Skip to content
News Item

Cyber security at sea: Why maritime must move to close the digital gap

As cyber attacks on global transport systems grow more frequent and sophisticated, the maritime sector faces mounting pressure to close its digital security gap and keep pace with its peers. ICS Leadership Insights speaks to cyber security experts for the latest.

26 February 2026
Maritime faces pressure to close its digital security gap. Credit: Shutterstock

In an age when ransomware can halt national infrastructure and state-backed hackers probe the world’s transport networks, the maritime sector finds itself at a crunch point. Despite progress and expanding regulations, experts warn that shipping remains less mature than other sectors, and the gap is widening.

CyberOwl, now part of DNV, monitors cyber risk across maritime operational assets and other critical infrastructure. CEO Daniel Ng offers a stark comparison: “If aviation is an eight or nine out of 10 in terms of cyber maturity, shipping overall is about a four, and the ships themselves are more like a two or three.” Ports and terminals score slightly higher at five or six.

For an industry carrying 90% of world trade, the gap matters. “There’s a gulf between operators who’ve experienced major attacks and everyone else,” Ng says. “Many mid-sized owners are still waiting for something to happen before they act.”

Fragmented regulation and uneven progress

That unevenness is partly structural. Maritime’s regulatory environment is a patchwork of IMO instruments, International Association of Classification Societies (IACS) requirements and national or regional rules. IMO Resolution MSC.428(98) requires cyber risk management to be integrated into Safety Management Systems, while the IACS Unified Requirements E26 and E27 tackle cyber resilience for onboard operational technology. For now, however, the IACS rules only apply to newbuilds contracted from mid-2024.

“You have a desperate hodgepodge of different regimes,” Ng says. “Shipowners are left trying to piece it all together.”

There have been calls from shipping industry bodies for the International Maritime Organization (IMO) to address this disjointedness by developing a new Maritime Cyber Code, with other transport modes currently benefiting from far more coherence. Gary Cannon, Head of Transport at cyber and software resilience business NCC Group, notes that automotive has surged ahead through UN Regulation 155 and ISO/SAE 21434. He explained that aviation remains advanced under the International Civil Aviation Organization (ICAO) and European Union Aviation Safety Agency (EASA) frameworks. Rail is progressing under NIS2. Maritime, he warns, is “gradually catching up”, but adoption “remains inconsistent due to reliance on flag States.”

NCC’s State of Supply Chain Security report highlights the risk. While 94% of businesses believe they could handle a supply chain attack, a third do not monitor suppliers regularly, and 21% think they would be unaffected if a key supplier were offline for five days.

Greig Ferguson, Senior Lead Consultant at cyber security consultancy Bridewell, explained: “Aviation benefits from a single global rulebook. Maritime has standards too, but enforcement varies wildly. Where governance is fragmented, progress relies more on leadership than regulation.”

Old systems, new threats

Beneath these governance gaps lie similar technical pressures across transport modes. Cannon points to entrenched legacy systems “designed long before cyber security was a priority,” increasing exposure as IT and OT converge. Complex supply chains, limited cyber skills and rising ransomware activity add further strain.

Legacy technology can create false confidence. Roger Grimes, CISO Advisor at security awareness training provider KnowBe4, calls it a double-edged sword – sometimes obscure enough to deter attackers, but difficult to patch and potentially catastrophic if targeted.

CyberOwl’s data shows how quickly threats are shifting. It handled around 1,200 cyber incidents in 2024. “Ninety per cent were low impact,” Ng says, “but that won’t stay true forever.” Remote access pathways rose from under 5% of incidents in 2023 to 13% in 2024. “Connectivity for emissions monitoring and performance analytics is ramping up. The more we connect, the more pathways we create onto vessels.”

The human link

Human behaviour remains a weak link. CyberOwl estimates that roughly three-quarters of malware incidents it sees on vessels are linked to USB use, a crew member plugging in a device that should never have been connected. An ICS online poll in October 2025 of shipboard weak spots told a similar story: more than half of respondents picked USB sticks and portable media as the most overlooked cyber risk on board, far ahead of Wi-Fi or cargo and engine control systems.

“Cyber awareness at sea is lagging,” Ng says. “It’s not part of mandatory STCW (Standards of Training, Certification, and Watchkeeping for Seafarers) training, so companies do the minimum.” He argues for cyber drills akin to fire drills and advocates “just-in-time” training, where crews receive immediate feedback after breaching a policy. “If someone breaks a safety rule, they’re corrected on the spot. Cyber should be no different.”

Lessons from other sectors

Stronger sectors embed cyber directly into safety management. “Aviation teaches that cyber belongs inside safety management, not alongside it,” Ferguson says. “When you treat cyber incidents as safety events, train for them, report them, and learn from them, maturity follows.”

Greg Linares, Principal Threat Intelligence Analyst at the managed cybersecurity provider Huntress, stresses that no transport sector is immune: “Aviation, rail, road, and maritime all come relatively close when it comes to defence, but cracks exist across downstream supply chains and third-party integrations.” Recent ransomware attacks on rail and aviation vendors disrupted payment and ticketing systems, though not safety-critical operations.

Linares highlights deeper structural challenges, and he says many industries still struggle to work constructively with security researchers. “Finding flaws, even with safety implications, can trigger pushback, legal threats or job loss.” Disclosure processes vary widely, slowing fixes and prolonging exposure.

He argues that multimodal tabletop exercises, combining manufacturers, researchers, developers, security teams and supply-chain specialists, are vital as hybrid cyber-physical attacks become more likely. “So many weaknesses exist because systems were never designed with hostile actors in mind. Once you show engineers how an attacker thinks, the realisation is immediate.”

Linares believes transport systems remain strong despite the volume of attacks, but insists that responsible disclosure protections and robust testing from design to maintenance “must become standard.”

Jamie Akhtar, CEO and Co-founder of cyber security monitoring platform CyberSmart, links the threat to national resilience. He said: “Like all critical infrastructure, transport is being increasingly targeted by sophisticated, often state-backed cybercriminals. Disrupting critical national infrastructure offers financial reward, maximum chaos and geopolitical leverage.”

Culture and collaboration

Commercial incentives may accelerate change. Some operators have already secured lower marine insurance premiums through stronger cyber risk management. “Once it affects the bottom line, leadership pays attention,” Ng says. Insurers and charterers can reinforce this through premiums and contractual requirements, though “the final mile of implementation still lies with the operator.”

Still, many boards find cyber uncomfortable. “Every time I show our data, 1,200 incidents in a year, jaws drop,” Ng says. “People don’t realise how frequent these events are. Because we’re not talking about them openly, urgency is lost.”

Cannon advocates for multimodal threat intelligence sharing, joint exercises, and common vendor requirements based on ISO/IEC 27001 and the NIST Cybersecurity Framework. Ferguson adds: “Transport systems don’t exist in isolation. A port outage can ripple across rail, road, and air. Cyber resilience should be a shared responsibility, just like safety.”

Today, limited vessel connectivity keeps operational cyber risk relatively contained. But that buffer is shrinking fast. “The challenge isn’t where we are today,” Ng concludes. “It’s how fast we’re moving into a more connected future without the right protections in place.”