Between 70% and 80% of the final output value of ship production is generated by the upstream supply chain, otherwise known as original equipment manufacturers (OEMs).
Today, ships are being continuously upgraded with digital technologies to improve their performance and augment value. This presents both an opportunity and a challenge when it comes to cyber security management, as the relationships with OEMs tend to sit with technical and/ or safety teams, and not IT departments.
OEMs play such an important role and are held to account by technical teams. But it’s complex. Like a Swiss cheese model, ship technology has layer upon layer upon layer of attack surfaces. An engine management computer will be supplied alongside a propulsion system by the engine manufacturer, but the computer itself will use peripherals manufactured by one supplier, a chipset from another, printed circuit boards from another, power supplies from another and so on. If it’s placed on a network, many pieces of componentry form part of the attack surface and may also provide a threat vector for infiltrating the most prized parts of the network.
Getting the balance right is tricky. Technical teams are pursuing performance and security requirements could slow things down. In addition, retrofitting security is very expensive. Now is the time to ensure enduring security controls and processes, so the total cost of maintaining the system is minimised over the lifespan.
This concept of trade partner risk is significant. As supply chains become further interlinked through digital technology, the chance that shipping companies become an infection pathway which causes harm to their customers and trade partners as a result of poor cyber risk management is increasing rapidly.
Supply chain cyber risk should be considered alongside protecting a company’s own network. As Wärtsilä Managing Counsel, Tom Barr, explains, “For OEMs and the wider maritime sector, cyber resilience needs to be embedded throughout the supply chain. It’s not just about making sure that our own house is in order, it is making sure that these standards are maintained up and down the supply chain.” Cost is one reason for considering supply chain risk carefully. Recent research from computer technology giant IBM shows that business partner supply chain compromises cost 11.8% more, and take 12.8% longer to identify and contain, than other types of breach.
As many companies are asking their suppliers and customers to interact with them in digital cloud environments, there is a heightened risk that infections and malicious software will be distributed up and down supply chains via these types of platforms. Another reason concerns the legal responsibility that shipping companies have to their supply chain and trade partners. Since 1 January 2021, cyber security has been part of the requirements of the International Safety Management System (ISM) Code. Supported by the IMO Resolution MSC.428(98), ship owners and managers are required to assess cyber risk and implement relevant measures. The adaptation of new technology in the supply chain inevitably means that the owners of vessels are under a heavier burden and must become even more diligent with their checks. A ship owner who is found not to have carried out and discharged his obligations in relation to his shipboard cyber arrangements is likely to render his vessel unseaworthy.
For a deeper dive into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


