Skip to content
avatar

Maritime and port cybersecurity.

Maritimeinfosec.org is an analysis site dedicated to maritime and port cybersecurity. Its articles offer insights into cyber threats, system vulnerabilities, and the digital challenges of the maritime sector, drawn from an operational reading of risks informed by the author’s experience and background.

Hyundai Heavy obtains cybersecurity certification for a VLCC

This article is also available in French.

The South Korean manufacturer Hyundai Heavy Industries has announced that it obtained a cybersecurity certification from the American Bureau of Shipping (ABS) for a Very Large Crude Carrier (VLCC) scheduled to be delivered to a European client in November 2018 (possibly the Greek company Okeanis?).

There are few details available, but the certification reportedly reflects work carried out on the security of the vessel’s industrial control systems.

Cybersecurity partnership between KPMG and Kongsberg

This article is also available in French.

I suggest reading this short article, which reports on a partnership between KPMG, the audit and consulting firm, and the Norwegian manufacturer Kongsberg, which designs systems for the oil and gas industries as well as the maritime sector.

There are not many details available, but it is nonetheless interesting to see manufacturers finally paying closer attention to the cybersecurity of their systems and turning to external audit and consulting firms for support. Let us hope they will find at least part of the solution there—bearing in mind that the problem, as always, is far from simple.

Windows XP (and ME) still in use in the Royal Navy

This article is also available in French.

I recommend reading this article from The Register about the challenges of updating systems aboard Royal Navy vessels (and the 129 comments that follow it…).

The article reveals that the Royal Navy is still using obsolete versions of Windows, namely Windows ME and Windows XP. How did they find out? Quite simply: the journalist… asked the question while embarked aboard HMS Enterprise.

The specific characteristics of maritime information systems

This article is also available in French.

The — relative — misunderstanding between traditional cybersecurity vendors and users of maritime information systems generally stems from a lack of familiarity with the maritime environment and from the difficulty of adapting or integrating conventional systems with the constraints of this sector. In this article, I describe some of the characteristics of the maritime environment that explain why a specific approach is necessary when deploying off-the-shelf systems and software in this domain.

Maritime information systems

In this article, I explain in more detail what a maritime information system is, attempting to classify them as clearly as possible.

Maritime information systems can refer to different types of infrastructure:

  • ships:
    • merchant vessels
    • warships
    • recreational vessels
    • fishing vessels
    • scientific / hydro-oceanographic / fisheries research vessels
    • barges
  • ports and naval infrastructures:
    • container loading/unloading systems, smartports, logistics systems
    • Port and Cargo Community Systems
    • cranes and gantries
    • dock and basin management systems
    • locks
    • pipelines
  • other onshore facilities:
    • maritime informatics of signal stations, MRCC (Maritime Rescue Coordination Centers), ship command and management centers
  • offshore installations:
    • drilling platforms
    • Marine Renewable Energies (MRE): wind turbines, tidal turbines…

Next, to make things easier to understand, I tend to divide systems into two major families: “IT” systems (Information Technology), which are fairly similar to what can be found in other sectors, and “OT” systems (Operational Technology), which, to simplify, could be described as “operational systems”, more specific to the maritime information domain.

The U.S. maritime industry poorly prepared for cyber threats

This article is also available in French.

Worth reading today: a study published by Jones Walker LLP on maritime cybersecurity in the United States.

The survey, conducted among 126 U.S. executives, indicates that 38% of them confirmed having experienced either successful intrusions (10%) or attempted intrusions (28%). The remainder may simply not have detected them, you might say—which is not an unreasonable assumption.

While 69% of respondents expressed confidence in the overall preparedness of the maritime sector, only 36% believe that their own company is adequately prepared. The most concerning results come from small and medium-sized enterprises in the sector, 94% of which consider themselves poorly prepared.