As shipping steams ahead into the 21st century, operations are changing and regulations are evolving. New technologies are being deployed, and these come with their own set of cybersecurity challenges. But while advancing cyber threats are anticipated, significant uncertainty remains around the impact these changes will have on current and future roles. Key roles and responsibilities within shipping operations are changing and new risks are emerging. Maritime professionals need to be upskilled in order to consider, understand, and manage these additional threats. However, this rush of new demands makes it difficult for shipping leaders to keep up, prioritise investments and make decisions.
In our main report, “Shifting Tides, Rising Ransoms and Critical Decisions” we explored the 3 key roles that are most impacted by the changing cyber risk landscape: risk management, IT management, and fleet safety management. The research uncovers how these roles, long established in shipping companies, are now evolving to incorporate cyber risk management and the key considerations for each of these roles in decision-making.
Risk management
Refers to those within the organisation who have ultimate responsibility for financial risk and business continuity. In some of the larger shipping operators, this is a separate function with dedicated leadership. But in most shipping organisations, these are a combination of board-level or C-Suite leadership positions. Historically, this function has deep expertise in geopolitical risks, vessel technical risks, ship and fleet operational risks, port operations and physical safety. However, cyber risk is now increasingly on the shipping risk register. There is a significant amount of evidence which shows that good cyber risk management must permeate a business from the top down to be in any way effective, similar to building a good safety culture.
IT Management
Refers to teams with strategic and operational responsibility to plan and implement hardware and software solutions that enable the business to execute its functions and maintain regulatory compliance. It is common in the maritime industry for cyber resilience to be delegated to personnel with broader IT responsibilities, but this varies widely across the sector. Traditionally, the IT function is treated as a “back office” function in a shipping company and is still rarely provided dedicated representation at the management team level. However, increasingly, IT teams are rightly or wrongly assumed to be the subject matter experts and enable innovation.
As shipping regulation on cyber security strengthens, they are also being thrust towards the coalface of managing inspectors, vetters and auditors, despite mostly being unfamiliar with the machinations of IMO, charterer bodies and the classification process. Their rapidly expanding remit and lack of authority can also make it increasingly hard for them to deal with emerging cyber threats. As a result, issues at this level can cause damage almost immediately.
Fleet safety management
Has the remit to manage fleet safety and operations from a nautical and ship-technical perspective. Fleet managers are highly skilled maritime operations professionals, usually composed of ex-chief officers, masters or chief engineers. As such, they take responsibility for maritime risks but do not usually have detailed knowledge and skills in cyber security. As IT and OT take more prominent roles in fleet operations, marrying cyber security skills with those in fleet management is vital. In addition, the primary regulatory mechanism for cyber risk management of ships is fundamentally connected with safety management systems. Strictly the safety function has technical ownership of cyber risk management.
For a deeper dive into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


