Unsurprisingly, cyber resilience across the shipping industry was not in a healthy state when the IMO guidelines were approved by the Maritime Safety Committee (MSC) in October 2021. That same year, one cyber security expert told a webinar audience that from over 750 ships, 600,000 threats, including 1,391 unique viruses were discovered.
Each vessel had an average close to two unique virus infections. What’s most interesting is that a 15-year-old virus was found to be introduced by crew using unauthorised USB drives, demonstrating the low baseline of cyber resilience on ships at the time. This worrying picture was supported by the fact that 95% of the cyber incidents detected by CyberOwl in 2021 could be linked back to the “unintentional insider”, showing the lack of awareness of cyber risk management practices among seafaring crews at the time.
That year, there were a number of high-profile attacks in the maritime supply chain including HMM, K-Line, Transnet, Port of Houston, CMA CGM, Swire Pacific Offshore, Danaos Management Consultants, and Hellmann Worldwide Logistics. Attacks were rapidly increasing in scope and frequency, with cyber criminals seemingly becoming more and more interested in the sector. Investment in automation and the digitalisation of maritime operations was rising rapidly, but investment in the cyber security infrastructure to protect it was in deficit, despite a 900% increase in maritime cyber attacks in 2020 alone.
The research carried out for this report goes some way toward bringing this picture up to the present day. The Maritime Cyber Attack Database (MCAD) created by the NHL Stenden University of Applied Sciences in the Netherlands has to date recorded 160 incidents, including the location spoofing of NATO ships visiting Ukraine in the Black Sea in 2021. Two years after the ISM cyber amendments were implemented, can the industry produce evidence of a greater maturity in cyber security? There is more top-down guidance to come in the form of a wave of new regulations, including the Data Act, the Cyber Resilience Act, and the AI Act, but what will the industry baseline look like when these regulations come into force?
Recognising the need for better cyber resilience doesn’t appear to be an issue for the maritime sector. According to a 2023 DNV survey, 87% of maritime professionals believe that the future of the maritime industry relies on a significant increase in connected networks between organisations, and 9 out of 10 respondents think that a serious disruption of ship and /or fleet operations caused by a cyber attack is likely in the near future. 79% believe that theft of property or cargo is likely, and more than half (56%) believe that a cyber attack could likely result in physical injury or loss of life.
The DNV survey does reflect some optimism about the state of maturity in cyber risk management. For example, 75% of respondents said that OT cyber security is a higher priority for their organisation today than it was two years ago. However, less than one in five could agree that their organisations were very well prepared for responding and recovering from a cyber attack on vessels at sea. There is also evidence to suggest that the industry is making strides towards better awareness and understanding of the cyber threat landscape.
For a deeper dive into the areas highlighted in this article, take a look at our thought leadership report, produced in collaboration with CyberOwl and HFW, titled “Shifting Tides, Rising Ransoms and Critical Decisions”. This comprehensive report offers insights into the evolving landscape of cyber threats in the maritime industry and explains that there is a new approach towards managing cyber risk. You can download your copy of the report below:


