Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

Market Research Intellect publishes "Global Cyber Security for Oil & Gas Market Size And Forecast"

This article is also available in French.

Market Research Intellect has published a market study on cybersecurity in the oil and gas sector, including projections extending to 2026.

The report, primarily focused on economic analysis and market trends, is available for purchase on the Market Research Intellect website.

The UK Department for Transport publishes an update to its port security guidance

This article is also available in French.

Following an initial publication in 2016, the UK Department for Transport has recently released an updated version of its guidance on good practices titled Cyber Security for Ports and Port Systems.

This 71-page guide, which can be compared to the work published by ENISA at the end of last November, brings together a set of best practices aimed at improving the management of cyber risks affecting port systems.

ENISA publishes a report on cybersecurity good practices for port systems

This article is also available in French.

On November 26, 2019, ENISA (the European Union Agency for Cybersecurity) published a report titled “Port Cybersecurity - Good practices for cybersecurity in the maritime sector”.

Like the rest of the maritime sector, ports are undergoing rapid digital transformation and increasingly evolving toward the concept of the smart port. The objective is to improve efficiency across logistics, safety, and financial performance.

France moves to strengthen its maritime cybersecurity capabilities

This article is also available in French.

Cyberattacks targeting the maritime sector are becoming increasingly frequent. Ships, ports, and logistics infrastructures are now part of the global digital threat landscape. In response, France has begun structuring an initiative aimed at strengthening cybersecurity across the maritime domain, with several major ports and industrial stakeholders preparing to play a role.

A widely cited example occurred in June 2017, when the shipping company Maersk suffered a major disruption following the spread of the Petya ransomware. The attack disabled thousands of servers and tens of thousands of workstations within the company’s infrastructure. The consequences extended beyond the company itself: operations at several major commercial ports were disrupted, and some facilities had to suspend activities temporarily.

Another submarine cable outage off the coast of Africa

This article is also available in French.

According to the newspaper Jeune Afrique, two submarine telecommunications cables were cut approximately 300 km off the coast of Cameroon. These two cables, named WACS and SAT3, each serve around ten countries across West Africa, from Senegal to South Africa.

Already affected by previous outages in 2007 and 2009, these cables are not the only ones serving West Africa, but their disruption still has a significant impact on the bandwidth available to telecom operators.

The Ryuk ransomware causes more than 30 hours of operational disruption for a maritime operator

This article is also available in French.

The website of the U.S. Coast Guard (which is involved in cyberspace issues, as mentioned in this article) reports that a U.S. maritime operator was impacted by the “Ryuk” ransomware.

This malicious code is not new. It first appeared in the summer of 2018 and has already affected numerous companies, such as Eurofins in the summer of 2019 or Prosegur more recently. As noted by CheckPoint, the malware is not particularly sophisticated from a technical perspective, but it specifically targets large companies and organizations with significant financial resources that may prefer to pay a ransom (which is not recommended and does not always work, particularly in the case of Ryuk) rather than lose several days of operations. As early as January 2019, it had already generated €3 million for its operators (source: Le Monde). In March 2019, the French cybersecurity agency ANSSI published both an alert bulletin and a news bulletin about this malware.