A ransomware infection hits your vessel's administrative network. The ECDIS displays are locked. The engine monitoring system shows anomalous readings. You are 500 nautical miles from the nearest port, with satellite bandwidth measured in kilobits. This is the reality of maritime cyber incident response.

This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

The Maritime Incident Response Challenge

Incident response frameworks assume rapid expert access. NIST, ISO 27035, and SANS all describe processes that work when you can deploy specialists within hours. At sea, that assumption fails.

Constraints Unique to Maritime Operations

  • Physical isolation: Days from port, weeks from specialist support
  • Limited bandwidth: VSAT connections often under 1 Mbps, unusable for remote forensics
  • No spare hardware: The server room is the only server room
  • Crew limitations: ITOs and ETOs are generalists, not incident responders
  • Operational pressure: The vessel must continue to operate safely

These constraints demand a fundamentally different approach to incident response planning.

The Maritime Incident Response Framework

Adapt traditional incident response phases to maritime realities:

Phase 1: Detection

Most maritime cyber incidents are discovered through operational symptoms rather than security monitoring:

  • Navigation systems displaying errors or incorrect data
  • Administrative computers locked with ransom messages
  • Unexplained network slowdowns affecting VSAT
  • Engine monitoring showing anomalous readings
  • AIS transponder behaving unexpectedly

Action: Train crew to recognise these symptoms as potential cyber incidents. The bridge team, engine room watch, and duty officers must understand that IT problems may have safety implications.

Phase 2: Initial Assessment

Before taking any action, answer these questions:

  1. What systems are affected? Navigation, propulsion, cargo, administrative?
  2. Is the vessel's safety compromised? Can we navigate? Can we manoeuvre? Are safety systems operational?
  3. Is the incident spreading? Are more systems becoming affected?
  4. Do we have manual backup procedures? Can we operate without the affected systems?

This assessment determines whether to prioritise containment or continued operation.

Phase 3: Containment

Containment at sea has different priorities than shore-based incidents. The goal is to preserve safe operation, not necessarily to preserve evidence.

Immediate Actions (if safety permits):

  • Isolate affected systems: Disconnect from network, disable wireless
  • Segment the network: If not already segmented, physically disconnect zones
  • Disable unnecessary connectivity: Shut down non-essential VSAT traffic
  • Document actions taken: Time, action, person responsible, observed effect

If safety systems are affected:

  • Switch to manual/backup procedures: Paper charts, manual steering, visual navigation
  • Notify the bridge: Master must know if navigation aids are unreliable
  • Consider voyage adjustment: Reduce speed, alter course toward safer waters
  • Prepare for degraded operations: Additional lookouts, conservative manoeuvring

Phase 4: Communication

Establish communication channels before attempting technical response:

Internal Communication:

  • Inform Master and relevant officers
  • Brief crew on operational changes
  • Establish command structure for incident management

External Communication:

  • Company DPA/Technical Manager: Report incident, request guidance
  • Flag State (if safety affected): SOLAS requires reporting of incidents affecting safety
  • Classification society: May be required for class-related systems
  • Insurers: P&I and H&M clubs may have notification requirements

Critical: Use out-of-band communication if ship's email is compromised. Satellite phone, Inmarsat Fleet Safety, or alternative VSAT circuit if available.

Phase 5: Remote Support

Shore-based support is essential but limited by bandwidth. Prioritise communication:

What to send ashore:

  • Incident description and timeline
  • Screenshots of error messages (compressed, not raw images)
  • List of affected systems
  • Actions already taken
  • Current operational status

What shore can provide:

  • Step-by-step guidance for containment
  • Identification of ransomware variants (if applicable)
  • Recovery procedure guidance
  • Coordination with vendors and specialists
  • Regulatory notification assistance

Avoid attempting remote desktop connections or large file transfers over maritime satellite links during incidents.

Phase 6: Recovery

Recovery priorities depend on operational requirements:

PrioritySystemsRecovery Method
1Navigation, GMDSSClean rebuild if necessary, manual backup until complete
2Propulsion control, steeringVerify integrity, test before relying
3Cargo monitoringManual monitoring if system recovery delayed
4Administrative systemsCan wait for port if necessary

Recovery approaches:

  • Restore from backup: If clean backups exist and backup media is aboard
  • Rebuild from installation media: Requires software installation files and license keys
  • Vendor support at next port: Acceptable for non-critical systems
  • Operate in degraded mode: Continue with manual procedures until recovery possible

Preparation: The Real Work

Effective incident response at sea depends entirely on preparation done before the incident occurs.

Documentation Required Aboard

  1. Incident Response Procedures: Step-by-step guides for common scenarios
  2. System Inventory: What systems exist, what they do, how to isolate them
  3. Network Diagrams: Physical and logical topology, zone boundaries, switch locations
  4. Contact List: Shore contacts, vendors, 24/7 support numbers
  5. Recovery Media: Software installation files, backup tapes/drives, license keys
  6. Manual Procedures: Documented alternatives for operating without each system

Training and Drills

Cyber incident drills should be as routine as fire drills:

  • Tabletop exercises: Walk through scenarios without system changes
  • Isolation drills: Practice physically disconnecting systems from the network
  • Communication drills: Test out-of-band communication to shore
  • Recovery drills: Verify backups are usable, restoration procedures work

Document all drills with date, participants, scenario, outcomes, and lessons learned.

Backup Strategy

Maritime backup must account for limited connectivity:

  • Local backups: Complete system images on isolated media
  • Incremental shore sync: Critical data only, when bandwidth permits
  • Air-gapped recovery media: Known-clean installation files stored offline
  • Tested restoration: Regular verification that backups are usable

Scenario: Ransomware at Sea

A practical application of this framework:

0600: Third Officer notices ECDIS workstation displaying ransom message. Other bridge displays working.

Immediate actions:

  1. Physically disconnect affected workstation from network
  2. Inform Master
  3. Check if other systems affected (they are not)
  4. Switch to backup ECDIS or paper charts
  5. Document incident with photos of ransom message

Assessment: Single workstation affected. Navigation capability maintained via backup. No immediate safety concern.

0630: Master informed. Decision: continue voyage, notify shore.

Communication: Satellite phone call to Technical Manager (email system not trusted). Email incident summary from Master's personal device via crew internet (isolated network).

Containment: Verify network segmentation effective. No other systems showing symptoms after 4 hours. Affected workstation remains isolated.

Recovery plan: Rebuild ECDIS workstation from installation media at next port (2 days away). Operate on backup ECDIS until then.

Post-incident: Forensic image of affected drive preserved for shore analysis. Investigation identified USB flash drive as infection vector.

Key Takeaways

  1. Maritime incident response prioritises safe operation over evidence preservation
  2. Preparation determines success—response capability must exist before the incident
  3. Manual procedures are your failsafe; ensure they exist and crew can execute them
  4. Communication planning must account for compromised systems
  5. Recovery at sea is limited; plan for degraded operations

Next in the Series

Port State Control inspections increasingly include cyber elements. The next article covers what PSC officers look for and how to prepare for cyber-focused inspections.


This is the fourth article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.