A modern vessel is a connected organisation with a dozen people aboard, an intermittent link and equipment from a dozen suppliers. That combination produces exposures that shore-based thinking does not fully cover.

The exposures that actually matter

Flat networks

The most consequential. Where crew devices, operational computers and equipment interfaces share one network, a single compromised laptop can reach everything.

Crew devices are personal, varied and unmanaged. They connect to networks in every port. They are the most likely entry point and the hardest to control, which is precisely why they belong on an isolated segment with no route anywhere else.

Separation between navigation and safety systems, operational systems and crew access is the single most valuable measure available — see vessel networks and satellite communications.

Supplier remote access

The exposure operators most often cannot describe.

Equipment suppliers need to support what they installed, so remote access is arranged. Years later it is still active, shared among their staff, unmonitored, and frequently not recorded anywhere by the operator.

Each supplier connection is a route into vessel systems that you do not control and cannot see. What is needed: named accounts rather than shared ones, access limited to the specific equipment, sessions logged, approval required where practical, and an annual review.

Start by asking each supplier what access they currently hold. The answers are informative.

Removable media

Chart updates, software updates, engineer's laptops and USB drives. These are how updates reach equipment that cannot be updated over a link, and they are a well-established route for malware into isolated systems.

Practical measures: a designated scanning station, a policy about whose media may be connected to what, and a rule that a visiting engineer's laptop does not connect to operational systems without being checked.

Patching

Difficult at sea for practical reasons: bandwidth, cost, and the impossibility of rolling back easily if an update breaks something mid-voyage.

The workable approach is staging. Updates are downloaded ashore or in port, tested on a representative system, then deployed deliberately during a suitable period. Automatic updating over the satellite link is neither affordable nor predictable.

Equipment that can no longer be updated at all should be identified and isolated accordingly.

Phishing, reaching the master

Vessel operations involve a stream of email from agents, charterers, port authorities and suppliers, often under time pressure, frequently with attachments, from correspondents the vessel has not dealt with before.

That is an unusually favourable environment for a convincing fraudulent message, and the pattern where bank details on an invoice are altered is well documented in shipping.

The defence is procedural rather than technical: any change to payment details is verified through a known contact by a separate channel, without exception and without regard to urgency.

The strongest maritime cyber measures are organisational. Segmentation, supplier access control and a verification rule for payment changes outperform any product.

Where it fits with safety management

Cyber risk management is now an expected component of safety management systems, and it is asked about during inspections and vetting.

What that means in practice is that you should be able to show: an assessment of cyber risks relevant to your vessels, defined responsibilities, procedures covering the areas above, evidence that crew have been made aware, and a plan for responding to an incident.

Requirements and expectations vary by flag, class and charterer, so confirm your specific obligations rather than working from a general description.

Incident response, adapted for sea

Shore incident response assumes specialists can be brought in quickly. At sea they cannot.

A vessel plan needs to be executable by the crew: what to disconnect and in what order, how to continue operating without the affected system, who to contact ashore, and what to preserve for investigation.

It must also be available offline and on paper. A response plan stored only on the system that has failed is not a plan.

Critically, it must distinguish between systems that may be disconnected and systems that may not. Navigation and safety equipment is not something a crew member disconnects because a computer is behaving oddly.

The general structure is covered in a small business incident response plan, adapted for the constraints.

The shore organisation

Vessel security is only half of it. The office holds the fleet data, the commercial systems and the banking, with a normal internet connection and a normal set of exposures.

Compromise ashore gives an attacker vessel schedules, crew details, commercial terms and email accounts that vessels and agents trust. In practice the shore office is the more likely target and the easier one.

The measures are the ordinary ones — multi-factor authentication, patching, tested backups, staff awareness — covered in the Cyber Essentials guide.

Where to start

  1. Find out what supplier remote access exists, and document it.
  2. Separate crew access from operational systems.
  3. Establish a rule for verifying payment detail changes.
  4. Put multi-factor authentication on shore email.
  5. Write an incident procedure the crew can follow on paper.

Our team works across maritime and business systems, with a background including vessel operations and GMDSS-certified radio work. Start a conversation.