Back in 2022 when Thetius, CyberOwl, and HFW carried out a similar analysis of the maritime cyber security landscape, 36% of respondents believed that their organisation had been the victim of an attack. In the 2023 survey, this figure remained much the same (35%). But what’s most interesting to note is that the cost of attacks and demand for ransom payments have skyrocketed.
In fact, we’ve seen a 200% increase in the cost of cyber attacks on organisations and a 357% increase in the demand for ransom payments. Respondents reported that over the last three years, their organisations have spent around US $550K on managing and mitigating cyber attacks. These costs are largely driven by the price of cyber security, IT and other external advisors, business interruptions and delays, and the cost of replacing or restoring systems. Other costs include the payment of ransom, loss of business, and being tricked into transferring funds.
In 2022, respondents noted that cyber security incidents were costing their organisations around US $182K. Just 18 months later, we’re seeing a substantial increase in the overall cost of cyber attacks to organisations operating in the maritime sphere. The 2023 survey shows that the average price paid for ransom has remained persistently high. In 2022, the average price paid was US $3.1m and in 2023 it is US $3.2m. Most important is the significant increase in demand for ransom payments. In 2022, only 3% of respondents said they had paid a ransom following a cyber attack, but this year, nearly 14% admitted to doing so. This is a whopping 357% increase in just over a year.
The rise in ransom payments is not limited to the maritime sector. Cyber insurance firm Coalition reported that ransomware claims increased by 27% during the first half of 2023. While in some cases, increased ransomware activity can be tied to Russia’s invasion of Ukraine, ultimately ransomware operations are scalable and easy money-makers for cybercriminals. The increase in ransom payments is not a surprise, but managing risk is an issue that needs addressing now.
In 2022, Thetius reported that 24% of industry professionals thought that their organisation did not have an insurance policy in place for cyber attacks, while 42% didn’t know. Ship operators were found to be unnecessarily exposing themselves to cyber risks by not understanding their insurance policies and their limitations. It seems that 18 months on, little has changed.
A large majority of this year’s respondents (42%) said that they are unclear about what is covered by their organisation’s cyber risk policy, while 25% of respondents thought their organisation did not have a cyber risk insurance policy in place. Moreover, 37% said that their insurance policy did not cover the claim they made following a cyber attack. A further 18% declined to comment or didn’t know, indicating that even where an insurance policy is in place, securing a payout is not always possible.
In terms of preparation and response, this has remained largely the same since the previous survey. In 2022, 73% of respondents said they believed that their organisation had a cyber emergency response plan that was regularly tested. In 2023, this figure remained relatively similar, with 71% believing their organisation has a response plan that is regularly tested.
Despite these rising figures, there is also evidence of progression. In 2022, we found that 54% of shipping companies admitted to spending less than US $100K on cyber security management, whereas in 2023 only 33% of shipping companies said they spent less than US $100K. This indicates that there is an increase in the number of organisations digging deeper into their wallets to combat cyber threats.
For a deeper dive into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


