01
ANALYTICSASSETSSERVICESSEGMENTSENVIRONMENTSMETEORSTORMFRAMEWORK
SPACE IS NO
LONGER A SANCTUARY

Welcome to orientation. You have joined Kestrel Orbital, a global commercial satellite operator whose three defending departments each describe the platform in their own words, and that gap is where missions and audits are lost. You are here to build and lead the department that closes it: Space Cybersecurity Operations and Resilience (SCOR).

One taxonomy
Controlled names for every platform element.
One ontology
The parent chain that relates them.
Five functions
Threats, attack paths, detections, response, resilience.
Pentagon of Pain
Five mastery areas that raise adversary cost.
3 checkpoints + assessment
Five questions each, then ten at 80%.
You leave ready for Day 1
The telecommand path decomposed: 44 elements.

One function a day for five days. First, the standard you will be held to.

METEORSTORM OVERVIEW
01/20
02
Day Zero

THE THREE MANDATES YOU'RE FOCUSED ON

You will build and lead Kestrel Orbital’s new department, Space Cybersecurity Operations and Resilience (SCOR), toward resilient cyber operations. It exists to meet three mandates of equal weight: Executive Order 14144 (United States), the NIS2 Directive (Europe), and Kestrel Orbital’s own mandate to open an information-sharing channel with the Space Information Sharing and Analysis Center (Space ISAC). They set your scope and the bar SCOR is judged by, and reaching resilient cyber operations is how you meet all three at once. Miss one and the department fails.

United States · binding now

Executive Order 14144 (January 2025): protect command and control of the space system. Encrypt commands, protect their integrity, authenticate their source, reject unauthorized attempts.

United States · Federal mandate

Executive Order 14144

Strengthening and Promoting Innovation in the Nation's Cybersecurity. Signed 16 January 2025. Published Federal Register Vol. 90, No. 11, 17 January 2025.

Most of this order is about federal software, cloud, and identity. One subsection is about you. Section 3(e) tells the Department of the Interior, the Department of Commerce, and NASA to review civil space contract requirements and recommend new cybersecurity language for the Federal Acquisition Regulation, on a risk-based, tiered approach, for all new civil space systems. Those requirements shall be designed to apply at minimum to the on-orbit segments and the link segments. That is Kestrel Orbital’s spacecraft and the radio path to them.

The four command-and-control requirements

Section 3(e)(i) directs that the recommended requirements address, for the highest-risk tier and as appropriate other tiers, protection of command and control of the civil space system, including backup or failover systems, by:

#Requirement, verbatim from the orderWhat you will build for it course mapping
1encrypting commands to protect the confidentiality of communicationsResilience measures on the telecommand path
2ensuring commands are not modified in transitDetection signatures on command integrity
3ensuring an authorized party is the source of commandsThreats and attack paths against command authenticity
4rejecting unauthorized command and control attemptsDetection signatures with response playbooks

The two further requirements

  • 3(e)(i)(B) establishment of methods to detect, report, and recover from anomalous network or system activity.
  • 3(e)(i)(C) use of secure software and hardware development practices, consistent with the NIST SSDF or any successor documents.

Why this reaches a commercial operator

The order does not regulate Kestrel Orbital directly. It directs agencies to put these requirements into contract language, and the tier a system falls in decides how much applies. An operator that wants civil space work meets them through the contract. That is why SCOR treats the four command-and-control items as a floor and not a ceiling, and why every one of them has to be evidenced against a named part of the platform rather than asserted.

, and the full text behind it.

A satellite command and control console in a dim mission operations room, telecommand and telemetry readouts glowing amber on the monitors.
European Union · binding now

The EU NIS2 Directive (2022/2555): Space is a sector of high criticality, and the ground infrastructure Kestrel operates carries reporting clocks of 24 hours, 72 hours, and one month.

European Union · Directive

The NIS2 Directive

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. Official Journal L 333, 27 December 2022.

NIS2 names Space in Annex I, Sectors of High Criticality, entry 11. The entity type it describes is precise: operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks. NIS2 is a Directive, so it does not bind an operator by itself: it obliges Member States to impose these duties in national law, and the duty reaches an operator through the transposing statute of the state it operates in. It is the ground segment that carries it, not the spacecraft. For Kestrel Orbital that is the Reston mission-operations enclave, SEG:GR:Ground:00, and the Kiruna TT&C ground-station enclave, SEG:GR:Ground:01.

