Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. A launcher explosion destroys a telecommunications satellite worth several hundred million in seconds. What distinguishes this loss from most industrial losses of the same size?
It is instantaneous, total and leaves no wreckage to survey
Launch insurance covers the phase from engine ignition to separation and initial positioning, sometimes extended to the first months in orbit, and that phase concentrates most of space risk. What makes it singular is not the amount, which industry can match, but the shape of the loss: it is instantaneous, it is total, and it leaves nothing to examine. A factory fire leaves walls, records and witnesses, and its figure is built over months of survey; a launch failure leaves a few seconds of telemetry and debris scattered at sea. The practical consequence is that all the insurer's work moves before the shot, into examining the vehicle's reliability, the payload and the procedures, since nothing can be worked up afterwards. It should be added that this market is narrow and concentrated on a few specialist carriers, which makes it strongly cyclical: a run of failures can consume several years of premium and harden terms abruptly, without any insured having changed anything about its own risk.
Glossary entry · assurance-lancement2. On 4 June 1996, Ariane 5's maiden flight ended in self-destruction thirty-seven seconds after lift-off, on a guidance software error. What does this case illustrate for pricing a maiden flight?
The fault appears on the first real flight, which ground simulation does not fully reproduce
Launcher failure rates are structurally higher on maiden flights than across a mature fleet, and this is not a market impression but a statistical regularity of the sector. The reason lies in the nature of the faults involved: design, integration or procedural errors that appear in real conditions and that ground simulation does not fully reproduce. The 1996 flight is the canonical example, since the cause was neither an engine nor a structure but guidance software carried over from an earlier vehicle into a different flight envelope: exactly the kind of fault no partial test brings out. An insurer therefore applies to a new vehicle's first commercial flight a premium well above that of a proven launcher, and the point to retain is that this loading does not pay for vague uncertainty but for the absence of history specific to that vehicle. Some operators draw the opposite conclusion and delay launching their most valuable payload until the vehicle has accumulated a few successes, which is a scheduling decision before it is an insurance one.
Glossary entry · risque-vol-inaugural3. Since the Commercial Space Launch Act of 1984, every US launch licence requires the state, the launch provider and the payload operator to waive all recourse between them. What does that impose on the operator?
Insuring its own damage, no recourse against a party at fault being open
The reciprocal waiver is a standard clause in launch contracts, imposed by several national frameworks as a licence condition: each party waives all recourse against the others for damage it or its property suffers, regardless of fault. Each therefore carries its own risk and its subcontractors', and covers itself with first-party insurance rather than counting on recourse. The motive is industrial before it is legal: a launch brings together a state, a launch provider, an engine maker, a satellite manufacturer, equipment suppliers and sometimes several customers under one fairing, and without the clause every failure would become years of litigation over apportioning fault between parties who must go on working together. The consequence for the insurer is twofold and must be seen whole: subrogation, elsewhere a real part of a file's value, is worth almost nothing here, and the premium must carry the entire risk alone. It is also why space cover is property cover, where intuition would expect liability.
Glossary entry · renonciation-reciproque-responsabilite4. The 1972 convention on liability for damage caused by space objects sets two regimes according to where the damage occurs. Which, and what does that change?
Absolute liability on the ground and to aircraft, fault-based liability in orbit
The convention refines and completes the principle of state liability laid down by the 1967 treaty, and its distinction is the pivot of the whole legal treatment of collisions and re-entries. For damage caused on the ground or to aircraft in flight, the launching state bears absolute liability: the victim need not prove fault, which makes sense since they chose nothing and have no means of establishing what happened hundreds of kilometres up. For damage caused in orbit to another space object, liability rests instead on proof of fault, the logic being that both parties are informed operators, voluntarily present in the same environment. That asymmetry has a very concrete practical consequence, and it is the one to keep: establishing fault in orbit means showing who ought to have manoeuvred, on the strength of which conjunction data and within what window, about destroyed objects of which only debris remains. The convention finally organises claims between states, adding a diplomatic tier where an insurer would want a counterparty.
Glossary entry · convention-responsabilite-19725. On 10 February 2009, the active satellite Iridium 33 struck the defunct Russian satellite Kosmos 2251 at over eleven kilometres per second, producing some two thousand trackable pieces of debris. How does this peril differ from an internal failure?
