Welcome to orientation. You have joined Kestrel Orbital, a global commercial satellite operator whose three defending departments each describe the platform in their own words, and that gap is where missions and audits are lost. You are here to build and lead the department that closes it: Space Cybersecurity Operations and Resilience (SCOR).
One function a day for five days. First, the standard you will be held to.
THE THREE MANDATES YOU'RE FOCUSED ON
You will build and lead Kestrel Orbital’s new department, Space Cybersecurity Operations and Resilience (SCOR), toward resilient cyber operations. It exists to meet three mandates of equal weight: Executive Order 14144 (United States), the NIS2 Directive (Europe), and Kestrel Orbital’s own mandate to open an information-sharing channel with the Space Information Sharing and Analysis Center (Space ISAC). They set your scope and the bar SCOR is judged by, and reaching resilient cyber operations is how you meet all three at once. Miss one and the department fails.
Executive Order 14144 (January 2025): protect command and control of the space system. Encrypt commands, protect their integrity, authenticate their source, reject unauthorized attempts. , and the full text behind it.

The EU NIS2 Directive (2022/2555): Space is a sector of high criticality, and the ground infrastructure Kestrel operates carries reporting clocks of 24 hours, 72 hours, and one month. , and the full text behind it.

Kestrel Orbital’s own mandate: machine-to-machine information sharing with the Space ISAC from our MISP instance, scoped, redacted, and policy-gated. , and .

That is your scope, and a policy binder will not meet it. Meet it by standing up Resilient Cyber Operations: adopt the METEORSTORM framework and run its five functions on the platform, so every threat, detection, and resilience measure is enumerated once and normalized into a single analytic picture all three teams read without re-translation. You start tomorrow with the Concept of Operations, the top-down decomposition of the one path those mandates put in scope: the telecommand route the three teams have never described the same way.
THE THREE PEOPLE WHO TURN THE TABLES
An adversary studies one platform. Your organization describes it three different ways, and every seam between those descriptions is somewhere an attack can live unseen. Each department has given you one contact. Adopt a standardized taxonomy and ontology at the organizational level to bridge all three, and the attacker loses the ground they were counting on.

Analyst lead in the Security Operations Center. She knows who is coming. Aligned with the other two, she can finally say which part of your platform they would land on, and watch it.

Senior controller in the Satellite Operations Center. He flies the platform every pass. He knows normal, which is the one thing an adversary cannot fake once normal is written down.

Systems engineer in Satellite Design & Engineering. She owns the update path, which is the road to the satellite. She can close doors the other two can only watch.
Each of them is right about a different platform. The adversary works the space between the three answers, and nobody owns it.
One enumeration, one set of names. Intelligence, operations, and engineering point at the same element, so nothing sits in a seam.
The adversary has to beat three departments who know the platform better than they do. That is the first point of the Pentagon of Pain, and you will meet all five later today.
“The adversary suffers when you know your platform better than they ever can.”
None of these three can see the whole platform, and no meeting fixes that. Enumeration does: one taxonomy, one ontology, every element named once and anchored to its parent, until three partial views become one model with nothing left unowned.
The shared data model
Day one, you describe one path through the platform, once, in a form all three departments read the same way. You do not describe the whole platform. The mandates name what matters, and that names your scope.
Decompose that path top down into Primary Capability Environment (PCE), Segment (SEG), Service (SVC), and Asset (AST) elements, and anchor every child to its parent. Everything you build over the next four days attaches to it.
YOU MUST IMPLEMENT A STANDARD TAXONOMY AND ONTOLOGY
- No standard taxonomy and ontology. Three departments, three vocabularies, and intelligence degrades at every handoff.
- Introduce one that solves that problem: a shared, open data model that names every element and relates it to its parent.
- Put one shared read of the platform in front of all three departments and let that win them over. Adoption is earned, not ordered.


You were hired to stop intelligence dying at the boundaries between Kestrel Orbital's departments, and the taxonomy is SCOR's first move against it. It gives every part of a space platform one name across the four structural layers: the Primary Capability Environment (PCE), where the platform physically operates; the Segment (SEG), the operational role of each enclave; the Service (SVC), the capability each enclave delivers; and the Asset (AST) elements that implement it. It is real and already in the open: the implementation lives at machinetag.json↗ as an MISP taxonomy. You will apply each layer and name your own platform with it in the days ahead.

