What changed at the launch deltas
Space Systems Command announced the new arrangement on March 23, 2026. The 630th Cyberspace Squadron activated at Vandenberg on March 10 under Space Launch Delta 30. The 645th Cyberspace Squadron had moved from Delta 6 to Space Launch Delta 45 at Patrick effective September 22, 2025. SSC describes their work as real-time defense of launch ranges during operations, alongside other defensive tasks.
The arrangement connects cyber personnel to a specific operational mission. It gives range commanders a more direct organizational relationship with the teams watching their systems and preparing responses. Establishing that relationship is a meaningful step; the effectiveness of the defense still depends on staffing, access, instrumentation and practiced procedures.
The workload is substantial. Vandenberg reported 51 rocket and missile launches in 2024. Representative Salud Carbajal's January 2026 letter to Air Force and Space Force leadership records 66 launches in 2025. The two figures come from differently described counts, so they should be read as evidence of a busy and growing range rather than a precisely matched statistical series.
Why range systems deserve mission-level attention
A launch brings ground control, telemetry, tracking, safety functions and communications into a time-sensitive operating sequence. A problem in a shared system can affect more than the immediate mission. It can also consume troubleshooting capacity and disrupt the preparation of subsequent launches.
Greater commercial activity adds partners and interfaces as well as launch opportunities. That does not make commercial participation inherently less secure. It does make responsibilities for remote access, configuration changes, incident reporting and shared infrastructure more important to define.
The security review should connect a technical event to an operational consequence. A suspicious login, loss of trustworthy telemetry and an unavailable communications path are different problems. They may require different authorities and different decisions about whether operations can safely continue.
A range team should be able to answer:
- Which digital functions are essential at each stage of launch preparation and execution?
- Who can distinguish a cyber indicator from an equipment or communications fault?
- Which containment actions could interrupt a safety-critical function?
- How does the cyber team communicate uncertainty to the operational decision-maker?
- What evidence is required before returning a recovered system to service?
Threat patterns observed in other sectors can inform exercises, but the exercise needs to reflect the actual range architecture. Familiar terminology such as intrusion or command spoofing is not a substitute for understanding the system's controls and operational dependencies.
Faster authorization needs better evidence
In a public Mitchell Institute interview, Seth Whitworth described the need to prioritize security by design and assess risk across connected systems instead of treating authorization as an isolated paperwork exercise. That is a useful direction for launch software: a change package should explain both the component and the mission connections it affects.
AI can assist with organizing evidence, identifying inconsistencies and helping reviewers navigate a large body of technical material. Those are useful candidate applications, not a reason to assume an automatically shortened approval cycle or substitute generated text for test results.
For a practical trial, measure the time spent finding and validating evidence, the errors that require correction and the completeness of the resulting risk assessment. Preserve the authorizing official's decision and the source material supporting it. Faster document production has limited value if it creates additional review work or hides an unresolved system dependency.
CROO tests another part of the space cyber problem
On-orbit monitoring is a separate technical effort from launch-range defense. In December 2024, BigBear.ai announced support to Proof Labs' Air Force SBIR project for Cyber Resilient On-Orbit, or CROO. The company described using SpaceCREST digital-twin capabilities and simulated attacks to develop AI/ML-based detection. Redwire subsequently described providing synthetic satellite telemetry for that work, including attention to the relationship between reported and actual subsystem behavior.
SSC named Proof Labs' CROO among the February 2026 Fight Tonight winners selected for further funding. That supports a development and transition effort; it does not establish fleet-wide operational availability. Its relevance is the attempt to recognize cyber effects through subsystem telemetry and software activity, rather than relying exclusively on conventional network indicators.
Evaluation should include benign faults and unusual but authorized spacecraft activity. A model that reports every departure from a familiar baseline may overwhelm operators, while a model tuned too narrowly may miss consequential changes. Teams need evidence about detection, missed events, false alerts and response options on the intended platform.
What suppliers should make easier
The common requirement across range defense, authorization support and on-orbit monitoring is usable evidence close to the mission. Each application has its own operating constraints, so progress in one should not be presented as proof of readiness in the others.
Suppliers can make integration more productive by delivering:
- A precise system boundary: Interfaces, dependencies, privileges and the functions the product does and does not control.
- Relevant test results: Scenarios tied to the intended mission, including degraded conditions and benign anomalies.
- Operator-ready outputs: Alerts and records that support a decision without concealing uncertainty.
- Controlled updates: Versioned software and models, regression evidence and a workable rollback plan.
- A sustainment plan: Training, support coverage and responsibility for changes across government and commercial interfaces.
That is a concrete opportunity for the industrial base: deliver security capabilities that range and mission teams can understand, exercise and maintain at their operating tempo.
Sources and further reading
- SSC: formation and alignment of defensive cyber squadrons
- Vandenberg: 2024 rocket and missile launch count
- Representative Carbajal: January 2026 letter recording 2025 launch activity
- Mitchell Institute: interview with Space Force cyber and data leaders
- BigBear.ai: CROO development collaboration
- Redwire: synthetic telemetry contribution to CROO
- SSC: February 2026 Fight Tonight funding selections
Spartan X's cybersecurity and AI engineering work focuses on making technical capability useful within the operating mission, with the integration evidence, human decisions and sustainment planning that a high-tempo launch environment demands.



