Companies are ploughing more capital into cyber protection tools. In 2022, 54% of shipping companies spent less than US $100K on cyber security management. The 2023 survey revealed that now only 33% spend less than that. Larger players are moving at a faster pace as they are exposed to vulnerabilities, and it has dawned upon them the potential for catastrophe if they are the successful target of a cyber criminal.
But 18 months later, the deployment of advanced digital technologies and higher levels of connectivity thanks to the addition of LEO satellites are catalysing the emergence of new threats. Vulnerabilities are infiltrating different levels of the organisational structure, bringing new demands and requiring some difficult decisions to be made. Risk management teams, IT and cyber management teams, and fleet technical and safety management teams must consider, understand, and manage cyber security threats in a very specific way.
In order to do so, maritime professionals require upskilling. Blending skills across all departments, which can be achieved with a cross-functional crisis team, can be useful in evaluating and mitigating cyber threats more effectively. However, in the majority of cases, IT isn’t yet considered a critical part of the cross-functional team. Making it further difficult to navigate the maritime cyber security environment is the uncertainty around cyber insurance.
We recommend the following for support in creating a safer maritime cyber security environment:
- Understanding how responsibilities and complex technologies but they also are evolving for key roles is critical. These roles are changing as a result of increased connectivity, digitalisation and the consequential cyber risks, and there are increasing pressures and demands on people. Not only do people require the skills to operate advanced need the right cyber security knowledge to reduce the risk of opening up systems to vulnerabilities. Blending skills across all departments is helpful and this can be done via cross-functional teams.
- Make deliberate and holistic term consequences to decisions. Developing decisions on investments in cyber risk management. This requires a coherent security programme, led by an authority that understands the risks. Making decisions on point-based solutions may result in high costs, but low effectiveness. There are longer abilities in-house versus leveraging the expertise and scale of outsourced providers that need to be considered carefully. So does the choice of bundling vs. disaggregating cyber security from other functions.
- When assessing the installation would increase cyber risks. Greater cyber of advanced satellite communications systems, such as LEO, additional cyber risks must be considered in the budget. 43% of respondents said that their organisation is planning to roll out LEO within the next 12 months and nearly half agreed that its protection will be required, but this will come at an additional financial cost.
- Secure the right relationships OEMs are held to account by technical with OEMs. Ships are being continuously upgraded with digital technologies and OEMs are held to account by technical teams. But it’s complex, and it’s important to acknowledge that an effective cyber security strategy comes from both one-off actions and continuous maintenance of security. OEMs also need to develop software to standards which are understood by industry to avoid unnecessary confusion.
- Insurance needs to be right. While having it in the first place is a start, not having a clear understanding of how and what protection it provides is a major but all too common issue seen today.
- Check your contracts. Assigning risk and responsibility pre-incident in a contract is one of the better ways to mitigate any exposure the parties may have following a cyber security breach. If the contract is silent and no provision is made for cyber security, consider if it is necessary to incorporate an appropriately drafted cyber security clause. Check your contracts. Assigning risk and responsibility pre-incident in a contract is one of the better ways to mitigate
For a deeper dive into the recommendations shared in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


