news Compliance & regulationOperational risk Hellenic Shipping News
The Email Divide at Sea: What Greece, Cyprus, the Gulf, Turkey, and Africa Reveal About Maritime Cyber Risk in Hellenic Shipping News 21/03/2026 Email is still the spine of maritime operations. Chartering instructions, spares orders, crew changes, port documentation, vendor payments to name a few. Most of it moves through inboxes, even as ships add new digital tools. But the way shipping markets treat email risk is far from uniform. In my work across Greece, Cyprus, Turkey, the Gulf, and parts of Africa, I see a widening “email divide” that has little to do with awareness campaigns and everything to do with operational culture, local infrastructure, and whether companies treat support as a strategic capability or an afterthought. The truth is simple: you can’t secure what you can’t support. And you can’t support what you don’t understand in the context of how ships actually operate. In Greece and Cyprus, IT teams tend to be more mature and demanding. Many operators have strong internal capability, experienced shoreside teams, and higher expectations from vendors. That’s the good news. The harder part is cultural, and it’s not a criticism, it’s a reality. Greeks are passionate. Everything is urgent. Decisions get made quickly, operations move fast, and there is limited patience for delays. This urgency is not “bad culture.” It’s often what keeps ships moving. But it creates a friction point with email security, which typically depends on verification steps, formal controls, and structured governance. The risk isn’t that email is used, it’s that email becomes the shortcut when time pressure is high. That’s exactly the environment BEC attackers exploit: urgency, fragmented approvals, and people trying to keep operations moving. In Greece and Cyprus, the vulnerability often isn’t ignorance. It’s speed. In Turkey, the Gulf states, and parts of Africa, the pattern is different. Email is still essential but many operators lean heavily on consumer-grade platforms such as Gmail, Outlook.com, or Hotmail. This is not because people are careless. It’s because these tools are familiar, easy to deploy, and appear “good enough” when the priority is getting things done under cost and resource constraints. Miltiadis Giannakoulias The problem is that familiarity creates complacency. If a business runs on free or low-cost email infrastructure, it’s more likely to treat email as a convenience channel rather than a controlled operational system. Security becomes something you think about after an incident, not as a design principle. There can also be gaps in training, or simply uneven access to specialist IT skills. In some cases, language barriers make it harder to absorb or act on technical guidance, especially when that guidance is written for shore-based enterprises rather than vessel reality. This is where perceived risk and real risk diverge. Many teams believe email is “fine” because it works. But in modern maritime operations, “works” is not the same as “resilient.” Across all regions, one of the biggest email-adjacent risks comes from legacy systems and fragmented responsibility. Ships still run a mix of old software, aging PCs, and stitched-together connectivity. When something goes down such as email access, a sync issue, a corrupted mailbox, or a misconfiguration, too many operators face the same moment: there’s nobody to call. That’s not just a service complaint. It’s a risk scenario. Because the moment systems fail at sea, operations don’t sto
The Email Divide at Sea: What Greece, Cyprus, the Gulf, Turkey, and Africa Reveal About Maritime Cyber Risk
Hellenic Shipping News
Read full article at Hellenic Shipping News →
Opens Hellenic Shipping News in a new tab