Article 21(2), the ten measures

Article 21(1) requires appropriate and proportionate technical, operational and organisational measures. Article 21(2) sets the floor, on an all-hazards approach, and it must include at least these ten.

#Measure, verbatim from the directiveWhere the course produces it course mapping
(a)policies on risk analysis and information system securityModule 02, the documented risk basis
(b)incident handlingModule 04
(c)business continuity, such as backup management and disaster recovery, and crisis managementModule 05
(d)supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providersModule 05
(e)security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosureNot produced in these five modules
(f)policies and procedures to assess the effectiveness of cybersecurity risk-management measuresNot produced in these five modules
(g)basic cyber hygiene practices and cybersecurity trainingNot produced in these five modules
(h)policies and procedures regarding the use of cryptography and, where appropriate, encryptionModule 05
(i)human resources security, access control policies and asset managementModule 01, for asset management. The rest is not produced in these five modules
(j)the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriateModule 05

Article 23, the reporting clocks

A significant incident, defined at Article 23(3) as one that has caused or is capable of causing severe operational disruption or financial loss, or has affected or is capable of affecting others through considerable damage, starts a fixed sequence from the moment you become aware of it.

ClockWhat is dueArticle
24 hoursAn early warning, indicating whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact23(4)(a)
72 hoursAn incident notification, updating the early warning with an initial assessment of severity and impact and, where available, the indicators of compromise23(4)(b)
On requestAn intermediate report on relevant status updates23(4)(c)
One monthA final report: detailed description, severity and impact, the type of threat or root cause, applied and ongoing mitigation, and cross-border impact where applicable23(4)(d)
Still ongoing at one monthA progress report at that time, and a final report within one month of handling the incident23(4)(e)

Why the 72-hour clock decides your data model

At 72 hours you owe indicators of compromise where you have them. An indicator you cannot attach to a named part of your platform is an indicator you cannot assess for severity or cross-border impact, and the clock does not pause while you work out what it touched. This is why the Concept of Operations comes first. The decomposition is what makes the 72-hour notification answerable.

, and the full text behind it.

A northern European satellite ground station at dusk in blowing snow, its parabolic antenna and lit control building beside a running clock.
Kestrel Orbital · binding now

Kestrel Orbital’s own mandate: machine-to-machine information sharing with the Space ISAC from our MISP instance, scoped, redacted, and policy-gated.

Kestrel Orbital · Internal directive · Simulated

KO-EXEC-2026-014

Approval of METEORSTORM analytic elements for machine-to-machine exchange with Space ISAC. Issued 9 January 2026 by Adaeze N. Okafor, Chief Executive Officer, and Gordon S. Reyes, Chief Technology Officer. Standing directive, effective immediately.

This memorandum is a course artifact. Kestrel Orbital is the fictional operator you work for. Executive Order 14144 and the NIS2 Directive are real instruments; this one models the internal directive a real operator would need to make sharing routine.

This one is Kestrel Orbital’s own, and it is the only one of the three the company wrote for itself. It exists because sector sharing does not happen by good intentions. The memorandum states the reason plainly: a threat, an attack path, or a detection that one operator confirms becomes usable to the rest of us before it arrives. It then removes the ambiguity that stops sharing in practice, by naming exactly what may cross the channel.

What it directs

  • Three co-equal mandates, Section 1.1. The order, the directive, and this exchange mandate carry equal weight. Section 4 states that none is subordinate to the other two.
  • Every element carries its identifier, Section 3.1. Its METEORSTORM tag and, where it names a specific instance on the platform, its ETEN identifier and parent chain, so a record means the same thing on both ends.
  • Machine to machine, Section 3.2. Structured records over the agreed Space ISAC interface, not free-text email or ad hoc attachments.
  • Scoped, not open-ended, Section 3.3. A redacted alert on a confirmed command-and-control attack under Executive Order 14144, and incident records consistent with the thresholds and clocks the NIS2 Directive sets.
  • Redaction is mandatory, Section 3.4. Mission-sensitive detail, customer identity, and any content restricted under ITAR or EAR is removed or withheld.
  • Reciprocal, Section 3.5. Elements received from Space ISAC in the same vocabulary are ingested into the shared platform view and routed to the department that owns the affected element.

The six approved element types, Section 2

Nothing outside this schedule crosses without a further written directive. The definitions are the published METEORSTORM analytic-layer text, and Section 2 forbids rewording, shortening, or paraphrasing them in an exchanged record, so they appear here as written.

