Satellites
LEO platforms across the constellation, with their payloads and critical subsystems.
Monitoring, protection and intelligent operation of the entire LeonAeroSpace space infrastructure from a single control centre.
The nerve centre overseeing the full infrastructure: from the satellite in orbit to the link reaching the customer.
LEO platforms across the constellation, with their payloads and critical subsystems.
Earth stations that open and close the contact windows with each satellite.
Entry points into the terrestrial network, including the Benavides de Órbigo teleport.
Operations centre that issues telecommands and verifies the health of the fleet.
Transport, routing and segmentation of traffic between the teleport and customers.
Management, analytics and customer portal services deployed on private cloud.
Ka- and Ku-band uplinks and downlinks, monitored continuously against interference.
Optical inter-satellite links that route traffic without returning to the ground.
5G core and non-terrestrial network functions that serve the end user.
Industrial systems for antennas, power supply and climate control across the sites.
Technical rooms hosting processing, storage and backup for the whole platform.
Each capability covers a different surface of the service, and all of them share one console and one incident flow.
Continuous surveillance of the constellation and the ground segment, every day of the year.
Security event correlation to identify hostile activity against the infrastructure.
Comparison of each subsystem behaviour against its expected nominal pattern.
Models that rank alerts and filter out false positives before they reach an analyst.
Full cycle of logging, triage, containment and documented closure for every incident.
TT&C telemetry analysis to detect in-orbit degradation at an early stage.
Spectrum monitoring to locate interference, jamming and unauthorised emissions.
Ephemeris tracking and conjunction risk assessment to preserve fleet integrity.
Cryptographic protection of the link and of telecommands between satellite and control centre.
Playbooks that carry out containment in seconds without waiting for manual action.
The whole service chain is instrumented: every node emits telemetry and every link is watched end to end.
Reference indicators for the constellation and the ground segment, updated continuously from the control centre.
Threats specific to the space domain alongside conventional IT ones, ranked by operational criticality.
Forged GNSS signals that induce position and timing errors across the platform.
Deliberate emissions that saturate the link and degrade the capacity of the beam.
Unauthorised access to the systems that drive the tracking antennas.
Malicious code introduced into ground segment or teleport servers.
Misuse of credentials to reach restricted operations consoles.
Saturation of network services and the customer portal through massive traffic.
Alteration of housekeeping data to mask the real behaviour of the satellite.
Illegitimate telecommands seeking to change in-orbit configuration or attitude.
Third-party emissions, intentional or not, overlapping the assigned frequencies.
Exploitation of the services and containers that support platform management.
Eight steps between the first signal and the lesson learned. Automated stages run without waiting for an operator.
Space and ground segment sensors register the first anomalous indicator.
The SIEM cross-references events from different layers into a single case.
The analyst assigns severity, scope and priority based on the impact on service.
The SOAR runs the matching playbook and gathers evidence with no manual input.
The affected element is isolated to stop the incident from spreading further.
Nominal service is restored and the integrity of every subsystem is verified.
The timeline, root cause and actions taken during the incident are documented.
Findings are fed back into detection rules and into the existing playbooks.
Models consume telemetry, logs and RF traffic to anticipate failure before it degrades the service.
Inputs
Outputs
RF interference, an intrusion attempt and rising latency. This is how it is correlated, contained and kept in service.
A third-party emission overlaps the service band over north-west Spain.
An attacker tries credentials against the console of a Ground Station.
Average link latency doubles and starts affecting user 5G traffic.
The SOC links the interference, the failed access and the degradation as one case.
A coordinated attack on the ground segment and the RF link is confirmed.
The playbook blocks the source of the access and isolates the compromised station.
Traffic switches to a clean frequency and to another available ground station.
Latency returns to nominal values and no customer session is lost.
The satellite 5G network stays in service while the incident is documented.
Space infrastructure and 5G connectivity, engineered in Spain. Let’s talk about your case: home, business, public administration or defence.