Many shipping professionals have yet to experience a large-scale cyber incident. Whilst one can point to historical examples such as the incident that crippled the operations of Maersk for weeks and reportedly cost US $300 million, these seem remote and unrealistic to the majority of shipping operators who find it hard to relate to the enormous scale of Maersk’s operations and the specificity of the particular attack they experienced. The total cost of a cyber attack varies widely and no two attacks will bear the same cost signature. This leaves the maritime risk executive unstuck.
The UK Government has previously put forward a framework for understanding, and budgeting for, the cost of managing cyber risk. They suggest classifying the cost of cyber crime into three categories to represent the distinct stages of how victims experience the costs of cyber crime, which are illustrated in the graphic that follows.

Our 2023 survey results indicate some very positive trends here. There is a clear and significant increase in investment in cyber defensive measures. 67% say they spend more than US $100K per year on cyber security management, whereas in 2022, this was only 44%. This indicates that shipping companies that continue to under invest are rapidly getting left behind their peers and falling short of average practice, let alone best practice.
But exactly where are these investments being spent in defensive measures? Whilst there continues to be a very wide range across the sector, some trends are emerging. It is no longer true that shipping companies are simply not investing in cyber risk management. Some progress is being made, even if this is still in the early stages of maturity. To lift the lid on this, the CyberOwl team performed an analysis across the shipping companies they engage with worldwide to get a better understanding of where defensive measures are being strengthened, and which areas still require significant work.
Beyond the obvious costs of implementing cyber security management solutions, such as anti-virus software, staff and consulting costs, physical network security infrastructure, and training, it is important not to forget the hidden costs. For example, additional satcom bandwidth is often required for many cyber security protection solutions. Extra cloud storage may also be needed, and even the price of additional human resources needed to manage cyber security should be considered in the cost of the cyber management protection process. These metrics will also play a role in the overall cost of cyber protection but are often forgotten.
The consequential cost of a cyber incident begins with the immediate aftermath. Software, equipment, and databases may have been damaged, so there will be costs associated with the recovery effort. There may also be direct financial losses associated, such as business disruption, theft, ransom, loss of intellectual property or commercially sensitive information, and reputational damage to repair. We explore this area further in the next article in this series of 12.
For further insight into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