Naming the parts is half the job; making those names connect is how you finish closing the gap, and that is the ontology. Every element anchors to its parent in the layer above: an Asset implements a Service, a Service is carried by a Segment, and a Segment operates within one or more Primary Capability Environments, one chain from the most concrete Asset back to the environment the platform operates in. Attach enrichment to any small part and it traces back through the chain to the larger part it concerns, so every defensive cyber operator you serve inherits structural context for free. You will walk the chain and write your own in the next modules.

YOU MUST TEACH THE DATA MODEL
- Departments, divisions, and vendors have no central reference for environments, segments, services, and assets.
- Introduce the two forms every record will use. The Taxonomic Element Nomenclature (TEN) names what an element is; the Enumerated Taxonomic Element Nomenclature (ETEN) records one real occurrence.
- Teach both forms until all three departments write them without you in the room.
The dictionary: a published category and its fixed definition. Hyphen form LAYER-TAG, published with its Label and Definition.
The record: the outcome of enumeration, naming one real occurrence of that type on your platform. Colon form with an ordinal: LAYER:TAG:Label:ORDINAL:Description.
One rule to carry forward: the ordinal is assigned in enumeration order within the element type, starting at 00.
YOU MUST IMPLEMENT RESILIENT CYBER OPERATIONS
- There is no taxonomy or ontology for space systems resilience operations. Enrichment, what analysis adds to platform context, dies inside the department that wrote it.
- Introduce the missing layer: METEORSTORM adds a fifth analytic layer of six fixed categories, each tied to the exact platform element it concerns.
- Show them how to go from threats to attack paths to detection signatures to resilience measures, in one form all three departments read.


This is how you make enrichment usable by every department: one published taxonomy for every kind of enrichment you produce. Six fixed categories cover the entire analytic surface: AN-IOC (Indicator of Compromise) and AN-IOA (Indicator of Attack) for what the adversary leaves behind and does, AN-THR (Threat), AN-ATT (Attack Path), AN-DET (Detection Signature), and AN-RES (Resilience Measure). It lives in the same machinetag.json↗ file as the structural taxonomy. You will apply each category to your own enrichment in the days ahead.

Enrichment is only useful if it points at a specific part of the platform, so each enrichment element names its target in a TARGET field. The four threat-side categories, AN-IOC, AN-IOA, AN-ATT, and AN-THR, name the element the adversary exploits: the Target of Exploitation (TOE). AN-DET detection signatures name a Target of Detection Method (TDM), and AN-RES resilience measures name a Target of Resilience Enhancement (TRE). Without a target an enrichment element is a free-floating note; with one, every defensive cyber operator can locate the part of the platform it concerns.

CHECKPOINT
Five questions on the shared data model: the four structural layers plus the Analytic layer, the difference between a type (TEN) and an instance (ETEN), and how parent anchoring ties the platform into one tree. Answer to confirm the foundation; your best score stays on this slide.
The Pentagon of Pain
This is the mindset you will use to drive the transformation: five mastery areas where investment makes every attack cost the adversary more than it costs you. The Pentagon of Pain gives Security Operations, Satellite Operations, and Satellite Design & Engineering one shared test for every hour and every dollar: does this raise the adversary's cost? When all three departments think this way, budget stops scattering across vendor pitches and compliance checkboxes, effort concentrates where the platform is provably exposed, and the adversary stops finding cheap wins. The outcome you can measure is a triad: detect, disrupt, and deter.
YOU MUST TURN THE COST BACK ON THE ATTACKER
- No shared defensive mindset exists across the three departments. Budget scatters across checkboxes while the adversary needs one path.
- Introduce the Pentagon of Pain: five mastery areas where investment provably raises the adversary’s cost.
- Drive the mindset until every hour and dollar is tested against adversary cost, and the adversary stops finding cheap paths.

Master Decomposition
"The adversary suffers when you know your platform better than they ever can."
Master Contextualized Threat Modeling
"The adversary suffers when every strike they imagine is already prepared for."
Master Converged Detection Engineering
"The adversary suffers when they cannot hide, and every move is seen."
Master Exposure Management
"The adversary suffers when every path they take ends in a trap."
Master Adversary Management
"The adversary suffers when their plans are known, broken, and turned against them."
THE FIVE FUNCTIONS
The METEORSTORM cyber resilience framework works through five functions. You apply them to Kestrel Orbital’s platform in order, one per day across your first five days. Each function hands its output to the next, each gives Security Operations, Satellite Operations, and Satellite Design & Engineering work they read without translation, and together they produce the evidence behind your three mandates. Each one starts as a problem you will find on the platform and ends as something you will build to solve it, shown here across all five as problem then solution.

