Maritime Reader

NEWS INTELLIGENCE ARCHIVE
03 AUG 2026 MONDAY
Advanced filters
Keywords | type to search… Date: All time Sources: All Topics: All
The noise around cybersecurity in shipping is growing and owners need to make informed choices, writes Angeliki Zisimatou, Director, Cybersecurity, ABS Cyber incidents in maritime are increasing in number and sophistication, with new forms of connectivity and new digital technologies creating additional risk for an industry that for a long time felt insulated from direct, targeted cyber attacks. To address these risks, the industry has seen the implementation of various regulations driven by industry-led initiatives, but a global unified standard has yet to be developed. Shipowners must address recent regulations while keeping an eye on the horizon for the development of a more substantial regulatory framework. New Unified Requirements from IACS covering ships and systems, new rules from the US Coast Guard covering US flagged vessels, guidelines from EMSA and BIMCO are all in place or coming soon. Since the introduction of provisions in the ISM Code, the International Maritime Organization has kept an eye on cybersecurity and will focus on the topic as a discussion item again in the near future. Cyber presents a multi-faceted problem for shipping, a reality compounded by contrasting approaches to the problem that divide along familiar lines. Many operators are taking the issue seriously, but the response often depends on their size and capability – and whether they have previous experience of a cyber incident. Some are investing heavily, establishing their own Security Operations Centres and cyber teams as well as addressing supply chain vulnerabilities. Smaller operators are less well advanced in the process of assessment and preparedness. The same pattern broadly applies among vendors, with large original equipment manufacturers working to IEC standards and smaller technology providers sometimes struggling to meet the IACS requirements. The same trend can be observed among shipyards, with some fully engaged and others believing their role as an integrator is primarily to collect information from vendors. In fact, the requirements of the IACS URs are quite specific in terms of what ship and system security should look like and there may be gaps in the data collected. Understanding Risk Among the challenges for operators is that effective cybersecurity generally requires a risk-based approach, whereas most maritime regulations attempt to be prescriptive in nature to better guide operators and assist them with implementation efforts. The lack of common data formats and the assumption that implementation of minimum security control levels is good enough can lead to compliance, but not necessarily security. Some vessel operators continue to believe that being “air-gapped” from the internet or using only minimal connectivity reduces their risk to an acceptably low level. This assumption discounts the reality that 83% of organizations reported at least one attack attributed to insiders, normally employees, whether intentional or otherwise. All operators, regardless of size, should start from the same baseline, but there are no restrictions on going further. All should, at the very least, have completed a risk management plan to understand their assets, associated vulnerabilities, and mitigating actions. A major factor in building that plan is understanding the human factor and the risks that accrue from the lack of training and awareness. Crew training in particular is critical, as many crewmembers have not had cybersecurity training and are
← Back to latest
news Splash247 ·2024-12-30

Growing cyber risk means owners should get ready for more regulation

Splash247
Read full article at Splash247 →
Opens Splash247 in a new tab

Topics & segments

← Back to latest

Related Knowledge

Documents on the same topic from the archive