Skip to content
Interview

Space as the Invisible Backbone: Eva Sula on Resilience, Dependency and the Stakes of Getting It Wrong

In this interview, Katerina Mazzucchelli speaks with Eva Sula, an independent defence and digital capability strategist working across NATO, European and allied defence ecosystems, and an advisory board member of Counterspace Europe. Eva advises governments, defence organisations, industry and innovators on capability development, interoperability, AI adoption, cyber resilience and operational integration. Her work increasingly spans the intersection of defence, cyber, resilience and space, where interoperability, integration and trust are becoming decisive strategic advantages.

The conversation covers some of the most pressing challenges in space security and resilience today. How are the dependencies on space-enabled services cascading across critical infrastructure and daily life in ways that remain poorly understood at the political level? What does the shift from jamming to spoofing in the Baltic tell us about where European preparedness stands? Why does Europe’s information sharing problem run deeper than classification rules? And what is going wrong with the current defence innovation model, and what would a better one look like?

Eva Sula draws on her experience running hybrid warfare tabletop exercises, advising governments, and working with defence innovation programmes across Europe to offer a grounded, pragmatic assessment of the challenges ahead.

Modern defence and society depend on space-enabled services for navigation, communications, timing and critical infrastructure. Yet that dependency is rarely understood at the political or societal level. Where does the awareness gap sit, and what would it take to close it?

The main challenge is that dependencies are usually not mapped. They are often assumed and referenced in legislation about who should do what, but they are not fully assessed or laid out in a way that shows who does what, when, how, or how deep the disruption would be if something breaks. For Europe, there has also been a broader assumption that disruptions are more of a Ukrainian problem, when they are not. Over the past year, those monitoring GPS jamming maps have seen jamming become wider. Spoofing has also become a bigger issue, particularly with drones in the Baltics and Finland.

We are also seeing how data itself is being tampered with. You can find shadow fleet vessels appearing to sit in Tallinn’s airport on maritime tracking systems. What is not fully understood or assessed is how losing satellite GPS connectivity cascades across everything. People tend to assume it is just a navigation challenge for planes or ships, but it reaches into daily life in ways most people have not begun to consider. And people are not rational when things go wrong. Containing the chaos when GPS fails or starts showing false data is a serious problem.

What we are now seeing from Ukraine is also significant. When Starlink was seen as the fallback plan, Russia developed countermeasures to disrupt the signal and interfere with drone attacks. Russia moves fast, and so does China. Understanding our dependencies, building resilience, and developing countermeasures is essential. And if we rely only on European-tested, UK-tested, or even US-tested capabilities, that is far from sufficient given the full range of frequencies, combinations, and systems Russia is already deploying for disruption.

Russia could use its shadow fleet to install jamming and spoofing systems capable of causing widespread disruption across Western Europe. There are different ways to do that, and some countries are beginning to think about it seriously. European Commission leadership has also raised the need for proper testing environments as increasingly urgent. In practice, realistic electromagnetic-warfare testing in Europe runs into a combination of regulatory, spectrum, safety, data-protection and cross-border constraints. The links between these issues are very real. Alongside that, the educational component is equally important, and catching up on capabilities is hard because, since the end of the Cold War, the assumption has been that we live in permanent peace.

Russian jamming and spoofing over the Baltic has shifted from blocking signals to falsifying them, with systems appearing to function normally while the data cannot be trusted. What does that tell us about where European resilience stands, and how do you build confidence in data provenance when the failure is invisible?

The data landscape is fragmenting in multiple ways. One dimension is open-source data, which has been used to train models and supply industry. The open-source information environment is also vulnerable to deliberate, large-scale manipulation. This matters more because open-source data feeds analytical systems and is also used to develop and train  AI models. If you do not know what you are looking for, distinguishing manipulated information from reliable information becomes increasingly difficult.

When we talk about the shadow fleet appearing on maritime tracking systems in the airport of Tallinn, if you know exactly what you are looking at, you know it is nonsense. But the bigger problem is when the location is not absurd. When a shadow vessel appears to be at a safe distance but is sitting at the entrance to a critical shipping lane or port, it becomes a safety risk.

When we talk about the Baltic Sea, we should stop talking only about Estonia and Lithuania and start looking at the full picture. Russian installations sit between islands that used to belong to Finland and that, after the Second World War, became Russian, and, of course, in  Kaliningrad. If you look at jamming maps, you see those areas impacting Finland, Sweden, Poland and the Baltic states. Some of the equipment has an effective coverage bubble of around 300 kilometres, and Russia has far more powerful devices. The largest systems, such as Murmansk-BN, have ranges measured in thousands of kilometres. At the other end of the scale, more compact jamming and spoofing equipment can be deployed from mobile or maritime platforms, including vessels. That creates a very different resilience challenge.

What we see daily in this region is Russia protecting itself against drone attacks, and sometimes deliberately spoofing to blind NATO nations and create the false impression that their airspace is being used for attacks against Russia. Flights have been diverted from smaller airports because of it, and ferry traffic has been affected. Authorities in the region have repeatedly warned drone operators about the risks of GNSS interference close to the Russian border, where navigation can become unreliable or aircraft can behave unpredictably.

If Russia were to shift from defensive to offensive capability, disrupting a very large area of the Baltic Sea would not be difficult. That is why joint alliance capabilities and a joint situational awareness picture are critical. Russia never does anything alone. Jamming and spoofing always come alongside something else, whether a cyber-attack or a disinformation campaign. It is always a combination.

