Maritime cybersecurity isn’t a one-time fix but a continuous challenge spanning the entire lifecycle of a vessel. Shipowners, charterers, shipyards, OEMs, crew, and insurers each play a role, but gaps in responsibility create vulnerabilities.
Who is accountable for cybersecurity at different stages of a vessel’s lifecycle? And how can stakeholders work together to embed resilience from design to daily operations?
In our latest report produced in partnership with CyberOwl, and HFW, reveals a shifting cybersecurity landscape. In 2023, 14% of shipping stakeholders admitted to paying ransoms, with an average cost of USD $3.2M. This year, ransom payments have dropped. Only 7% admit to paying a cybercriminal, with most of those payments being under USD $100K. While this shift is promising, new challenges are emerging.
One of the biggest concerns is the inconsistent application of cybersecurity standards across a vessel’s lifecycle. The International Association of Classification Societies (IACS) Unified Requirements E26 and E27 establish cybersecurity standards for newbuilds, but do not apply to existing vessels. This means that while some shipowners embed cybersecurity into the design phase, others do not. This lack of uniformity forces shipowners to manage a patchwork of security postures, increasing cyber risk exposure.
Further complicating matters is the finding that only 17% of shipyards have in-house cybersecurity expertise, and just 1 in 6 shipowners fully understand what a cyber-secure vessel should look like at delivery. While shipyards expect shipowners to set cybersecurity requirements, many shipowners lack clear guidance, creating uncertainty during vessel handovers.
The challenges extend into construction and operation of a vessel. Original Equipment Manufacturers (OEMs) and shipowners must build systems that balance security with adaptability. Older systems that were designed before cybersecurity was a priority will realistically remain on vessels for a long time. So it is critical that there is a shared understanding, continuous visibility of the risks posed by these systems, and a practical, collaborative response plan should they come under attack.
OEMs often function as “black boxes,” providing shipowners with little visibility into system vulnerabilities and security measures. Crew training is another weak link, as many seafarers rely on desk-based exercises that fail to prepare them for real-world cyber scenarios.
A vessel’s cybersecurity is only as strong as the relationships across its supply chain. Cybersecurity is not just an IT issue but an aspect fundamental to a vessel’s seaworthiness and operational resilience. Without early collaboration and clearly defined responsibilities in a vessel’s design phase, stakeholders risk falling behind. This can lead to greater exposure to cyber threats and costly retrofits.
Our latest report answers the following questions and provides insights, recommendations, and practical steps to help the industry enhance cybersecurity resilience.
- What is the current state of maritime cybersecurity?
- How are new regulations shaping cybersecurity requirements?
- What are the challenges in designing, constructing, and operating a cyber-secure vessel?
- How do key stakeholders contribute at each stage of a vessel’s lifecycle?
- How can stakeholders prioritise cybersecurity and collaborate to address present and future threats?
In this series of articles, we’ll explore the answers to these questions, and examine the key challenges, regulatory impacts, and the roles of different stakeholders across the vessel lifecycle.
For further insight into the areas discussed in this article, download our latest thought leadership report, The Lifecycle Dilemma, created in partnership with CyberOwl and HFW.

