Cybersecurity is no longer an afterthought for drones and autonomous vehicles. It is the foundation that determines whether these systems stay safe, lawful and mission ready. That was the message from this year’s Law-Tech Connect panel, “Building Digital Fortresses: Cybersecurity, National Security and Communications Resilience for Autonomous Systems,” where legal, policy and technical experts unpacked how GPS spoofing, jamming, cloud vulnerabilities and a shifting supply chain ruleset have converged to reshape the autonomy industry.
Moderator Bill Daggett of Delta Advisory Group opened by drawing on his own background flying MQ-1 drones out of what was then Indian Springs Auxiliary Airfield, now Creech Air Force Base. He recalled radioing a satellite contractor for a command and control (C2) frequency only to have Fox News pop up on his screen instead of a secure feed. “We’ve come a long way,” Daggett said, but he warned that anyone scanning the electromagnetic spectrum can still find these signals with relative ease.
Joining him were Evan Wolff, partner and co-chair of the cyber and privacy practice at Akin Gump; Davis Hake, senior director of cybersecurity at Venable; Sara Baxenberg, a partner at Wiley in the telecom, media and technology group; and Bronwyn Morgan, who runs the drone OEM ZeroAvia and the training organization Airversity. Together they connected battlefield lessons from Ukraine to the compliance frameworks now landing on both commercial and defense drone operators.
Ukraine Reshapes the Threat Landscape

The war in Ukraine changed how the industry thinks about resilience. Morgan said the conflict has driven an iteration cycle on GPS spoofing, jamming and cybersecurity that nobody could have predicted a few years ago. She noted the effect extends well beyond aerial drones into ground, underwater vehicles and space. She pointed to the reinstallation of celestial navigation domes on military KC-135 aircraft as a key indicator that GPS can no longer be assumed reliable.
Wolff extended the military discussion to the next conflict. “It’s been said by many people smarter than me that all the next wars will be fought in cyber, and digital wars will predate any physical or kinetic war,” he noted.
For drone makers, that means adversaries are already mapping supply chains and infrastructure vulnerabilities long before any shots are fired. This is why the Department of War (DoW) focuses so heavily on protecting the information used to design and control unmanned systems.
Wolff also drew a distinction between how the United States and its adversaries approach weapons development. The U.S. tends to build a constrained sandbox around new capabilities, testing them within limits shaped by political concerns about civilian harm. Russia, he said, treats active conflict itself as the sandbox. He pointed to ransomware strains that spread across Europe in 2017 and 2018 as evidence that Russian actors test tools against real targets without proof of concept first. He said Russian forces have applied that same experimental approach against Ukrainian civilian infrastructure, including power grids and unmanned systems, and argued the U.S. needs to study those tactics now rather than wait to encounter them at scale at home.
Hake added an unsettling example of how the electronic warfare (EW) fight has already spilled beyond the battlefield. In May, he said, two Ukrainian drones that had suffered GPS spoofing crossed from Russia into Latvia and struck Latvian fuel depots. The onboard model apparently had been programmed to identify fuel depots as targets, but never anticipated operating over European territory. “There’s a huge issue, as we start thinking about programming and where that fails,” Hake explained, using the incident to illustrate how a spoofed navigation input can trigger a technically correct but catastrophically wrong autonomous decision.
Baxenberg noted that these battlefield events are actively shaping civilian regulation. She said the FCC has been watching developments in Ukraine and Iran with growing concern about data exfiltration and GPS spoofing, in relation to civilian networks and devices. She also flagged a subtler policy tension. U.S. rules only authorize drones to use GPS (U.S.) and Galileo (Europe) satellite positioning. However, much of the industry’s hardware also relies on BeiDou (China) and GLONASS (Russia) by default. The FCC has an open proceeding examining GNSS spoofing and resilience precisely because, as she put it, “what happens when we’ve already put the regulatory restrictions in place, but the technology just doesn’t align.”

Designing Resilient Architecture From the Ground Up
Turning from threats to solutions, Hake offered a practical framework of six categories operators should evaluate when assessing risk:
- Navigation
- C2 links
- Payload data integrity
- Ground crew trust in what they observe
- Cloud and fleet systems, and
- Supply chain
He explained that both Russian and Ukrainian forces have embedded malware in captured drones, that sometimes burns USB ports to disable onboard computers or uses captured hardware to beacon location data back to the side that seized it to allow follow-up strikes on the interrogation site itself.
Wolff pushed the conversation toward a broader historical parallel, arguing that the drone industry is repeating a mistake the internet made decades ago. “We did this with the internet. I mean, ARPANET and the internet itself was not based on security. It was the very last thing that we thought about,” he said. He argued the aviation sector built its culture around safety, not security, and now needs to import lessons from how the internet eventually adopted encryption, secure coding practices and VPN-style tunneling. Crucially, he said, those standards should be industry-led rather than dictated top-down.
Baxenberg agreed, warning that heavy-handed regulatory tools can backfire if they are not developed collaboratively. She cited the FCC’s ban on foreign-produced drones and critical components that emit radio frequencies (RF) as an example of a tool designed to boost domestic production but one that risks unintended consequences if similar blunt instruments get applied to cybersecurity requirements.
Morgan brought the conversation back to operational reality. She stressed that closing the loop with every supplier matters more than checking a box for a specific list. “This is about really understanding in each part of the supply chain where data is stored, where is the server, what happens if the cloud crashes,” she said, adding that operators need clear contingency plans before any mission begins, not after something fails.
CMMC Compliance Meets Small Business Reality

