Given the challenges in understanding and quantifying the total cost of cyber risk, addressed earlier in the report, securing the right resources to manage cyber risks properly can be a difficult task. Cyber risk management doesn’t fall neatly into traditional business case categories of driving more revenue or reducing costs. Rather, it is more closely associated with reducing risks and potential financial exposure.
According to UK Government Research, qualitative data reveals a set of issues that prevent boards from engaging more in cyber security. These include a lack of knowledge, training and time, but the same data also highlights, “the importance of people in cyber roles being able to write persuasive business cases for cyber security spending, especially when they report directly to finance leads.”
Thetius’ 2023 survey results illustrate the challenge in shipping:
- 33% felt that one of the biggest challenges in improving cyber risk management is understanding the level of risk.
- 30% said that it was difficult to understand best practices.
For this reason, securing the right level of investment in resources is one of the top challenges for shipping cyber practitioners at the moment. Our 2023 survey results further indicate that there is a very wide range of investment in resources related to cyber risk management in shipping:
- At one end of the spectrum, 33% spend less than US $100K per year on cyber security management.
- At the other end, 3% said they invest more than US $10 million.
Ships operated by smaller and less well-resourced operators may be of equivalent size and complexity to those operated by the industry leaders. The challenges and risks associated with a successful attack remain equal. However, those with a lack of resources and less ability to invest in and staff a cyber risk management function in-house must rely on external assistance or maintain a higher tolerance to risk than their larger counterparts.
Investing in the wrong or insufficient resources can hurt the organisation in ways that are not immediately obvious. Many ship operators quantify one-off costs associated with cyber security solutions but fail to consider the resources required to maintain the systems and controls they wish to put in place. An example of this is establishing individual logins and passwords. While this sounds like a good security policy in theory, it comes with the operational cost of maintaining up-to-date logins and passwords in practice, in the face of changing crews and vessel visitors.
Even in the cases where investment has been secured for in-house resourcing, the effectiveness can vary greatly. IBM has observed that only 1 in 3 data breaches were detected by in-house teams. 67% were reported by “benign third parties” offering cyber security monitoring services, or in some cases, announced by the attackers themselves.
Finding the unicorns- the need for combined maritime and cyber skills
A lack of talent or human failure will be responsible for over 50% of all significant cyber incidents by 2025, according to Gartner. The shipping industry needs a major refocus on people to minimise the chance of this predicted statistic becoming a reality. One major issue remains – attracting cyber talent into shipping is like searching for unicorns.
There are several reasons for this which we have explored further in our report produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


