Skip to content
avatar

Maritime and port cybersecurity.

Maritimeinfosec.org is an analysis site dedicated to maritime and port cybersecurity. Its articles offer insights into cyber threats, system vulnerabilities, and the digital challenges of the maritime sector, drawn from an operational reading of risks informed by the author’s experience and background.

The U.S. Coast Guard once again takes the lead on maritime cybersecurity issues

This article is also available in French.

The U.S. Coast Guard (USCG) is frequently involved in initiatives related to maritime cybersecurity. They were recently seen responding to a vessel affected by a cyber incident and also reporting on the impact of the Ryuk ransomware on a U.S. maritime operator. In their security bulletins, they also regularly address cyber threats in the maritime environment.

In a new circular, available as a PDF on the USCG website, the U.S. Coast Guard proposes updated guidance for addressing cyber threats affecting facilities and vessels under their authority.

Cyber risks associated with satellite positioning systems

This article is also available in French.

Today, the relatively low cost (a few tens of euros for a basic receiver), the miniaturization of hardware, and the widespread availability of GPS receivers have led many to assume that this global infrastructure will always be available. These advantages have also enabled the rapid expansion of GPS usage across many sectors where it was previously absent: healthcare, pet tracking, sports, agriculture, domestic robotics such as lawn mowers, photography, and even port cranes (see also this article). As a result, it is now difficult to estimate how many GPS receivers are currently deployed worldwide.

According to Lloyd’s, a cyberattack on Asian ports could cost $110 billion

This article is also available in French.

Container ship loaded at a port terminal

According to a report published by Lloyd’s of London in collaboration with CyRiM (see the video on Vimeo and the full PDF report), and relayed by the news agency Reuters, a cyberattack targeting Asian ports could result in losses of up to 110 billion dollars. This amount is roughly equivalent to half of the total economic losses caused by natural disasters in 2018.

The United States raises concerns with the International Maritime Organization over the surge in satellite navigation signal disruptions

This article is also available in French.

I have mentioned this several times before: GPS signals (and GNSS more broadly) are essential for the safe day-to-day operation of the maritime sector. We have already discussed the risks associated with spoofing or jamming of these signals, the specific risks related to autonomous maritime vehicles, as well as several real-world examples, including incidents in the Persian Gulf.

On March 10, 2020, the United States formally raised concerns with the Maritime Safety Committee of the International Maritime Organization (IMO) regarding the increasing number of disruptions affecting GPS and GNSS signals. The submission, available as an IMO document (PDF), calls on the IMO to urgently address cases of jamming and spoofing that threaten the safety of ships and seafarers.

Cyber threats in the maritime sector: have all scenarios really been considered?

This article is also available in French.

The Bordeaux-based maritime insurer Adam Assurances has published a study on cyber risks affecting the maritime sector, available as a blog article and in PDF format.

After recalling the digital transformation underway across the maritime industry and the growing dependency that accompanies it, the insurer reviews several cyber incidents that have already affected the sector (MSC, COSCO, Maersk, among others).

Cyberattack on MSC confirmed by the shipping company

This article is also available in French.

As mentioned in a recent article, the shipping company MSC was the victim of a cyberattack about a week ago. The incident disrupted the operation of its online booking systems for four days.

In a recent statement, the company confirmed the cyber origin of the incident, which affected several servers located in Geneva: “we have determined that it was a virus attack exploiting a targeted vulnerability.”