Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

Chinese cyberattacks reportedly targeted the military maritime sector

This article is also available in French.

According to the Wall Street Journal, cyberattacks attributed to Chinese actors have targeted at least 27 universities in Canada, Southeast Asia, and the United States since at least April 2017, including institutions such as MIT, the University of Hawaii, and the University of Washington.

The objective? The attackers reportedly sought to obtain sensitive information related to military technologies in the maritime domain. The attack vector appears to have been relatively conventional: a spear-phishing campaign.

The U.S. Navy and its partners face a wave of cyberattacks

This article is also available in French.

Following a first alarming article published last week, a Wall Street Journal article dated March 12, 2019 confirms growing concerns regarding the U.S. military maritime sector.

Referring to a 57-page internal report submitted to then-Secretary of the Navy Richard Spencer, the newspaper states that the U.S. Navy and its industrial partners are effectively under “cyber siege.” Once again, China is explicitly identified as the main actor, accused of having stolen sensitive military information over recent years, potentially threatening the United States’ position as the world’s leading military power.

GPS, maritime systems and April 6, 2019

This article is also available in French.

Since February, several media outlets - both newspapers and television - have raised concerns about the Week Number Rollover scheduled for April 6, 2019. With alarmist headlines, some even suggest you might need to pull out your paper charts again. So who should we believe? What are the real implications for maritime information systems?

On April 10, 2018, the U.S. Department of Homeland Security, and more specifically CERT-ICS, published a memorandum aimed at users of the GNSS (Global Navigation Satellite System), particularly GPS (Global Positioning System).

Three areas of focus for the U.S. Navy in cybersecurity

This article is also available in French.

This fairly comprehensive and candid article on the U.S. Navy’s cybersecurity priorities deserved a brief analysis.

The U.S. Navy acknowledges - although this was already known - that it has been the target of cyberattacks on several occasions, with varying degrees of severity and impact. On January 7, 2019, the Naval Air Systems Command announced new research efforts across no fewer than 36 domains, ranging from artificial intelligence to resilience, as well as endpoint and server security.

Hack.lu 2018: how to hack a yacht

This article is also available in French.

This video was recorded during the well-known hack.lu 2018 conference in Luxembourg. In the first part, Stephan Gerling presents his view of maritime information systems and briefly discusses services such as GPS and AIS. He then focuses on ship-to-shore connectivity, particularly satellite communications.

Release of the 3rd edition of the cybersecurity best practices guide for the maritime industry

This article is also available in French.

There are many recommendation guides for implementing cybersecurity measures in the maritime sector. Perhaps too many, and of uneven quality, which can sometimes make things difficult to navigate (put yourself in the shoes of the seafarer or the shipowner who must understand and apply them).

Among these guides, one nevertheless stands out as a reference, both because of the number of associations and major industry stakeholders involved in its development (21 in total) and because it addresses the maritime world in its own terms, adapting cyber threats to the specific characteristics of this sector. This guide, “The Guidelines on Cyber Security Onboard Ships,” has just been released in its third edition.