No shared structural taxonomy across the operational stack.

Threats tracked as actor names with no link to the platform elements they target.

Detection rules written before attack paths and source inventory exist.

Vendor-locked signatures with no paired response playbook for the SOC.

The same adversary returns; the same flaw stays exposed; no shared posture.

Decompose the in-scope telecommand path into enumerated elements all three departments read the same way.

Enumerate the threats against Kestrel Orbital’s platform and anchor each one to the elements it targets.

Map how an adversary would traverse Kestrel Orbital’s command path, and the data and signal sources needed to see each step.

Write the detection signatures and the response playbooks the Security Operations Center runs when they fire.

Shrink the attack surface the adversary keeps finding across Kestrel Orbital’s missions.
CHECKPOINT
Five questions on the five functions: their names and order, what each one produces, and how each consumes the output of the one before it. Answer to confirm the arc before you begin Day 1; your best score stays on this slide.
Three ways to start
Activate, Integrate, or Engage. The framework gives you three ways in, and no two of Kestrel Orbital’s departments will enter the same way. Matching each department to its entry point is your next call.
YOU MUST START WHERE EACH DEPARTMENT ALREADY IS
- Reality dictates progress: no two departments start at the same capability, and one door turns most away.
- Introduce a pragmatic range of starting points: Activate, Integrate, Engage.
- Demonstrate each door works: the Security Operations Center activates, Satellite Design & Engineering integrates, and the Satellite Operations Center enters through Engage, where all three build together.



- Adopt the shared taxonomy inside your existing Threat Intel Platform so confirmed enrichment reads the same way for every analyst, vendor, and partner. Federating with Space ISAC peers stands up the sharing channel Kestrel Orbital requires; what you federate stays selective.
- Align Security Operations, Satellite Operations, and Satellite Design & Engineering on the five-function process while the platform is being designed or rebuilt, so each department runs the framework as part of daily work rather than alongside it.
- Run exercises in an environment fully separate from production with Security Operations, Satellite Operations, and Satellite Design & Engineering, using synthetic adversary data, so the detection signatures, response playbooks, and resilience measures the three departments build during the exercise graduate straight into production the moment it closes.
ACTIVATE
If a department is already operational, it activates the framework taxonomy in its current Threat Intel Platform (TIP). At Kestrel Orbital that department is the Security Operations Center, and this is your first move.
010203


INTEGRATE
If the platform is still being designed, walk through the full five-step process before launch. At Kestrel Orbital that makes this Satellite Design & Engineering’s entry point, with the next platform on its drawing board. Each step produces a specific kind of cataloged enrichment that feeds the next. Step through the five functions with the F01 to F05 buttons under the panel.
F01F02F03F04F05




ENGAGE
Engage is where you unite Security Operations, Satellite Operations, and Satellite Design & Engineering on one floor, running tabletops, red-team engagements, and training exercises in an environment fully separate from production. One change from live operations: the adversary inputs are synthetic, scripted by the exercise designers and tagged as exercise data. What participants build in response is real production-grade work. At close-out the tag is the filter: tagged synthetic inputs retire with the environment, and untagged participant work graduates into operations. Move through the five steps with the STEP buttons under the panel.
0102030405




CHECKPOINT
Five questions on the mindset and the rollout: the five mastery areas of the Pentagon of Pain, and the three entry points, Activate, Integrate, and Engage, with the Kestrel Orbital match for each. Answer to confirm the rollout plan; your best score stays on this slide.
Get started
That is the framework, end to end. Orientation closes here; one thing remains, your first task.
ENTER
THE METEORSTORM
You are the change Kestrel Orbital invested in, so hit the ground running with a scope and a concept. The mandates set the scope; your first task is the Concept of Operations (CONOPS) for it: decompose the in-scope telecommand path into its Primary Capability Environment (PCE), Segment (SEG), Service (SVC), and Asset (AST) elements. Every later function attaches to what you produce here.