HLSS645Wk7
Maritime Cybersecurity: A Rising Tide Lifts all Boats
Light Dark
November 4, 2021
By Mike Elgan
3 min read
Incident Response
Security Services
Accept all
Required only
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your cookie preferences options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
Ports and ships — the maritime industry — are vital points in the global supply chain for food, medicine, consumer goods, fuel and many other products. Most of the world’s globally traded goods travel by sea. That’s why maritime security is key for supply chain security. Meanwhile, maritime cybersecurity faces threats at multiple places, including ports, communications systems and ships themselves.
Potential cyber attacks on maritime infrastructure are familiar types: phishing, malware, social engineering, brute force, denial of service, ransomware and others. What’s different is the unique placement of the targets.
Ships Rely on Digital Tools Ships often rely on digital tools to function, many of which are automated. Even ship compasses are digital and depend on a mix of gyroscopes and GPS. All these systems could be at risk for a digital attack. Dependence on GPS puts shipping at risk because attackers can spoof or jam GPS signals.
More than most industries, maritime infrastructure tends to be old and complicated, further hampering marine cybersecurity.
Is There an IT Worker on the Ship? Another risk factor people don’t talk about enough is the absence of IT people on ships. A ship is like a building packed with computer systems, servers and electronics. Yet, out at sea, the crew is on their own in managing these systems and dealing with breaches.
A digital attack could control or shut down a ship or drive it off-course, causing a crash. Some ships have dangerous cargo, such as explosive
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
fuel, in large quantities.
Ports are also heavily dependent upon complex digital network logistics management systems. Some of these systems track every container on every ship. In the past, attackers have been able to delay, erase the knowledge of, redirect and steal actual cargo. They could abuse access to data on the location of cargo in a ransomware attack, or lock records.
The most likely risk is that digital attacks, through any number of possible attack types, delay shipping. That costs millions or billions of dollars to shipping companies, ports or shipping customers.
Maritime Cybersecurity Attacks Increasing Attacks targeting maritime information systems are on the rise. In the �rst few months of the pandemic, attempted cyber attacks rose by 400%. We can expect this trend to continue, with rising attacks on ships and ports.
Attackers targeted the Port of Houston this year in a suspected nation- state attack, an event that raised the urgency level of maritime security infrastructure. The port is 25 miles long and handles a quarter of a billion tons of cargo every year.
The attack involved a password management program that contained a formerly unknown vulnerability. The attackers exploited that to install malicious code that granted access to the networks, which they used to ex�ltrate log-in credentials needed to control network access. Luckily, “no operational data or systems were impacted,” according to a statement issued by Port authorities.
How To Handle Maritime Cybersecurity Risks The need to address maritime cybersecurity is urgent. Here are some general approaches for how to address it:
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
Pinpoint speci�c possible threats. Understand what cyber criminals and nation-state actors might want from an attack. Pay special attention to the risk of ransomware. Consider attacks that could shut down the flow of goods, take ports offline and bring ships off course. Run red-team exercises and hire ethical hackers to help �nd likely attack points and methods. Identify digital vulnerabilities. Inventory all systems and �gure out what are unpatched, unpatchable, legacy or problematic in any way from a cybersecurity perspective. Think through the implications of existing physical security, and �gure out how unauthorized people could gain access to digital systems. Consider how rogue or disgruntled employees could threaten security. Initiate a maritime cybersecurity action plan. Address all vulnerabilities correctly, by patching or replacing problematic systems. Work with managers, leaders and stakeholders to develop these plans, then brief all concerned on how to use the plans in the event of an attack. Install smart detection tools. For example, network detection and response tools use arti�cial intelligence (AI) to �nd odd and potentially malicious behavior on maritime networks. Have your software working 24/7 to watch for possible emerging attacks. Launch new crew and employee cybersecurity training programs. Focus on phishing attacks, physical security and social engineering. Establish contingency or continuity plans. For each possible attack scenario, develop a detailed plan for running your business through it, and also what the recovery processes are.
A threat to maritime information systems is a threat to global trade. Therefore, supply chain cybersecurity is one of the world’s most urgent business priorities.
maritime industry | marine cyber security | maritime | Cybersecurity awareness
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
training | cybersecurity costs | Cybersecurity | Supply Chain | Supply Chain Security | Transportation Industry
Mike Elgan
POPULAR
INTELLIGENCE & ANALYTICS | December 19, 2023
Web injections are back on the rise: 40+ banks affected by new malware campaign 8 min read - Web injections, a favored technique employed by various banking trojans, have been a persistent threat in the realm of cyberattacks. These malicious injections enable cyber criminals to manipulate data exchanges…
GOVERNMENT | December 28, 2023
Roundup: Federal action that shaped cybersecurity in 2023 3 min read - As 2023 draws to a close, it’s time to look back on our top �ve federal cyber stories of the year: a compilation of pivotal moments and key developments that have signi�cantly shaped the landscape of cybersecurity a…
CONTINUE READING
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
MORE FROM INCIDENT RESPONSE
RISK MANAGEMENT | December 27, 2023
Are you tracking your cybersecurity implementation? 4 min read - From May 7 to 12, 2021, the massive Colonial Pipeline re�ned oil product delivery system ground to a halt. It was the victim of a DarkSide ransomware cyberattack. The Colonial Pipeline delivers about 45% of…
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
November 29, 2023
What cybersecurity pros can learn from �rst responders 4 min read - Though they may initially seem very different, there are some compelling similarities between cybersecurity professionals and traditional �rst responders like police and EMTs…
October 6, 2023
X-Force uncovers global NetScaler Gateway credential harvesting campaign 6 min read - This post was made possible through the contributions of Bastien Lardy, Sebastiano Marinaccio and Ruben Castillo. In September of 2023, X-Force uncovered a campaign where…
September 27, 2023
Tequila OS 2.0: The �rst forensic Linux distribution in Latin America 3 min read - Incident response teams are stretched thin, and the threats are only intensifying. But new tools are helping bridge the gap for cybersecurity pros in Latin America. IB…
August 31, 2023
Alert fatigue: A 911 cyber call center that never sleeps 4 min read - Imagine running a 911 call center where the switchboard is constantly lit up with incoming calls. The initial question, “What’s your emergency, please?” aims to funnel the event t…
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.
Topic updates
Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Analysis and insights from hundreds of the brightest minds in the cybersecurity industry to help you prove compliance, grow business and stop threats.
© 2024 IBM Contact Privacy Terms of use Accessibility Cookie Preferences Sponsored by
Subscribe today
Cybersecurity News By Topic
By Industry Exclusive Series
X-Force Podcast
Events Contact
About Us
Follow us on social
About cookies on this site Our websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.
For more information, please review your
options. By visiting our website, you agree to our processing of information as described in IBM’s privacy statement.
To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.