Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

Naval Dome provides cyber defense for a yacht

This article is also available in French.

Naval Dome, an Israeli company, announced that it has equipped a luxury yacht (MY Lucky Me) with its maritime cybersecurity solution.

According to the company, the solution includes host-level protection (endpoint protection) combined with cloud-based cybersecurity capabilities (cloud-based solution). Nothing particularly revolutionary at first glance, but what stands out most is the integration approach: rather than operating in isolated silos, the solution appears to cover both IT and OT systems on board. That is clearly the direction the sector should be moving toward.

COVID-19: 400% increase in attempted cyberattacks in the maritime sector

This article is also available in French.

The website offshore-energy.biz reports that the number of attempted cyberattacks in the maritime sector has increased by 400% since February 2020. This surge is reportedly linked in part to the widespread adoption of remote working tools during the COVID-19 pandemic.

The figure was cited by Naval Dome, an Israeli cybersecurity company previously mentioned on this site, notably in relation to the cyber defense of a yacht. Within this reported 400% increase, Naval Dome notes a rise in various forms of malware, including ransomware, as well as phishing attempts. These developments occur in a context where social distancing measures, travel restrictions, and economic difficulties have limited the ability of maritime companies to maintain their usual cybersecurity posture.

The European Space Agency funds research on risks related to satellite positioning systems

This article is also available in French.

As discussed several times on this site, the risks associated with satellite-based positioning and vessel tracking systems are numerous. In this context, the European Space Agency (European Space Agency, ESA) has recently announced that it is funding a feasibility study to develop solutions aimed at securing these systems.

ESA has awarded a contract to the Swiss company CYSEC SA to identify possible approaches for strengthening the security of satellite-based ship tracking and positioning services used in the maritime sector. The main risks involve spoofing and jamming of satellite positioning systems (GNSS), as discussed previously in relation to US-Iran tensions in the Persian Gulf and GPS spoofing and jamming.

Estonia receives €2.5 million from the European Union to create a maritime cybersecurity center

This article is also available in French.

The Digital Forensics and Cybersecurity Center of the Tallinn University of Technology (TalTech) and the Estonian Maritime Academy have received nearly €2.5 million in funding from the European Union to establish a maritime cybersecurity center.

Dan Heering, one of the project leaders at the Estonian Maritime Academy, explains that “the maritime industry has never really taken cybersecurity seriously, and there is still a great deal of work to be done in this area. Because there is very little publicly available information about successful cyberattacks or incidents involving ships, shipowners often underestimate the threat.”

Known incidents

This article is also available in French.

This article lists nearly 80 public incidents that have affected the maritime sector, deliberately or otherwise, over the past twenty years. It is not intended to be exhaustive, but please let me know if you are aware of other public and corroborated cases. The aim is not to single out a company or a state, but to raise awareness of incidents that have already occurred and, when known, their consequences. I will add more over time. As always, attribution and sources should be treated with caution, as should the apparent increase in the public number of incidents. I am also gradually adding submarine cable outages.

Possible cyberattack targeting Iranian ports in the Strait of Hormuz

This article is also available in French.

According to ZDNet and Ilna News, Iranian officials acknowledged last Sunday that a limited number of computers were affected following a cyberattack targeting the port of Bandar Abbas in the Strait of Hormuz. ZDNet even reported that port operations were temporarily halted on Friday.

Beyond these official statements, very few details about the incident have been disclosed.