Explore the maritime cyber security threats facing vessels, ports and shoreside teams, from ransomware and phishing to IoT vulnerabilities, supply chain risk and onboard system exposure.
As the maritime sector embraces connectivity, digitisation, automation and IoT, its exposure to cyber risk has increased sharply. The report notes that maritime cyber attacks have reportedly risen by 900%, while the average time to identify an attack inside a ship's system is 140 days. A single coordinated cyber attack on major Asia-Pacific ports could cost an estimated $110 billion.
The threats are already affecting vessels, ports and supply chains. In January 2023, a ransomware attack on DNV's ShipManager software affected around 1,000 vessels, while the Port of Lisbon was hit by the LockBit group, which demanded a $1.5 million ransom. The report also highlights the risk of phishing, IT supply chain compromise, legacy systems, connected navigation systems, cargo handling systems, AIS, GPS, ECDIS and IoT devices.
With only 55% of organisations offering regular cyber security safety training, this report explains why tailored cyber security awareness for crew, officers, masters and shoreside personnel is essential to reducing maritime cyber risk.
In this free eBook, you'll discover:
TSC helps maritime organisations reduce human error risk through practical security awareness training tailored to crew, officers, masters and shoreside teams. We help people recognise phishing, ransomware, IoT risks, supply chain threats and unsafe behaviours that could expose vessels, ports and critical systems.
View the report Book an eLearning demo
Maritime cyber security is important because vessels, ports and shipping operations now rely on connected systems, IoT devices, cloud services, navigation technology and digital communications. If these systems are compromised, attackers can disrupt operations, steal data, affect safety and damage commercial reputation.
Key maritime cyber risks include phishing, ransomware, IT supply chain compromise, legacy systems, insecure IoT devices, unpatched onboard systems, weak security practices and attacks on AIS, GPS, ECDIS, cargo handling, communication and engine room systems.
Maritime companies can reduce cyber risk by training crew and shoreside staff, improving phishing awareness, securing IoT and onboard systems, managing third-party suppliers, updating legacy equipment where possible, monitoring vessel systems and building secure working practices across ship and shore operations.