TagElementPublished definition
AN-THRThreat“Confirmed and active threat against a converged space system.”
AN-ATTAttack Path“Confirmed attack path for a converged space system.”
AN-IOAIndicator of Attack“Confirmed indication that a converged space system has been attacked.”
AN-IOCIndicator of Compromise“Confirmed indication that a converged space system has been compromised.”
AN-DETDetection Signature“Validated and operational pattern, signal, or logic that triggers on contextualized threat behavior for a converged space system.”
AN-RESResilience Measure“Validated and operational protective capability ensuring converged space system resistance or recovery from confirmed threats.”

What it puts on you

Section 4 gives SCOR the vocabulary, the interface, and the redaction standard, and the job of training Security Operations, Satellite Operations, and Satellite Design and Engineering to produce and consume these elements as one system. It also states the line all five modules run on: the work done for the first two mandates is the work that feeds the third. You do not build a separate sharing program. You share what the five functions already produced.

, and
Global · Collective defense

The Space Information Sharing and Analysis Center

Established April 2019, headquartered in Colorado Springs. Member of the National Council of ISACs since 2020, participant in the EU Council of ISACs since 2023.

The three mandates make one operator harder to attack. This is how an entire sector does, and it is the reason the vocabulary matters as much as the findings. Space ISAC’s stated mission is to collectively protect global space systems to secure the future of humanity and to be the primary communications channel for the global space community. It was conceived in 2017 by the Science and Technology Partnership Forum to address information-sharing gaps in the cybersecurity and space community, presented at the 34th Space Symposium in April 2018, and established a year later.

Why collective defense is the point, not a benefit

An adversary that develops a technique against one operator’s ground segment can use it against every operator whose ground segment looks the same, and most of them do. The asymmetry is structural: the attacker builds once and reuses, while each defensive cyber operator discovers alone. Sector sharing inverts it. A confirmed threat, attack path, or detection signature crossing the channel means the second operator to be targeted is the first one already prepared.

That only works if the finding survives the trip. A detection written against “the ground station” tells another operator nothing they can act on, because their ground station is not yours. A detection anchored to an enumerated element, with its parent chain, tells them exactly which part of their own platform to look at. This is why the memorandum insists on the published definitions and the ETEN identifier. The vocabulary is what makes collective defense mechanical rather than aspirational.

What membership provides

From the Space ISAC membership materials in your reference pack. Benefits are tiered, so what any operator gets depends on the level it holds.

  • Information Sharing Portal accounts receiving Watch Center alerts. Fifteen at Platinum, five at Gold, two at Silver, one at University and Laboratory.
  • Actionable space-related threat intelligence and vulnerability disclosures, thought leadership, and a voice at the table with the public and private sector.
  • Unlimited participation in collaborative groups, and access to critical industry reports and whitepapers. Below Gold this excludes the Analyst Working Group.
  • The opportunity to pitch a project to the Cyber Vulnerability Lab Committee, four times a year at Platinum down to once at Small Business.
  • Placing analysts in the Watch Center, virtual or in person. This is a Platinum benefit. University and Laboratory members get priority access to apply for open Fellow positions instead.

Your part in it

Kestrel Orbital’s commitment is membership and a machine-to-machine connection, contributing and consuming, redacted and policy-gated. The company runs a MISP instance, the same platform that publishes the meteorstorm taxonomy you tag against from Module 02 onward, and that instance is what carries the exchange. The memorandum sets the form at Section 3.2: structured records over the agreed Space ISAC interface, not free-text email or ad hoc attachments. What you build across the five modules is what fills that channel, and it is portable to it by construction, because it was written in a published vocabulary from the start rather than translated into one afterwards.

.

A dark globe ringed by orbital paths with glowing green nodes linked across it, representing machine-to-machine intelligence sharing.

That is your scope, and a policy binder will not meet it. Meet it by standing up Resilient Cyber Operations: adopt the METEORSTORM framework and run its five functions on the platform, so every threat, detection, and resilience measure is enumerated once and normalized into a single analytic picture all three teams read without re-translation. You start tomorrow with the Concept of Operations, the top-down decomposition of the one path those mandates put in scope: the telecommand route the three teams have never described the same way.

