NIS2 Space Cyber Resilience Portal
The NIS2 Directive asks in-scope organizations to do more than write down their security measures. Article 21(2)(f) requires policies and procedures to assess whether those measures are actually effective, and Article 21(2)(b) and (c) place incident handling and crisis management among the measures in scope. In practice, that means exercising.
H3 is how we answer it: we prepare your organization to run its own exercise, and everything we use is published here at no fee. Below: who we are and the training options behind it.
Who we are What we have already done, the seats we hold today, how we think, and who backs the work.
Proving Duties NIS2 now writes down, carried under real pressure before the Directive made them law.



The duties NIS2 now writes down are ones we have already carried under real pressure. Not advised on, carried. Each of these was done before the Directive made it a legal obligation, which is the only kind of evidence that means anything.
- Incident handling and crisis management, on the clock. Led global cybersecurity operations at a European satellite operator through the February 2022 Viasat attack, when tens of thousands of modems went down across Europe in minutes. That is Article 21(2)(b) and (c) lived rather than documented.
- Security built into the standard, not bolted on after. Over 500 hours as Technical Editor of IEEE P3536, from scoping through ballot, plus three peer-reviewed IEEE publications on space system security. That is Article 21(2)(e), security in the development and maintenance of systems, at the level where the requirements are written.
- Effectiveness, actually assessed. Ran Operation Electro Magnetic Panic in Madrid in October 2025: five ground-station teams, eight challenges, 21 professionals certified. That is Article 21(2)(f), and the whole pack is published for anyone to check, now being packaged as the first H3 exercise bundle.
Leading The seats where the rules for this sector are still being written, held now rather than once.



The work did not stop when the standard reached ballot. We hold the seats where the rules for this sector are still being written, which means your programme is designed against what is coming rather than what has already been superseded. These are current appointments, not past ones.
- Writing the standard your programme will be measured against. Technical Editor of IEEE P3536 and lead of its Integration Subgroup, the group making the user, link, ground and space segments hold together as one security picture instead of four.
- Extending supply chain transparency to whole space systems. Co-chair of the Space System Extended (x) Bill of Materials Task Force at the Space ISAC, where bill of materials practice long familiar in software is being worked out for spacecraft and the supply chain behind them. That is Article 21(2)(d), before the tooling for it exists.
- Publishing the method instead of selling it. METEORSTORM is an official MISP taxonomy, the H3 harness is published in full at no fee for anyone to run, and we are accredited by the Luxembourg Ministry of National Education as an organizer of continuing vocational training. That is Article 21(2)(g) and the sharing Article 29 encourages.
Thinking The Pentagon of Pain: the five transformations that make an adversary pay for the attempt.
The Pentagon of Pain is an internal transformation across departments, mindsets, and priorities, ideally evolving toward a Space Collective Defense community where ISAC information sharing of IOCs, IOAs, detection signatures, and resilience measures raises the bar for real-world platform exploitation. The five points below are reproduced as published.
Illustrative image
Illustrative image
Illustrative image
Illustrative image
Illustrative image
Sponsors and contributors The partners who fund and pilot the work, and how to become one.
Research and Development Partners
303 Overwatch collaborates with a select group of Research and Development Partners on focused technical initiatives that extend METEORSTORM into domain-specific environments such as maritime, aerospace, orbital, and deep space operations. Each partnership is structured around a defined research topic.
Community Contributors
Community Contributors are individuals and organizations contributing their time, feedback, and hands-on piloting of METEORSTORM, validating the framework in real-world environments and strengthening the collective defense posture of the international space community.
What we do We set up your own exercise programme, run the method with you, and train your team. The harness and the training, each in full.
Training options The SCOR micro-credentials: Associate and Practitioner, prices, and preregistration.



Everything above is yours to run. Some organizations want the method taught rather than read, want their team assessed rather than self-assessed, or want a credential at the end of it. That is what the SCOR micro-credentials are for. They are how the work above is sustained.
The five functions are also taught one at a time, one hour each, scheduled on demand, or delivered privately for your team: start an organizational request.



