Lack of cybersecurity in maritime, especially in ports, makes MTS SPoFs.
Andrzej Gab, August 2024

Lack of cybersecurity in maritime, especially in ports, makes MTS SPoFs.

In IT or OT, very often in cybersecurity, we use term SPoF (a Single Point of Failure) - defined as Wikipedia states as "a part of system that, if it fails, will stop the entire system from working."

Murphy in his general Laws was more exact and specified:

  • Anything that can go wrong will go wrong.
  • If there is a possibility of several things going wrong, the one that will cause the most damage will be the one to go wrong.
  • If anything simply cannot go wrong, it will anyway.
  • If you perceive that there are four possible ways in which a procedure can go wrong, and circumvent these, then a fifth way, unprepared for, will promptly develop.
  • Left to themselves, things tend to go from bad to worse.
  • If everything seems to be going well, you have obviously overlooked something.

First thing - this post was inspired by Zygmunt Gorszczyński , my friend, and his last comments about MTS Cybersecurity.

The classic SPoFs in Maritime:

  • Major Ports: Some ports serve as critical nodes in the global shipping network. If a major port like Rotterdam, Shanghai, or Los Angeles experiences a shutdown due to labor strikes, infrastructure failure, or cyberattacks, it can lead to significant delays and congestion in the maritime shipping network.
  • Canals and Straits: The Suez Canal and the Strait of Malacca are examples of maritime chokepoints. A blockage or closure, such as the Ever Given container ship incident in the Suez Canal in 2021, can disrupt global shipping routes, leading to delays and increased costs as ships are forced to take longer alternative routes.
  • Intermodal Connections: Maritime transport is often just one leg of a longer journey. If the intermodal connections (such as port-to-rail or port-to-truck facilities) are not robust, a failure in one mode can impact the entire transportation chain.

Still you don't see anything cyber? Maritime relying now heavily on digital tools and systems in many aspects doesn't see it either.

So let's check some public known cases.

  • November 2023, Australia - DP World needed to stop almost all their operations in its port terminals at Sydney, Melbourne, Brisbane, and Fremantle due to a cybersecurity incident.
  • July 2014, Galapagos - 260 Chinese vessels switched off their AIS radios to illegally fish sharks an international no-fishing zone
  • December 2022, Singapore - Voyager Worldwide supporting 25% of shipping companies on the globe was hit by cyberattack and all its systems were taken down
  • December 2022, Lisbon - Ransomware attack caused Port of Lisbon to be suspended for four days, apart from stolen financial reports, audits, budgets, contracts, cargo information, ship logs, port documentation, among other vital port-related information.
  • July, 2019, Strait of Hormuz - GPS spoofing made British-flagged tanker Stena Impero to allegedly violate maritime regulations and the vessel got seized by Iran's Revolutionary Guards.

*All the data and info are based on MCAD (Maritime Cyber Attack Database, https://www.nhlstenden.com/en/maritime-cyber-attack-database).

As we can see the reliance on technology in the maritime industry has introduced new types of SPoFs, where a cyberattack on a single system can have far-reaching consequences for global trade and security. Also the integration of digital navigation tools, cargo tracking systems, and automated port operations has created new vulnerabilities that cybercriminals can exploit. All of these means that maritime organizations must be vigilant in identifying and protecting against potential SPoF threats in their IT / OT / Maritime infrastructure & software and finally being seen as a SPoF in MTS by other maritime stakeholders. It does mean that IT / OT / Maritime should be well budgeted, not only cyber, but the whole infrastructure & software supporting operations.

It should be said that Cyber governance function should advocate for and allocate appropriate resources for cybersecurity measures, ensuring that the necessary tools and technologies are in place to build proper architecture and processes to prevent and mitigate SPoFs. Additionally Cyber governance facilitates collaboration across different departments and with external stakeholders to ensure a unified approach to cybersecurity, addressing business and cybersecurity needs more effectively.

If you have no cyber function, if you're underbudgeted, if you don't govern cyber and you don't talk with business on cyber and you're happy with that please let me cite one truth reminded me by Gary C. Kessler lately - If you are happy with your cyber countermeasures the bad guy is happy too!

I will finish with more optimistic F@b's comment to Murphy's Law:

While you are reading this, something is going wrong but you don't know it... yet ;-)

Samah Al-Ghamdi

Lead Security Architect

6 个月

Very informative Andrzej Gab . From my perspective, digitalizing Maritime operations should be accompanied with building Maritime cybersecurity governance that cover People, Technology and Process, and most importantly, make management aware of Maritime cybersecurity risks to get the required resources to counter this risk.

James Hagberg

Aspiring Cybersecurity Professional

6 个月

Good post. I was working around the Straits of Hormuz with the Iranians (I believe) were spoofing GPS. ECDIS and GPS not matching the RADAR picture, major headache. From my 30 + years in the maritime world, I sadly believe shipping companies don't spend money until they absolutely have to. Usually they wait until the regulatory agencies enact something. I am now retired from shipping and completing a Cybersecurity bootcamp to get my Security + cert. I hope to be part of, what I believe to soon be, a big movement to shore up cybersecurity in the maritime sector.

要查看或添加评论,请登录

Andrzej Gab的更多文章

  • Moravec's paradox for Maritime

    Moravec's paradox for Maritime

    Let me start with a disclaimer: Everyone's talking about AI and GenAI, so I thought I'd give it a try. In Polish, we…

  • How far is PSC detention from cyber containment?

    How far is PSC detention from cyber containment?

    July 1st, one of the first hard regulations went alive - IACS UR E26 & E27. Many articles were written on this subject…

  • Immersed in neurodiversity

    Immersed in neurodiversity

    This post is about my other activity I have been involved for the last years and how surprisingly it does fit into…

    2 条评论
  • 6/29/35/50 looking back grateful

    6/29/35/50 looking back grateful

    [PL] Polska wersja poni?ej [EN] As you've noticed, and LinkedIn has reminded you, I've just completed 6 years of work…

    9 条评论
  • Does broader Internet link to a ship expands your attack surface?

    Does broader Internet link to a ship expands your attack surface?

    This article is a continuation of my conversation with Chris about whether increased internet bandwidth also expands…

    5 条评论
  • Increase your all network visibility for you

    Increase your all network visibility for you

    I'm a network guy, cybersecurity too but networking-based guy. My understanding of cybersecurity is well-grounded in…

  • Maritime Insider Threats and Overtrust in Vendors

    Maritime Insider Threats and Overtrust in Vendors

    For the past few weeks, I've had this article on my mind. Now it is the time to write it down.

  • Is it your time?

    Is it your time?

    This article is also inspired by a man - Tomasz Widomski who has just graduated Cybersecurity Management MBA…

    4 条评论
  • How secure are your doors, windows, walls and cameras?

    How secure are your doors, windows, walls and cameras?

    Today's post is thanks to Brian Harris who at Friday's Maritime Cyber Guild meeting near ?resund strait shore, showed…

    4 条评论
  • What Maritime-based CISO should know

    What Maritime-based CISO should know

    In today's world, every organization should already have a cybersecurity strategy in place. In those where the risk…

社区洞察

其他会员也浏览了