METEORSTORM OVERVIEW
02/20
03
Day Zero

THE THREE PEOPLE WHO TURN THE TABLES

An adversary studies one platform. Your organization describes it three different ways, and every seam between those descriptions is somewhere an attack can live unseen. Each department has given you one contact. Adopt a standardized taxonomy and ontology at the organizational level to bridge all three, and the attacker loses the ground they were counting on.

Maya Reyes, analyst lead in the Kestrel Orbital Security Operations Center, at her workstation.
Security Operations
Maya Reyes

Analyst lead in the Security Operations Center. She knows who is coming. Aligned with the other two, she can finally say which part of your platform they would land on, and watch it.

Theo Lindgren, senior controller in the Kestrel Orbital Satellite Operations Center, at his console.
Satellite Operations
Theo Lindgren

Senior controller in the Satellite Operations Center. He flies the platform every pass. He knows normal, which is the one thing an adversary cannot fake once normal is written down.

Dana Whitfield, systems engineer in Kestrel Orbital Satellite Design and Engineering, at her workbench.
Satellite Design & Engineering
Dana Whitfield

Systems engineer in Satellite Design & Engineering. She owns the update path, which is the road to the satellite. She can close doors the other two can only watch.

Separately

Each of them is right about a different platform. The adversary works the space between the three answers, and nobody owns it.

Aligned

One enumeration, one set of names. Intelligence, operations, and engineering point at the same element, so nothing sits in a seam.

The table turns

The adversary has to beat three departments who know the platform better than they do. That is the first point of the Pentagon of Pain, and you will meet all five later today.

Pentagon of Pain · first of five
“The adversary suffers when you know your platform better than they ever can.”

None of these three can see the whole platform, and no meeting fixes that. Enumeration does: one taxonomy, one ontology, every element named once and anchored to its parent, until three partial views become one model with nothing left unowned.

METEORSTORM OVERVIEW
03/20
04
Day one

The shared data model

Day one, you describe one path through the platform, once, in a form all three departments read the same way. You do not describe the whole platform. The mandates name what matters, and that names your scope.

Scope comes first
Executive Order 14144 covers command and control; the NIS2 Directive binds the ground infrastructure carrying it.
Your scope is one path
The telecommand path: an operator keystroke to the spacecraft, across ground, link, and space.
Off the path, not enumerated
Other element types stay in the taxonomy as reference, so you can still read any platform.
44 elements, that path
Not a whole-platform inventory. One route, described once, in full: 44 = 4 PCE + 4 SEG + 15 SVC + 21 AST.

Decompose that path top down into Primary Capability Environment (PCE), Segment (SEG), Service (SVC), and Asset (AST) elements, and anchor every child to its parent. Everything you build over the next four days attaches to it.

METEORSTORM OVERVIEW
04/20
05
Your mission

YOU MUST IMPLEMENT A STANDARD TAXONOMY AND ONTOLOGY

  • No standard taxonomy and ontology. Three departments, three vocabularies, and intelligence degrades at every handoff.
  • Introduce one that solves that problem: a shared, open data model that names every element and relates it to its parent.
  • Put one shared read of the platform in front of all three departments and let that win them over. Adoption is earned, not ordered.
METEORSTORM OVERVIEW
05/20
06
Your mission

YOU MUST TEACH THE DATA MODEL

  • Departments, divisions, and vendors have no central reference for environments, segments, services, and assets.
  • Introduce the two forms every record will use. The Taxonomic Element Nomenclature (TEN) names what an element is; the Enumerated Taxonomic Element Nomenclature (ETEN) records one real occurrence.
  • Teach both forms until all three departments write them without you in the room.
TEN · teach what each element is

The dictionary: a published category and its fixed definition. Hyphen form LAYER-TAG, published with its Label and Definition.

PCE-OR · Orbital Environment
"Operational zones within planetary or satellite orbits."
Open TEN reference
ETEN · teach how to apply it

The record: the outcome of enumeration, naming one real occurrence of that type on your platform. Colon form with an ordinal: LAYER:TAG:Label:ORDINAL:Description.

PCE:OR:Orbital:00:The geostationary orbit regime (~35,786 km) part of the fleet flies in, fixing its coverage geometry, contact windows, and radiation exposure
All five fields are required; the description is what makes it a concrete operational record.
Open ETEN reference

One rule to carry forward: the ordinal is assigned in enumeration order within the element type, starting at 00.