Some countries are beginning to think seriously about how these things cascade across all vital national services. We don’t have good solutions, and we aren’t fully prepared. But if we build awareness, work toward proper testing in Europe, and enable better information sharing and collaboration, we will have a better chance of responding properly. Today we are operating below the threshold of armed conflict, which places very different legal and political constraints on what governments and militaries can do. That makes deterrence, resilience and preparedness especially important.

Taxonomy disputes consume most governance meetings. Classification barriers prevent effective information sharing, and the EU’s proposed Information Sharing and Analysis Centre remains contested. Is Europe’s information sharing problem mainly technical, legal, cultural or political, and what would it take to resolve it?

It is a mix of different things. Europe does not have power over member states’ national security matters. What can be done across critical infrastructure, the public sector and defence is a national decision. The challenge usually begins where overclassification starts. There are matrices for classifying certain levels of data, and different laws that must be followed. At times, they can contradict each other, so it becomes hard to know what the right thing to do is, and the easiest response is to stamp it and move on. That is a struggle everybody faces, and it is not only a European problem.

That leads to a bigger challenge: policies need heavy review. How do we ensure information sharing while making sure data is classified correctly but not overclassified unnecessarily? Overclassification adds cost in upkeep, maintenance, security, IT systems, storage and administration. A major challenge is that data classification changes over time. What is highly classified at one moment can become open data. Any changes add complexity.

It is never only tied to data policies. It is tied to national cyber policies, classification standards, and the overall political stance on what platforms and solutions we use. That is a question of political will, not military decision-making. Militaries follow orders.

The trust problem is fundamental. Trust between countries, trust between different parties, trust in the systems themselves. At the moment, trust is very fragile. Countries are pulling inward to protect themselves, becoming more like isolated islands rather than asking how to collaborate and share the information space. Getting agreements across Europe is hard enough. Even NATO is very complicated. That is why regional approaches, such as Northern Europe and the JEF coalition, can make more sense because they bring together actors where the pressure is felt most acutely.

We cannot keep living on data laws that talk about floppy disks and DVDs. We must properly address the digital space, the data coming from it, AI, and how we use those things and for what. The first step is always to identify the problem you are trying to solve, then pick the right tool. We can put paint on a wall with a hammer, but it is very counterproductive and very expensive to fix afterwards.

Legal frameworks for space were designed during the Cold War and did not anticipate commercial providers, dual-use convergence or hybrid operations. If a cyber operation disrupts a satellite service used simultaneously by military and civilian users, who has the authority to respond, and where does accountability sit for protecting assets that governments rely on but do not own?

That leads back to the dependency question. How the dependencies roll and unfold should tell us who is accountable. Having run hybrid warfare tabletop exercises, I can tell you that once things start cascading, the first reaction is almost always: I thought it was you. The exercise is a useful tool for understanding who is accountable, when you need to inform, and when you need to engage other parties in your country, neighbouring countries, or across the alliance, so it doesn’t cause panic but still lets you act on time. That is exceptionally hard.

Another challenge is ensuring satellite providers and satellite data-handling companies also secure themselves, because adversaries often use subcontractors and partners to gain access to defence and national security players. The security measures on the innovation side are often minimal. The basics are not there.

We need to build awareness of how we protect and secure data flows, who has access rights for what, and what the plan B and plan C are. If one system or company gets compromised, how do others step in? That requires collaboration, and it is very hard because everyone runs their own business and profit model. But it is necessary for resilience.

It has long been feared that a cyberattack could become a major driver of satellite disruption through connectivity, data-transfer layers, and data manipulation. If you do not know what you are looking for, or whether what you are seeing makes sense, you think things are fine when they are not. That is the biggest danger.

The current defence innovation model is generating significant frustration among the militaries it is supposed to serve, while start-ups and university spin-offs doing critically needed work remain largely invisible to the procurement system. What is going wrong, and what does a better model look like?

There are multiple layers to this. Militaries have traditionally bought platforms and physical hardware. Now we have space, where much of what matters cannot be touched: AI, cyber, cognitive capabilities, space-based data. That is not how procurement and capability planning have been done.

This is not just a procurement problem. It starts with capability planning, which feeds into budgeting. Governments or parliaments confirm budgets, then procurement follows, and then comes the critical part: adoption, which includes sustainment, data labelling, and security. Those things are usually missing.

On the innovation side, much of what is being built rests on assumptions about the real problem that need closer examination. There is a great deal of information available about what is happening: the situation in Ukraine, the real conditions on the ground, and innovation does not always engage with that material seriously. That raises the question of whether we are building relevant things or building toward hype and the hope of getting rich. That hope does not work in defence.

Research has always had a structural problem: it cannot do business-to-business, and it takes years. We are in a situation now where there is no time to build something hypothetical over years. It would be very valuable if governments initiated and supported ways to combine research and innovation, bringing together the more academic, long-horizon thinking with the practical, fast-moving innovation side. Together, those two things could be very powerful.

We also need proper testing for security, for electromagnetic warfare, for space capabilities. The development cycle in Ukraine is now measured in days, not weeks. We need to shift from fixed solutions to things that can be adapted when they become obsolete in three days. What is tested in a lab has very little to do with what happens in a real battlefield environment.

We need to ask the uncomfortable questions and incentivise answers. If connectivity is lost, what is plan B? How do we build offensive capability readiness for cases where we might need to use it, even though we legally cannot today? Without preparedness, we can never get there. Lists of MOUs and summits are not enough. Actions are what tend to fall short.

Get Involved

Join Counterspace Europe

Attendee

Join us as an Attendee

Meet industry leaders, discover capability developments, and build meaningful connections at Counterspace Europe in Brussels.

Register Interest
Exhibitor

Join us as an Exhibitor

Gain direct access to European defence stakeholders, national ministries of defence, armed forces, and international partners.

Stand Enquiry