Threats and vulnerabilities:
- Ship systems increasingly rely on networked IT and OT (operational technology) - the bridge (ECDIS, GPS, AIS, radar, VDR), the engine control and monitoring systems, the cargo/ballast control, the power management, and the ship-to-shore communications (VSAT, email, internet).
- Threats: malware/ransomware, phishing and social engineering of crew, unauthorised access, denial-of-service, spoofing of GPS/AIS (spoofing, jamming), and attacks that could manipulate navigation, propulsion or cargo systems; also the risk of a compromised shore/company network or a malicious USB/email.
- Vulnerabilities: default passwords, unpatched software, open/unsupervised ports (USB, network), lack of segregation between IT and OT, crew using personal devices, weak access control, and the increasing connectivity (remote monitoring, e-navigation) that expands the attack surface.
Protective measures and best practices:
- Adopt a cyber security management approach (e.g. the IMO's Guidelines on Maritime Cyber Risk Management and the ISM Code - cyber risks should be addressed in the SMS; the IMO Resolution MSC.428(98) requires cyber risk management to be incorporated into the SMS).
- Implement access control (strong passwords, multi-factor, least privilege), network segmentation (separate the OT from the IT and the internet), firewalls and intrusion detection, and regular patching/updates.
- Restrict and control removable media and USB ports; use secure email/web; train the crew in cyber hygiene (recognising phishing, not using unauthorised devices).
- Back up critical data and systems; have a cyber incident response plan; monitor and log network activity; and conduct regular cyber risk assessments and drills.
- Ensure the ship's systems are configured securely (disable unnecessary services, change default settings) and that remote access is controlled and encrypted.
- IMO Resolution MSC.428(98) (2017) and the IMO Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3) require that cyber risk management be addressed in the Safety Management System (ISM) - i.e. cyber risks are to be considered as part of the ship's safety management, and the flag/RO audits verify that cyber risk management is incorporated. This is a mandatory (via ISM) but high-level requirement.
- The IMO's "Guidelines on Maritime Cyber Risk Management" (2017) and the "Guidelines on Cyber Security Onboard Ships" (BIMCO/ICS) provide a framework (identify, protect, detect, respond, recover) and best practices.
- The ISM Code (amended) requires the Company to assess and manage cyber risks as part of the SMS; the ISM audits verify this.
- Class societies (e.g. IACS) have cyber security notations/guidelines, and the IACS UR E26/E27 (2024) set cyber resilience requirements for new ships' OT/IT.
- The EU and some flag States have additional cyber requirements; the NIS Directive and the EU's cyber resilience apply to ports/companies.
Effectiveness: The IMO/ISM approach is effective in raising awareness and mandating that cyber risk be managed within the SMS, and it is enforceable through ISM audits and PSC. However, it is largely principle-based and relies on the company's implementation; the effectiveness depends on the crew's training, the segregation of OT/IT, and the actual technical controls. The newer IACS UR E26/E27 and the increasing regulatory attention (and the growing number of cyber incidents) are improving the technical baseline, but the human factor and the connectivity of legacy systems remain challenges. Overall, the framework is a necessary and increasingly effective foundation, but it must be backed by robust technical controls and continuous vigilance.