METEORSTORM OVERVIEW
06/20
07
Your mission

YOU MUST IMPLEMENT RESILIENT CYBER OPERATIONS

  • There is no taxonomy or ontology for space systems resilience operations. Enrichment, what analysis adds to platform context, dies inside the department that wrote it.
  • Introduce the missing layer: METEORSTORM adds a fifth analytic layer of six fixed categories, each tied to the exact platform element it concerns.
  • Show them how to go from threats to attack paths to detection signatures to resilience measures, in one form all three departments read.
Analytic layer referencesTEN reference ETEN reference
METEORSTORM OVERVIEW
07/20
08
Overview

CHECKPOINT

Five questions on the shared data model: the four structural layers plus the Analytic layer, the difference between a type (TEN) and an instance (ETEN), and how parent anchoring ties the platform into one tree. Answer to confirm the foundation; your best score stays on this slide.

METEORSTORM OVERVIEW
08/20
09
The mindset

The Pentagon of Pain

This is the mindset you will use to drive the transformation: five mastery areas where investment makes every attack cost the adversary more than it costs you. The Pentagon of Pain gives Security Operations, Satellite Operations, and Satellite Design & Engineering one shared test for every hour and every dollar: does this raise the adversary's cost? When all three departments think this way, budget stops scattering across vendor pitches and compliance checkboxes, effort concentrates where the platform is provably exposed, and the adversary stops finding cheap wins. The outcome you can measure is a triad: detect, disrupt, and deter.

METEORSTORM OVERVIEW
09/20
10
Your mission

YOU MUST TURN THE COST BACK ON THE ATTACKER

  • No shared defensive mindset exists across the three departments. Budget scatters across checkboxes while the adversary needs one path.
  • Introduce the Pentagon of Pain: five mastery areas where investment provably raises the adversary’s cost.
  • Drive the mindset until every hour and dollar is tested against adversary cost, and the adversary stops finding cheap paths.
Pentagon of Pain hero composition: a glowing amber pentagon hovering in deep space with five energy nodes at its vertices, deflecting wireframe adversary silhouettes that fragment into amber and cyan particles
01

Master Decomposition

"The adversary suffers when you know your platform better than they ever can."

02

Master Contextualized Threat Modeling

"The adversary suffers when every strike they imagine is already prepared for."

03

Master Converged Detection Engineering

"The adversary suffers when they cannot hide, and every move is seen."

04

Master Exposure Management

"The adversary suffers when every path they take ends in a trap."

05

Master Adversary Management

"The adversary suffers when their plans are known, broken, and turned against them."

METEORSTORM OVERVIEW
10/20
11
The method

THE FIVE FUNCTIONS

The METEORSTORM cyber resilience framework works through five functions. You apply them to Kestrel Orbital’s platform in order, one per day across your first five days. Each function hands its output to the next, each gives Security Operations, Satellite Operations, and Satellite Design & Engineering work they read without translation, and together they produce the evidence behind your three mandates. Each one starts as a problem you will find on the platform and ends as something you will build to solve it, shown here across all five as problem then solution.

F01Concept of Operations
F02Contextualized Threat Modeling
F03Converged Detection Engineering
F04Incident Response Preparation
F05Adversary Management
Problem
Problem: fragmented dashboards and inconsistent labels in an ops center with no shared structural taxonomy

No shared structural taxonomy across the operational stack.

Problem: unanchored threat-actor cards floating with no lines attaching them to platform elements

Threats tracked as actor names with no link to the platform elements they target.

Problem: detection rules scattered as floating cards with no attack-path graph beneath them

Detection rules written before attack paths and source inventory exist.

Problem: vendor-locked detection silos with no portability and no link back to attack-path steps

Vendor-locked signatures with no paired response playbook for the SOC.

Problem: defensive cyber operator team scrambling reactively with no rolling adversary profiles, same adversary returns without context

The same adversary returns; the same flaw stays exposed; no shared posture.

Solution
Solution: unified ops center using one shared structural taxonomy, parent-child layers visible on every workstation

Decompose the in-scope telecommand path into enumerated elements all three departments read the same way.

Solution: threats anchored by connecting lines to specific structural elements on the platform decomposition

Enumerate the threats against Kestrel Orbital’s platform and anchor each one to the elements it targets.

Solution: clear attack-path graph laid out across the four structural layers with the one anchor element highlighted and the traversal drawn beneath it

Map how an adversary would traverse Kestrel Orbital’s command path, and the data and signal sources needed to see each step.

Solution: portable RootA signatures linked to attack-path steps, paired with response playbooks

Write the detection signatures and the response playbooks the Security Operations Center runs when they fire.

