Maritime Cybersecurity: The Most Sensible Solutions in 2025

The industry has been losing billions of dollars to maritime cybersecurity events which calls for immediate, sensible solutions to prevent the attacks.

Since 2024, the shipping industry has been in serious danger of losing billions of dollars to maritime cybersecurity due to the recent escalation in data breaches, operational disruptions, and ransomware attacks. This calls for immediate, sensible solutions to prevent continued maritime cybersecurity attacks in the industry.

Rising Cybersecurity Threats Against Ships’ Digital Systems

Most modern vessels have built-in digital systems that enhance their functionalities, such as navigation and control systems, monitoring systems, security systems, and communications and connectivity systems. The year 2024 marked a period of heightened maritime cybersecurity attacks in the global shipping industry.

The statistics in the table below paint a gloomy reality about the rising maritime cybersecurity threats against shippers. All of these attacks occurred only in the first half of 2024 [1]:

Types of Cybersecurity events/attacksAmount  
Malware 23,400 detected
Ransomware incidents178 reported
Firewall events50+ billion recorded
Security alerts14.8 billion flagged

Exploring the Vulnerabilities in Port Operational Technologies

There have been reports of several ports incurring huge losses due to some maritime cybersecurity events despite being equipped with modern infrastructure. For instance, in April 2024, multiple ports came under well-coordinated cyberattacks that resulted in disruptions in operations and misrouted cargo, leading to substantial financial losses exceeding $500 million. The attackers deployed sophisticated ransomware and malicious software to cripple port operations and manipulate Automatic Identification Systems (AIS) on multiple ships, leading to substantial delays, misrouted cargo, and increased risk of collisions and grounding.

Cyber attack DNV
Cyber attack on ShipManager, a DNV software

DNV has reported a cyber attack on its ShipManager software that forced the company to take its dedicated ShipManager servers offline.

Ship Nerd

Other recent destructive cyberattacks include the MarineMax 2024 Ransomware attack that compromised MarineMax’s (the US boat retailer’s) accounting system and released sensitive financial documents, employee records, customer information, and other confidential data online.

Similarly, the 2023 DP World Australia’s cyberattack reportedly created a backlog of 30,137 containers, halting ports’ operations and causing logistics delays. Significant breaches were also reported by BR Logistics, USA and Magsaysay Maritime Corporation(MMC), Philippines, whereby LockBit 3.0 and Monti ransomware were deployed to disrupt these companies’ operations.

It was pointed out that the weaknesses in some ports’ operational technologies (OT) were responsible for the seriousness of some cyberattacks. For instance, a large percentage of ports still rely on legacy systems with outdated hardware and software that are not updated to handle modern cyberattacks. Others have AIS and GPS systems that cybercriminals can easily manipulate, while some ports’ IoT devices are unsecured. These structural weaknesses in ports’ operational technologies readily expose them to ransomware and data breaches, disrupting the global shipping supply chain. [2] [3]

Organization Guidelines on Maritime Cybersecurity Management

The International Maritime Organization (IMO) provided useful guidelines and high-level recommendations on maritime cyber risk management, including MSC-FAL.1-Circ.3-Rev.2, which highlights some functional requirements or elements that must be incorporated into shipping companies’ existing risk management procedures to reduce the occurrence of maritime cybersecurity.

In addition, IMO’s Resolution MSC.428(98) requires that shippers’ administrations should handle the issue of maritime cybersecurity as an integral part of their safety management measures under the ISM Code.

Other organizations have also weighed in and offered recommendations on how best to manage cyber risks in the shipping industry. They include:

  • The International Association of Classification Societies (IACS) published a Consolidated Recommendation on Cyber Resilience (Rec. 166) and, with its UR E26 and E27, IACS highlights the minimum technical requirements on vessels in order to become cyber-resilient.
  • BIMCO developed Guidelines on Cyber Security Onboard Ships aimed at creating awareness about maritime cyberattacks, safeguarding shipboard IT and OT systems, and encouraging a prompt response to instances of cyberattacks to prevent further operational disruptions.
  • In strict compliance with IMO’s maritime cybersecurity guidelines and BIMCO’s Guidelines on Cyber Security Onboard Ships, INTERTANKO has equally published its own guidance in relation to how shippers can identify and prevent jamming and spoofing so as to protect their tanker operations against cyber interference.
  • ISO/IEC 27001 provides details about the necessary security techniques shippers need to implement to protect and enhance their information security management systems.
Guidance on cyber risk management beyond IMO 2021
Guidance on cyber risk management beyond IMO 2021

How the shipping industry can raise cyber risk management standards amid escalating threats to maritime cyber security is demonstrated.

Ship Nerd

Implementing Helpful Cybersecurity Frameworks in the Shipping Industry

Two of the most common maritime cybersecurity frameworks employed in the shipping industry include the POSEIDON Shield and the NIST Cybersecurity Framework.

The POSEIDON Shield was developed by ADACOM and designed to provide some resilience for shippers in the event of cyberattacks. The Framework provides solutions to safeguard ships’ digital infrastructure and operational technology (OT) and IT systems. It outlines incident response strategies that should be immediately carried out to lessen the effects of cyber threats. POSEIDON Shield is well regarded for its strict compliance with existing international maritime cybersecurity guidelines and regulations.

The five main elements of the NIST Cybersecurity Framework (CSF) are: (i) identify (assets that are vulnerable to cyberattacks); (ii) protect (IT & OT systems); (iii) detect (cyber threats using monitoring systems); (iv) respond (instantly to cybersecurity threats); (v) and recover (by ensuring business continuity). CSF 2.0, which is the latest Framework, includes undertaking incident response and supply chain cybersecurity risk management.

Available Solutions to Tackle Cybersecurity Threats

The shipping industry has taken some strategic steps to protect their activities from being disrupted by cyberattacks. Highlighted below are some of the actions currently taken to safeguard international operations:

  1. Undertaking Zero Trust Security Model: This entails that shippers must continuously undertake the verification of their devices and users utilizing the most appropriate authentication protocols and allowing only authorized users to have access to their sensitive devices.
  2. Putting in Place Endpoint Protection & Network Security: This involves setting up intrusion detection systems (IDS), firewalls, and endpoint security solutions to prevent maritime cybersecurity events from happening.
  3. Utilizing Cloud Security & Data Protection: Shippers are protecting their digital systems by implementing encryption, multi-factor authentication (MFA), and secure access controls in strict compliance with ISO 27001, NIST cybersecurity standards, and GDPR.
  4. Using AI-Powered Threat Detection: With the advent of AI, shippers are now using AI-powered detectors for identifying cyber threats beforehand. They can assist shippers in detecting ransomware, phishing, and malware in real time.

For shippers without in-house cybersecurity experts or IT personnel, some maritime cybersecurity companies or agencies can help them monitor their operations, identify any cyber threats in real time, and set up security systems for their clients’ vessels.

Key Takeaways

The shipping industry cannot afford to let the increasing cybesecurity threats destabilise their routine operations, even as the current, Trump Administration-led Trade War has already created some level of distability and volatility in the global marine dynamics.

See Also

Blockchain Tech for Safe Chemical Cargo Transport
Blockchain Tech for Safe Chemical Cargo Transport

GSBN partners with Chinese companies to enhance the transportation of chemical cargo safety using blockchain technology.

Ship Nerd
Author