operators – which makes Patrick the ideal person to puncture a dangerous assumption: that the satellite is the prize and the ground is just plumbing. As he puts it, the plumbing is exactly what gets you access to the satellite. People talk about jamming and signal spoofing, but the real soft target is the terrestrial infrastructure: polluted software supply chains, abused user access rights, and all the familiar weaknesses of any IT system. A system is only as strong as its weakest link – and that link is usually on the ground.
From there, the conversation ranges across the questions that rarely make the slides: how to retrofit secure-by-design, DevSecOps and zero trust into existing systems without breaking them or the budget; what NIS2, Germany’s space security strategy and the coming EU Space Act mean for operators built on assumptions regulators may be about to retire; and the unglamorous reality that certification is fragmented across countries and standards.
Patrick is candid on scaling security across thousands of satellites – layered architecture, automated key management, and resilience that lets you cut a compromised ground station loose and keep operating – and on why zero trust has moved from recommendation to near-mandate, even if “100% zero trust” remains a utopian ideal.
He also tackles AI on both sides of the fight (penetration testing and productivity versus smarter attacks), the post-quantum threat and the NIST algorithms built to withstand it, and why none of this is a military-only problem: every asset in orbit is mission critical and worth protecting. His one ask for Monday morning? Think about security from day one — never as a bolt-on afterthought.
Sharp, practical, and refreshingly free of hype. Press play.







