The maritime industry stands at an inflection point. Autonomous vessels, remote operations centres, AI-enhanced navigation, and pervasive connectivity are transforming shipping from an analogue industry with digital components to a digital industry with physical assets. The cyber security implications are profound.

This is the final article in the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

The Trajectory of Maritime Digitalisation

Consider the evolution over two decades:

  • 2005: Electronic charts supplement paper; most systems isolated
  • 2015: ECDIS mandatory; VSAT connectivity common; systems networked
  • 2025: Remote monitoring standard; AI decision support; extensive integration
  • 2035: Autonomous vessels operational; shore-based management; minimal crew

Each step increases capability and efficiency. Each step expands the attack surface.

Maritime Autonomous Surface Ships (MASS)

The IMO has been developing a regulatory framework for Maritime Autonomous Surface Ships (MASS), categorised by degrees of autonomy:

  • Degree 1: Automated processes with seafarers on board to intervene
  • Degree 2: Remotely controlled with seafarers on board
  • Degree 3: Remotely controlled without seafarers on board
  • Degree 4: Fully autonomous—no human intervention required

Even Degree 1 vessels require cyber security beyond current requirements. Degree 3 and 4 vessels are fundamentally cyber-dependent: a successful cyber attack could render the vessel uncontrollable.

MASS Cyber Considerations

MASS DegreePrimary Cyber RiskMitigation Approach
1-2 (crewed)System manipulation affecting decisionsVerification, override capability
3 (remote control)Communication link compromiseRedundancy, authentication, encryption
4 (autonomous)Algorithm/AI manipulationIntegrity verification, anomaly detection

Shore-Based Ship Management

Even before full autonomy, vessels increasingly operate as nodes in shore-managed networks:

  • Performance monitoring: Real-time engine and fuel data to technical managers
  • Voyage optimisation: Route and speed recommendations from shore
  • Predictive maintenance: AI analysis of equipment condition
  • Remote diagnostics: Vendor engineers troubleshooting from shore

Security Implications

This connectivity creates new attack vectors:

  • Shore-to-ship: Compromised shore systems could push malicious commands to vessels
  • Ship-to-shore: Infected vessels could compromise corporate networks
  • Man-in-the-middle: Intercepted communications could be manipulated
  • Vendor access: Third-party remote access expands the trust boundary

AI and Machine Learning at Sea

AI is being deployed across maritime operations:

  • Collision avoidance: Enhanced ARPA with predictive capabilities
  • Weather routing: Dynamic route optimisation based on conditions
  • Anomaly detection: Identifying unusual system behaviour
  • Maintenance prediction: Anticipating equipment failures

AI-Specific Threats

AI systems face unique attack vectors:

  • Training data poisoning: Corrupted data creates flawed models
  • Adversarial inputs: Crafted inputs that fool AI but not humans
  • Model theft: Extracting proprietary algorithms
  • Dependency attacks: Compromising ML libraries or frameworks

A navigation AI that was trained on poisoned data might make systematically wrong decisions in specific circumstances—potentially leading vessels into danger.

Evolving Regulatory Landscape

IMO MASS Regulatory Scoping

The IMO is adapting existing conventions for MASS operations. Cyber security is explicitly addressed as a cross-cutting issue affecting:

  • Safety of Life at Sea (SOLAS)
  • Standards of Training, Certification and Watchkeeping (STCW)
  • Marine Pollution Prevention (MARPOL)
  • Rules for Preventing Collisions at Sea (COLREGs)

IACS Requirements Evolution

IACS UR E26 and E27 are first-generation requirements. Expect future versions to address:

  • Remote operation security requirements
  • AI system integrity verification
  • Communication link resilience standards
  • Shore control centre certification

NIS2 and Beyond

The EU's NIS2 Directive brought maritime into cybersecurity regulation. Future iterations may require:

  • Mandatory vulnerability disclosure
  • Supply chain security certification
  • Security-by-design requirements for new vessels
  • Harmonised incident reporting across jurisdictions

Preparing for the Future

For Ship Operators

  1. Build capability now: Cyber maturity developed on conventional vessels transfers to advanced operations
  2. Demand vendor security: Require cyber security evidence from equipment suppliers
  3. Invest in people: Develop internal expertise, not just compliance
  4. Participate in standards development: Industry input shapes practical regulations

For Equipment Manufacturers

  1. Adopt secure development: Security embedded in design, not bolted on later
  2. Plan for updates: Secure update mechanisms for the vessel's lifetime
  3. Document security: Clear guidance for secure configuration and operation
  4. Support legacy systems: Existing equipment needs ongoing security support

For Regulators and Classification Societies

  1. Balance innovation and safety: Enable technology while managing risks
  2. Develop practical standards: Requirements that can be verified and enforced
  3. Harmonise internationally: Shipping is global; regulations must be consistent
  4. Build expertise: Surveyors and inspectors need cyber competence

The Security Imperative

The cyber-enabled ship offers extraordinary benefits: efficiency, safety, environmental performance. But these benefits depend on security. A navigation AI that can be fooled is worse than no AI at all. Remote control that can be hijacked is more dangerous than no remote control.

Security cannot be an afterthought added to digitally-transformed operations. It must be foundational—designed in from the start, maintained throughout the vessel's life, and continuously adapted as threats evolve.

Conclusion: The Maritime Cyber Playbook

This series has covered the current state of maritime cyber security:

  1. Regulatory foundations: IMO, IACS, NIS2—the compliance baseline
  2. IT/OT convergence: How ship networks create unexpected attack paths
  3. IACS compliance: Practical steps for classification surveys
  4. Incident response: Managing cyber events at sea
  5. PSC inspections: What port state inspectors look for
  6. Crew training: Building human firewalls on rotating crews
  7. Risk assessment: Systematic approach to identifying and treating risks
  8. Future trajectory: Where maritime cyber security is heading

The maritime industry's digital transformation is irreversible. The choice is not whether to embrace cyber-enabled operations but whether to do so securely. Those who build strong cyber foundations today will be best positioned to operate safely and competitively in the digital maritime future.


This concludes the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.