Art. 23(3)
Mapped SPARTA techniques (18)
Techniques referencing this article
Primary mapping to Art. 23(1) treats ransomware as a significant incident. Art. 23(3) defines the significance criteria (operational disruption, financial loss); ransomware against MOC/IT systems satisfies both directly and frequently has cross-border impact when the affected operator serves multi-Member-State customers.
Primary mapping to Art. 23(1) treats wiper malware as significant. Art. 23(3) significance criteria are met directly: destructive wipes cause operational disruption and considerable damage; in space operations they often have cross-border impact when the operator's services span Member States.
Primary mapping to Art. 23(1) treats flooding as significant. Art. 23(3) is met by the operational-disruption test directly; cross-border impact applies when the flooded service supports users across Member States.
Primary mapping to Art. 23(1) treats MOC compromise as significant. Art. 23(3) significance is met by operational-disruption and considerable-damage criteria; cross-border impact applies to multi-mission ground systems whose telemetry and payload data flow across Member States.
Primary mapping to Art. 23(1) treats partner-site compromise as significant. Art. 23(3) significance is met by the cross-border test directly: partner networks (commercial GS, relay, processing) routinely span Member States, so an EXF-0009 event is structurally cross-border.
Primary mapping to Art. 23(1) treats GS initial access as significant. Art. 23(3) significance is met because GS compromise enables operational disruption of the spacecraft itself; cross-border impact applies when the GS supports multi-tenant or international missions.
Primary mapping to Art. 23(1) treats this technique as significant. Art. 23(3) significance is met because malicious commanding produces operational disruption directly on the spacecraft; cross-border impact attaches when the spacecraft serves multi-Member-State users.
Primary mapping to Art. 23(1) treats deception as significant. Art. 23(3) significance test is met by the considerable-damage criterion (induced wrong reactions by mission stakeholders) and the affecting-other-persons criterion (downstream consumers of falsified telemetry).
Primary mapping to Art. 23(1) treats disruption as significant. Art. 23(3) significance test is met directly by the operational-disruption criterion; cross-border impact applies when affected services span Member States.
Primary mapping to Art. 23(1) treats denial as significant. Art. 23(3) significance test is met directly by the operational-disruption criterion (denial blocks ground-controller access entirely); cross-border impact applies when the denied service spans Member States.
Primary mapping to Art. 23(1) treats degradation as significant. Art. 23(3) significance test is met by the considerable-damage criterion (lifespan reduction, subsystem impairment) and frequently the financial-loss criterion via lost mission years.
Primary mapping to Art. 23(1) treats destruction as significant. Art. 23(3) significance test is met directly by the considerable-damage and operational-disruption criteria; cross-border impact applies when the destroyed asset served multi-Member-State users.
Primary mapping to Art. 23(1) treats theft as significant. Art. 23(3) significance test is met by the financial-loss criterion (commercial mission data) and frequently the cross-border criterion (constellation data routinely covers multi-Member-State customers).
Primary mapping to Art. 23(1) treats constellation hopping as significant. Art. 23(3) significance is met by the operational-disruption criterion (multiple satellites compromised) and the cross-border criterion (constellation members typically span Member States).
Primary mapping to Art. 23(1) treats GS persistence as significant. Art. 23(3) significance applies conditionally on the persistence enabling downstream impact (operational disruption, theft); persistence alone is preparatory but, on a NIS2-regulated GS, the access-level criterion typically meets the considerable-damage threshold once detected.
Primary mapping to Art. 23(1) treats infrastructure compromise as significant. Art. 23(3) significance is met when the staged-resource use enables operational disruption or considerable damage downstream; for resource-development-only cases (no follow-on impact), significance attaches to the unauthorized access itself.
Primary mapping to Art. 23(1) treats this as significant. Art. 23(3) significance attaches to the operational-disruption potential a compromised mission-operated GS introduces; cross-border impact is conditional on the GS supporting multi-Member-State customers.
Primary mapping to Art. 23(1) treats this as significant. Art. 23(3) significance is met by the cross-border criterion directly: third-party GS providers commonly serve operators across Member States, making cross-border impact structural rather than conditional.