It depends on the orbital environment, and its loss degrades that environment for everyone
An internal failure belongs to the craft: it depends on its design, its components and its operation, meaning things the insurer can examine at the insured's. Collision depends on something else, the density of objects at a given altitude and the quality of conjunction tracking, that is, on a shared environment no operator controls alone. The relative speed, here over eleven kilometres per second, is enough to destroy both objects entirely, and that is not the only consequence. The debris cloud produced often persists for years and degrades the orbit for everyone occupying it, making this one of the few perils whose loss raises the probability of the next. An insurer therefore sees a risk that does not diversify like others: covering ten satellites at the same altitude is not covering ten independent risks. Note finally that operators with propulsion manoeuvre to avoid ever more often, which burns propellant and shortens useful life, while non-manoeuvrable satellites stay fully exposed.
Glossary entry · collision-orbitale6. On 15 November 2021, a missile destroyed the defunct satellite Cosmos 1408, producing more than fifteen hundred trackable pieces of debris and forcing the International Space Station crew into their escape vehicles. What question does this event put to space policies?
That of the war or hostile act exclusion, for damage suffered by unintended third parties
An anti-satellite test differs from an accidental collision on a point that changes everything for drafting: it is intentional, and its scale is foreseeable to the state conducting it. The consequences, by contrast, escape all control once the cloud exists, spreading across a wide range of altitudes and orbital lifetimes, with some fragments threatening satellites and crews for years. The insurance difficulty is there: the act is hostile or military in nature, which calls up the war exclusions present in most space policies, but the eventual damage strikes civil operators who are party to nothing and whom nobody targeted. Applying the exclusion to the letter would leave without cover an operator whose satellite is destroyed by debris from a test conducted on the other side of the world years earlier; not applying it would make the market carry a consequence of state action. It is a drafting question before it is a claims question, and it is settled in the definition of a hostile act rather than in argument after the event.
Glossary entry · essai-antisatellite-asat7. Between 2017 and 2019, propulsion leaks affecting several satellites of one model were settled not as total losses but as partial losses indexed to the reduction in useful life. How does that settlement work?
A scale on lost capacity or years, with a threshold tipping into total loss
Few space failures are as clean as an explosion at launch. A satellite can lose part of its transponders, its electrical power or its expected years of service without ceasing to transmit, and that is in fact the commonest case once in orbit. The partial loss clause indemnifies that degradation without waiting for a total loss, on a scale set in the policy, often as a percentage of the insured value, computed on capacity lost or on the shortening of useful life against what was expected at inception. A cumulative degradation threshold, generally around half the capacity or value, triggers constructive total loss: the insurer then settles as for a total loss and takes over the degraded asset where appropriate. What this mechanism avoids deserves seeing, because it has no immediate equivalent elsewhere: without it the insured would choose only between operating a diminished asset for nothing and claiming a total loss the facts do not support. The scale is therefore where the cover's real value is decided, far more than the sum insured.
Glossary entry · clause-perte-partielle8. In April 2010, a geostationary satellite lost all control from the ground while continuing to transmit on its frequency band, drifting for months across the geostationary belt. Why is this case hard to classify?
The asset is intact and still transmitting, while its operation is lost
A drifting satellite, sometimes called a zombie satellite, has lost all control from the ground after an electronic or software failure, yet stays physically intact and sometimes keeps transmitting on its original frequencies. The classification difficulty lies exactly in that gap: the operator's loss of use is certain and permanent, while the asset is not destroyed and a surveyor looking at it would see nothing broken. Policies handle this through constructive total loss, which looks at use rather than physical integrity, and it is one of the few places in insurance where a still-working asset is indemnified. A second problem follows, belonging not to the insured but to its neighbours: the craft drifts unmanoeuvrable through closely coordinated orbits, the geostationary belt in particular, and the interference it keeps emitting disturbs operators along its path. One event therefore produces both a first-party loss and a liability exposure towards third parties with no connection to the failure, and the two are handled in neither the same policy nor on the same evidence.
Glossary entry · satellite-derive-incontrole9. A constellation numbers thousands of identical satellites in low orbit, mass-produced and run by one operator. What does that model change about accumulation, compared with a fleet of large geostationary satellites?
A production-run defect or a degraded orbit strikes the whole fleet at once
Intuition says a large number of units diversifies, and it does when the units are independent. Here they are not, for two compounding reasons. The first is manufacturing: mass-produced satellites share a design, components and procedures, so a production-run defect does not spread out, it strikes the whole model. The second is orbit: the congestion created by deploying thousands of objects raises the probability of collisions, whose debris in turn feeds a runaway effect, and a degraded orbital environment strikes the entire fleet occupying it at once. It is the same mechanism as a single point of failure in cyber, transposed to a physical medium: a shared dependency the unit count does not reveal. A third exposure follows, belonging not to the operator but to its customers: the growing dependence of critical services on these constellations creates a failure-of-supply risk whose losses will occur outside space altogether. It is that bundle, more than unit value, that makes the model hard to insure.
Glossary entry · risque-megaconstellation