Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

Rising US–Iran tensions in the Persian Gulf raise concerns about GPS spoofing and jamming

This article is also available in French.

The U.S. administration has issued a maritime advisory for vessels transiting the Persian Gulf and surrounding waters. Among the risks identified are GPS interference (jamming or spoofing), as well as intrusion, jamming, and impersonation in VHF communications with ships. In some cases, vessels have reportedly impersonated U.S. or coalition ships over the radio.

Since May 2019, the U.S. authorities have recorded numerous unlawful activities in the region. In two of those cases, GPS interference occurred at the same time as other suspicious events.

Launch of an insurance product dedicated to maritime cyber risks

This article is also available in French.

In a press release, the insurer Willis Towers Watson announced the launch of a new insurance product specifically designed to cover cybersecurity risks in the maritime sector. The objective of this product is to address the incomplete coverage of cyber risks in most traditional insurance policies and to respond to the growing number of cyber incidents affecting the maritime industry.

The policy reportedly covers several situations, including: crisis management in the event of ransomware attacks, data theft, incidents involving third parties, loss of connectivity following attacks on satellite communication links, as well as cases related to GDPR and the NIS Directive.

U.S. Coast Guard responds to a cyber incident aboard a vessel

This article is also available in French.

A recent security advisory from the U.S. Coast Guard provides interesting details about a cyber incident that occurred in February 2019 aboard a deep-draft vessel (no further details were provided). The vessel, which was sailing on an international route bound for the Port of New York and New Jersey, notified the Coast Guard that it was experiencing a significant cyber incident affecting its onboard IT network.

The U.S. Coast Guard once again takes the lead on maritime cybersecurity issues

This article is also available in French.

The U.S. Coast Guard (USCG) is frequently involved in initiatives related to maritime cybersecurity. They were recently seen responding to a vessel affected by a cyber incident and also reporting on the impact of the Ryuk ransomware on a U.S. maritime operator. In their security bulletins, they also regularly address cyber threats in the maritime environment.

In a new circular, available as a PDF on the USCG website, the U.S. Coast Guard proposes updated guidance for addressing cyber threats affecting facilities and vessels under their authority.

Cyber risks associated with satellite positioning systems

This article is also available in French.

Today, the relatively low cost (a few tens of euros for a basic receiver), the miniaturization of hardware, and the widespread availability of GPS receivers have led many to assume that this global infrastructure will always be available. These advantages have also enabled the rapid expansion of GPS usage across many sectors where it was previously absent: healthcare, pet tracking, sports, agriculture, domestic robotics such as lawn mowers, photography, and even port cranes (see also this article). As a result, it is now difficult to estimate how many GPS receivers are currently deployed worldwide.

According to Lloyd’s, a cyberattack on Asian ports could cost $110 billion

This article is also available in French.

According to a report published by Lloyd’s of London in collaboration with CyRiM (see the video on Vimeo and the full PDF report), and relayed by the news agency Reuters, a cyberattack targeting Asian ports could result in losses of up to 110 billion dollars. This amount is roughly equivalent to half of the total economic losses caused by natural disasters in 2018.