The maritime industry stands at an inflection point. Autonomous vessels, remote operations centres, AI-enhanced navigation, and pervasive connectivity are transforming shipping from an analogue industry with digital components to a digital industry with physical assets. The cyber security implications are profound.
This is the final article in the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.
The Trajectory of Maritime Digitalisation
Consider the evolution over two decades:
- 2005: Electronic charts supplement paper; most systems isolated
- 2015: ECDIS mandatory; VSAT connectivity common; systems networked
- 2025: Remote monitoring standard; AI decision support; extensive integration
- 2035: Autonomous vessels operational; shore-based management; minimal crew
Each step increases capability and efficiency. Each step expands the attack surface.
Maritime Autonomous Surface Ships (MASS)
The IMO has been developing a regulatory framework for Maritime Autonomous Surface Ships (MASS), categorised by degrees of autonomy:
- Degree 1: Automated processes with seafarers on board to intervene
- Degree 2: Remotely controlled with seafarers on board
- Degree 3: Remotely controlled without seafarers on board
- Degree 4: Fully autonomous—no human intervention required
Even Degree 1 vessels require cyber security beyond current requirements. Degree 3 and 4 vessels are fundamentally cyber-dependent: a successful cyber attack could render the vessel uncontrollable.
MASS Cyber Considerations
| MASS Degree | Primary Cyber Risk | Mitigation Approach |
|---|---|---|
| 1-2 (crewed) | System manipulation affecting decisions | Verification, override capability |
| 3 (remote control) | Communication link compromise | Redundancy, authentication, encryption |
| 4 (autonomous) | Algorithm/AI manipulation | Integrity verification, anomaly detection |
Shore-Based Ship Management
Even before full autonomy, vessels increasingly operate as nodes in shore-managed networks:
- Performance monitoring: Real-time engine and fuel data to technical managers
- Voyage optimisation: Route and speed recommendations from shore
- Predictive maintenance: AI analysis of equipment condition
- Remote diagnostics: Vendor engineers troubleshooting from shore
Security Implications
This connectivity creates new attack vectors:
- Shore-to-ship: Compromised shore systems could push malicious commands to vessels
- Ship-to-shore: Infected vessels could compromise corporate networks
- Man-in-the-middle: Intercepted communications could be manipulated
- Vendor access: Third-party remote access expands the trust boundary
AI and Machine Learning at Sea
AI is being deployed across maritime operations:
- Collision avoidance: Enhanced ARPA with predictive capabilities
- Weather routing: Dynamic route optimisation based on conditions
- Anomaly detection: Identifying unusual system behaviour
- Maintenance prediction: Anticipating equipment failures
AI-Specific Threats
AI systems face unique attack vectors:
- Training data poisoning: Corrupted data creates flawed models
- Adversarial inputs: Crafted inputs that fool AI but not humans
- Model theft: Extracting proprietary algorithms
- Dependency attacks: Compromising ML libraries or frameworks
A navigation AI that was trained on poisoned data might make systematically wrong decisions in specific circumstances—potentially leading vessels into danger.
Evolving Regulatory Landscape
IMO MASS Regulatory Scoping
The IMO is adapting existing conventions for MASS operations. Cyber security is explicitly addressed as a cross-cutting issue affecting:
- Safety of Life at Sea (SOLAS)
- Standards of Training, Certification and Watchkeeping (STCW)
- Marine Pollution Prevention (MARPOL)
- Rules for Preventing Collisions at Sea (COLREGs)
IACS Requirements Evolution
IACS UR E26 and E27 are first-generation requirements. Expect future versions to address:
- Remote operation security requirements
- AI system integrity verification
- Communication link resilience standards
- Shore control centre certification
NIS2 and Beyond
The EU's NIS2 Directive brought maritime into cybersecurity regulation. Future iterations may require:
- Mandatory vulnerability disclosure
- Supply chain security certification
- Security-by-design requirements for new vessels
- Harmonised incident reporting across jurisdictions
Preparing for the Future
For Ship Operators
- Build capability now: Cyber maturity developed on conventional vessels transfers to advanced operations
- Demand vendor security: Require cyber security evidence from equipment suppliers
- Invest in people: Develop internal expertise, not just compliance
- Participate in standards development: Industry input shapes practical regulations
For Equipment Manufacturers
- Adopt secure development: Security embedded in design, not bolted on later
- Plan for updates: Secure update mechanisms for the vessel's lifetime
- Document security: Clear guidance for secure configuration and operation
- Support legacy systems: Existing equipment needs ongoing security support
For Regulators and Classification Societies
- Balance innovation and safety: Enable technology while managing risks
- Develop practical standards: Requirements that can be verified and enforced
- Harmonise internationally: Shipping is global; regulations must be consistent
- Build expertise: Surveyors and inspectors need cyber competence
The Security Imperative
The cyber-enabled ship offers extraordinary benefits: efficiency, safety, environmental performance. But these benefits depend on security. A navigation AI that can be fooled is worse than no AI at all. Remote control that can be hijacked is more dangerous than no remote control.
Security cannot be an afterthought added to digitally-transformed operations. It must be foundational—designed in from the start, maintained throughout the vessel's life, and continuously adapted as threats evolve.
Conclusion: The Maritime Cyber Playbook
This series has covered the current state of maritime cyber security:
- Regulatory foundations: IMO, IACS, NIS2—the compliance baseline
- IT/OT convergence: How ship networks create unexpected attack paths
- IACS compliance: Practical steps for classification surveys
- Incident response: Managing cyber events at sea
- PSC inspections: What port state inspectors look for
- Crew training: Building human firewalls on rotating crews
- Risk assessment: Systematic approach to identifying and treating risks
- Future trajectory: Where maritime cyber security is heading
The maritime industry's digital transformation is irreversible. The choice is not whether to embrace cyber-enabled operations but whether to do so securely. Those who build strong cyber foundations today will be best positioned to operate safely and competitively in the digital maritime future.
This concludes the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.