The panel’s deepest dive centered on the Cybersecurity Maturity Model Certification framework, or CMMC, and its DFARS implementation. Wolff explained that CMMC exists to solve a problem the DoW has wrestled with since the 1998 Moonlight Maze intrusion: how to ensure contractors adequately protect sensitive government information. Earlier contract clauses failed, he said, so the government built a third-party attestation model requiring companies to meet roughly 110 security controls and then hire an assessor to verify compliance.
But Wolff argued CMMC solves only part of the problem. Controlled Unclassified Information (CUI), the category CMMC protects, spans roughly 40 different subcategories, from personally identifiable information (PII) to material once labeled “for official use only” (FOUO). That breadth, he said, makes the category almost impossible to protect uniformly.
He also raised a pointed concern about smaller drone manufacturers. “If you’re dealing with a 10 or 50 person organization that has 10 computers and a person named Joe or Josephine that’s protecting their infrastructure, it’s not reasonable for them to spend $15,000 on an assessor,” Wolff said. He called for a different compliance model tailored to small and medium-sized suppliers that make up the bulk of any defense weapons program’s supply base.
Hake reinforced the point from the resilience side. He cautioned that certification alone will not stop a determined adversary. “Compliance is often required, but rarely sufficient,” he said. Federal systems have been repeatedly penetrated by nation-state actors even after agencies spent billions meeting audit standards. He urged companies pursuing CMMC to also invest in penetration testing and adversary-style thinking about their internet-connected hardware, rather than treating a passed audit as the finish line.
Wolff pointed to a hopeful counterexample from this year’s DEFCON conference, where an AI-focused competition awarded prize money, including a $4 million top prize to Team Atlanta, for automatically discovering and patching vulnerabilities in critical infrastructure hardware and software without human intervention. Competitors found and fixed more than 800 vulnerabilities using AI alone. “This is where I’m a cyber optimist because we can do this now in the UAV industry. We couldn’t do it a year ago when I was on the same stage,” Wolff said.
Supply Chain Rules Upend Procurement Choices
Baxenberg walked through what she called a stressful holiday season for the industry. Six months before the panel, the FCC hit a statutory deadline to add DJI and Autel to its Covered List of equipment barred from receiving new RF equipment authorization, then surprised the industry by extending the ban to all foreign-produced critical UAS components. Existing equipment on the market is grandfathered, she noted, but manufacturers face real constraints on pushing software updates or swapping parts given tightening component availability.
Baxenberg reframed the restrictions as industrial policy rather than a simple ban. “I think these bans are broad and they sound scary, but ultimately what they are is the administration pushing industrial policy,” she explained. Companies can pursue conditional approvals and exemptions by working with the Department of Homeland Security (DHS) to demonstrate a credible path toward domestic manufacturing.
Morgan described living through that regulatory shock as an operator actively trying to build an American-made platform. “It is scary because your options are limited,” she lamented. She added that every industry event now surfaces new domestic suppliers worth vetting, but that rushing toward a compliant solution can compromise product quality if companies do not verify efficacy alongside origin.

Audience Questions Surface Emerging Risks
During the question period, a retired FAA official raised the issue of time spoofing, a less-discussed cousin of GPS spoofing. Baxenberg said the FCC is examining position, navigation and timing holistically, with a particular focus on combining ground-based terrestrial systems and satellite systems to improve resilience. She predicted timing attacks will become a bigger issue for drones as commercial aviation and advanced air mobility (AAM) operations grow more congested at low altitude.
A second audience question probed a scenario current compliance frameworks may not fully address: what happens when a cyberattack does not damage the drone itself but instead corrupts the AI model’s decision-making. Hake said adversaries are already experimenting with data poisoning attacks against AI systems, comparing early techniques to fake product reviews designed to manipulate Amazon’s ranking algorithm. He warned that poisoning a model requires far less data than training one. Hake referenced the earlier Latvia incident as a real-world case where a spoofed input led an otherwise correctly functioning AI model to execute an incorrect targeting decision. On liability, Hake noted the law remains unsettled. He pointed to Air Canada being held responsible for its chatbot’s erroneous promises as one precedent suggesting operators and deployers, not just software developers, may bear responsibility when autonomous decision-making goes wrong.
Daggett closed the session by tying the panel’s threads together. He told attendees that a true digital fortress for autonomous systems is not a single firewall or encrypted link. It is an ecosystem of resilient architecture, clean supply chains, disciplined training and clear legal frameworks. The choices companies make now in design, procurement and compliance will determine whether their operations remain secure when the environment turns hostile.
LTCO is made possible by the generous support of this year’s LTC Premium Sponsors: Akin (Gold), Crowell and Greenberg Traurig (Silver), Venable and GrandSKY (Bronze).