Solution: closed framework loop with structural-exposure heat map, adversary profiles, and resilience measures across SOC, SatOps, SatDev-Eng

Shrink the attack surface the adversary keeps finding across Kestrel Orbital’s missions.

METEORSTORM OVERVIEW
11/20
12
Overview

CHECKPOINT

Five questions on the five functions: their names and order, what each one produces, and how each consumes the output of the one before it. Answer to confirm the arc before you begin Day 1; your best score stays on this slide.

METEORSTORM OVERVIEW
12/20
13
The rollout

Three ways to start

Activate, Integrate, or Engage. The framework gives you three ways in, and no two of Kestrel Orbital’s departments will enter the same way. Matching each department to its entry point is your next call.

METEORSTORM OVERVIEW
13/20
14
Your mission

YOU MUST START WHERE EACH DEPARTMENT ALREADY IS

  • Reality dictates progress: no two departments start at the same capability, and one door turns most away.
  • Introduce a pragmatic range of starting points: Activate, Integrate, Engage.
  • Demonstrate each door works: the Security Operations Center activates, Satellite Design & Engineering integrates, and the Satellite Operations Center enters through Engage, where all three build together.
ENTRY POINT · ACTIVATEBest fit when ops already run, taxonomy does not
  • Adopt the shared taxonomy inside your existing Threat Intel Platform so confirmed enrichment reads the same way for every analyst, vendor, and partner. Federating with Space ISAC peers stands up the sharing channel Kestrel Orbital requires; what you federate stays selective.
ENTRY POINT · INTEGRATEBest fit when the platform is being designed or rebuilt
  • Align Security Operations, Satellite Operations, and Satellite Design & Engineering on the five-function process while the platform is being designed or rebuilt, so each department runs the framework as part of daily work rather than alongside it.
ENTRY POINT · ENGAGEBest fit when the three departments need to build production work product together
  • Run exercises in an environment fully separate from production with Security Operations, Satellite Operations, and Satellite Design & Engineering, using synthetic adversary data, so the detection signatures, response playbooks, and resilience measures the three departments build during the exercise graduate straight into production the moment it closes.
METEORSTORM OVERVIEW
14/20
15
Activate

ACTIVATE

If a department is already operational, it activates the framework taxonomy in its current Threat Intel Platform (TIP). At Kestrel Orbital that department is the Security Operations Center, and this is your first move.

METEORSTORM OVERVIEW
15/20
16
Integrate

INTEGRATE

If the platform is still being designed, walk through the full five-step process before launch. At Kestrel Orbital that makes this Satellite Design & Engineering’s entry point, with the next platform on its drawing board. Each step produces a specific kind of cataloged enrichment that feeds the next. Step through the five functions with the F01 to F05 buttons under the panel.

METEORSTORM OVERVIEW
16/20
17
Engage

ENGAGE

Engage is where you unite Security Operations, Satellite Operations, and Satellite Design & Engineering on one floor, running tabletops, red-team engagements, and training exercises in an environment fully separate from production. One change from live operations: the adversary inputs are synthetic, scripted by the exercise designers and tagged as exercise data. What participants build in response is real production-grade work. At close-out the tag is the filter: tagged synthetic inputs retire with the environment, and untagged participant work graduates into operations. Move through the five steps with the STEP buttons under the panel.

METEORSTORM OVERVIEW
17/20
18
Overview

CHECKPOINT

Five questions on the mindset and the rollout: the five mastery areas of the Pentagon of Pain, and the three entry points, Activate, Integrate, and Engage, with the Kestrel Orbital match for each. Answer to confirm the rollout plan; your best score stays on this slide.

METEORSTORM OVERVIEW
18/20
19
Day zero ends

Get started

That is the framework, end to end. Orientation closes here; one thing remains, your first task.

METEORSTORM OVERVIEW
19/20
20
ANALYTICSASSETSSERVICESSEGMENTSENVIRONMENTSMETEORSTORMFRAMEWORK
Your starting point

ENTER
THE METEORSTORM

You are the change Kestrel Orbital invested in, so hit the ground running with a scope and a concept. The mandates set the scope; your first task is the Concept of Operations (CONOPS) for it: decompose the in-scope telecommand path into its Primary Capability Environment (PCE), Segment (SEG), Service (SVC), and Asset (AST) elements. Every later function attaches to what you produce here.

METEORSTORM OVERVIEW
20/20