Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

The specific characteristics of maritime information systems

This article is also available in French.

The - relative - misunderstanding between traditional cybersecurity vendors and users of maritime information systems generally stems from a lack of familiarity with the maritime environment and from the difficulty of adapting or integrating conventional systems with the constraints of this sector. In this article, I describe some of the characteristics of the maritime environment that explain why a specific approach is necessary when deploying off-the-shelf systems and software in this domain.

Maritime information systems

In this article, I explain in more detail what a maritime information system is, attempting to classify them as clearly as possible.

Maritime information systems can refer to different types of infrastructure:

  • ships:
    • merchant vessels
    • warships
    • recreational vessels
    • fishing vessels
    • scientific / hydro-oceanographic / fisheries research vessels
    • barges
  • ports and naval infrastructures:
    • container loading/unloading systems, smartports, logistics systems
    • Port and Cargo Community Systems
    • cranes and gantries
    • dock and basin management systems
    • locks
    • pipelines
  • other onshore facilities:
    • maritime informatics of signal stations, MRCC (Maritime Rescue Coordination Centers), ship command and management centers
  • offshore installations:
    • drilling platforms
    • Marine Renewable Energies (MRE): wind turbines, tidal turbines…

Next, to make things easier to understand, I tend to divide systems into two major families: “IT” systems (Information Technology), which are fairly similar to what can be found in other sectors, and “OT” systems (Operational Technology), which, to simplify, could be described as “operational systems”, more specific to the maritime information domain.

The U.S. maritime industry poorly prepared for cyber threats

This article is also available in French.

Worth reading today: a study published by Jones Walker LLP on maritime cybersecurity in the United States.

The survey, conducted among 126 U.S. executives, indicates that 38% of them confirmed having experienced either successful intrusions (10%) or attempted intrusions (28%). The remainder may simply not have detected them, you might say - which is not an unreasonable assumption.

While 69% of respondents expressed confidence in the overall preparedness of the maritime sector, only 36% believe that their own company is adequately prepared. The most concerning results come from small and medium-sized enterprises in the sector, 94% of which consider themselves poorly prepared.

Useful links

A selection of reference websites and documents on maritime and port cybersecurity. This is a long-term effort, so the list is certainly still incomplete. A French version of this page is also available, with the addition of the French national framework.

  • NORMA Cyber, the Norwegian Maritime Cyber Resilience Centre
  • MTS-ISAC, the Maritime Transportation System Information Sharing and Analysis Center
  • IAPH, the International Association of Ports and Harbors

Most of the awareness videos I collect are gathered in a dedicated YouTube playlist:

Threat sources targeting the maritime sector

This article is also available in French.

Who might want to target maritime information systems?

Intentional threat sources are broadly similar to those encountered in other sectors. Rather than reproducing a long and exhaustive list of possible threat actors, it is worth noting that the French cybersecurity agency ANSSI has already documented them in detail (see p. 15 and following pages in the reference below).

Today, the most realistic threat sources include: