HLSS645Wk7

profileRawono1
Experts_MaritimeIndustryRemainsVulnerabletoCyberAttacks-USNINews.pdf

Experts: Maritime Industry Remains Vulnerable to Cyber Attacks

BY JOHN GRADY

SEPTEMBER 28, 2020 5:23 PM - UPDATED: SEPTEMBER 28, 2020 5:27 PM

A crew aboard Coast Guard Air Station San Francisco’s Forward Operating Base Point Mugu MH-65 Dolphin helicopter conducts an overflight near an anchorage site off the coast of Los Angeles, Calif., on April 23, 2020. US Coast Guard Photo

While handling 90 percent of the global economy

daily, maritime industry ashore and a�oat remains

increasingly vulnerable to cyber disruptions and

attacks from “neerdowells and bad actors” that

threaten �nancial markets and the country’s national

security, the head of the Maritime Administration

said last week.

Lacking a coordinated code affecting all modes of

transportation and ports and terminals, the

“movement of our armed forces” can be disrupted

“by a few key strokes of bad actors” that can affect

ship operations, cargo handling and on-shore

facilities, retired Rear Adm. Mark Buzby said during a

Sept. 24 virtual event hosted by The Atlantic Council.

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

Cyber disruptions in San Diego and Barcelona port

operations in 2018 and continuing ransomware

attacks on European transport companies

underscore the vulnerability of these interlocked

modes of economic movement, Coast Guard Capt.

Jason Tama, commander of Sector New York, and

Heli Tiirmaa-Klaar, Estonia’s ambassador-at-large for

cyber diplomacy, added.

Speaking as part of the online forum, Kathy Metcalf,

president and chief executive of�cer of the Chamber

of Shipping of America, said all too often cyber

security is thought of as the takeover of a ship and

ramming it into the Verrazano-Narrows Bridge,

which connects Brooklyn and Staten Island at the

entrance to New York’s harbor.

The real need is for “collaboration” on all the details

affecting small links in a supply chain or parts used in

maintenance. “The system will only be as good as its

weakest link,” Metcalf said.

The maritime industry includes many links — some

more than 30 years old that remain extremely

vulnerable, while others are brand new and

hardened, Xavier Bellekens, lecturer at the Institute

for Signals, Sensors and Communications, University

of Strathclyde, said at the forum.

Security at the maritime edgeSecurity at the maritime edge

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

Looking only at ships, using open source information,

Bellekens said anyone “can relatively easily … learn

very fast about,” a ship at sea. Using slides, Bellekens

selected one ship operating from a Southeast Asian

port and in less than a day followed its course

outbound, obtained biographical data on its captain,

information on the makeup of the crew, current

cargo, destinations and the ship’s current position.

The data are potentially useful to hackers, pirates,

criminals, terrorists or hostile nation-states.

As he was speaking, Bellekens presented a news

photo of the aftermath of a collision at sea between a

Russian frigate and merchant ship in Danish waters

that occurred the day prior. He used the photo,

which was available within a few hours of the

mishap, to emphasize the point that “there are many

ways to gather open source information.”

Master Mariner Capt. Alex Soukhanov, managing

director at Moran Cyber, said that while designers

and builders have understood for decades the need

for safety, segmentation or compartmentalization in

ship work, “cyber and networks” were “not priorities”

for years. Those legacy systems are still operating

today.

“It really doesn’t matter who the bad guy is” in

hacking the vessel itself, from propulsion to

navigation systems, port management, terminal

capacity of cargo, to a maintenance facility’s work

schedule because “all of these systems are

connected together.”

Tama said, “we’re years behind other sectors,” like

�nance, in understanding these connections and the

need for collaboration between ship owners, vessel

operators, ship builders and designers, terminal and

port authorities, and companies and law

enforcement.

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

The reluctance to collaborate in the private sector

and even in public-private partnerships with law

enforcement agencies, including coast guards, has

been shifting, Metcalf, Tama and Tiirmaa-Klaar

agreed.

The impact of ransomware demands in all manners

of business — from health care to utilities to

transportation — has been a key factor in this shift.

Even reducing this to cybersecurity on ships alone,

Metcalf said, “not all the ships are the same” because

they were built at different times for different

operations. An example of “�esh on the bones” for

vessels could be drawn from the International Safety

Management agreement to improve cybersecurity

a�oat.

Moreover, Metcalf said the reality aboard a ship is

that the �rst questions a captain or master ask if the

ship’s operations are disrupted aren’t about cyber.

They will instead ask about restoring that capability

or how to work around it. In addition, most of�cers

and crew “don’t realize how important [a part, a

system, etc., are] until it’s no longer working.”

For all the activities involved in maritime operations,

“you can set up some general principles” and “the

right place is in the [International Maritime

Organization],” she added.

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

John Grady

John Grady, a former managing editor of Navy Times, retired as

director of communications for the Association of the United States Army. His reporting on national

defense and national security has appeared on Breaking Defense, GovExec.com, NextGov.com,

DefenseOne.com, Government Executive and USNI News.

SHARE TO:

ALSO ON USNI NEWS

HouthisHouthis Fired Fired … … 10 days ago 63 comments•

ReportReport to to … … 8 days ago 8 comments•

     

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

USNI News Comment Policy

Please be thoughtful and respectful of others. Personal attacks and abusive language are not tolerated.

Got it

Share

Best Newest Oldest

3 Comments 1 Login

LOG IN WITH

OR SIGN UP WITH DISQUS

Name

Join the discussion…

?

TDog − ⚑

3 years ago

Cybersecurity is viewed as an afterthought because risk mitigation combined with a desire to cut costs results in the mentality that "someone else will pay for it." When a ship gets hijacked by Somali pirates, the US Navy sends in SEALs and they liberate it or Lloyd's of London pays out on the insurance policy covering it. Either way, the primary stakeholder in question isn't out a dime.

As such, the impetus for crafting a more robust cyberdefense across an industry as widely distributed as shipping is asking for an awful lot. One would probably have better luck demanding the sacri�ce of th � t b hild f th i t d hi i

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

see more

Reply •

the �rst born child of these various port and shipping operators than one would asking them to implement and adhere to more stringent cybersecurity matters. Corporate culture values two things above all else: divestment of responsibility and pro�t. "It's not my

1 0

kapena16 − ⚑> TDog

3 years ago

Yes. Absolutely correct on every point.

The international shipping industry, controlled by several independent men of wealth in addition to a handful of dictatorial national gov't's (namely, China) are their own worst enemy.

It's is NOT a case of the industry not trying to protect themselves from cyber attacks. They don't WANT to work together on anything IN THE AREA OF LOGISTICS, let alone, cyber security. To be clear, they are adamant of 'going it alone' and keeping their operations to themselves all in an effort to maximize their pro�ts and maintain and/or gain market share

Share ›

K

RELATED POSTS

U.S. Navy Helo Crews Kill Houthi Assault Boat Teams

AVIATION

China Masses Militia Ships in Spratlys, Transit of USS Gabrielle

CHINA

Destroyer USS Carney Downs 3 Drones in Red Sea;

FOREIGN FORCES

Russia Lays Mines in Black Sea to Block Ukrainian Ports, NSC Says

FOREIGN FORCES

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +

USNI News is the independent, non-profit news service of the Naval Institute. Our mission is to provide unbiased coverage of the U.S. Navy, Marine Corps, Coast Guard and international maritime affairs.

    

 

About USNI News

U.S. Naval Institute

After Red Sea Attack

This post has

been updated

with a statement

from the Houthis

Ten Houthi

�ghters are dead

after attempted

attacks on…

Gi�ords Irks Beijing

Littoral Combat

Ship USS

Gabrielle Giffords

(LCS-10) sailed

past Second

Thomas Shoal in

the disputed

Spratly Island

chain in the…

Commercial Ships Attacked

This post has

been updated

with an

additional

statement from

U.S. Central

Command.

Destroyer USS

Carney (DDG-64)

shot down three…

Russia has laid

sea mines in the

Black Sea that

could interfere

with Ukrainian

grain exports, the

White House

announced…

 BROWSE BY TOPIC LATEST POPULAR

FLEET AND MARINE TRACKER ABOUT

Support USNI News Today +