On a modern vessel, the electronic chart display on the bridge shares network infrastructure with the crew's internet access. The engine monitoring system sends data through the same satellite link that delivers email. This convergence of Information Technology (IT) and Operational Technology (OT) creates attack surfaces that traditional maritime safety thinking never anticipated.
This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.
The Origins of Maritime IT/OT Convergence
Twenty years ago, bridge systems were islands. The Electronic Chart Display and Information System (ECDIS) ran on proprietary hardware. The radar operated independently. The Automatic Identification System (AIS) transmitted on VHF frequencies with no IP connectivity.
Then came three converging forces:
- Cost pressure: Commercial off-the-shelf (COTS) hardware running Windows became cheaper than purpose-built maritime systems
- Connectivity demands: Charterers, owners, and crew all wanted internet access at sea
- Remote monitoring: Shore-based technical management required real-time engine and cargo data
The result: modern vessels have dozens of Windows-based systems, connected through Ethernet networks, sharing bandwidth on VSAT links that also carry crew welfare internet traffic.
The Attack Surface on a Modern Vessel
Consider the network topology of a typical 2020-built container ship:
Bridge Systems (OT)
- ECDIS (often Windows-based, requires chart updates)
- Radar/ARPA (increasingly integrated with ECDIS)
- AIS transponder (connected to display systems)
- Voyage Data Recorder (network-connected for data extraction)
- Dynamic Positioning system (on DP vessels)
- GMDSS equipment
Engine Room Systems (OT)
- Engine monitoring and alarm systems
- Power management systems
- Cargo monitoring (tank levels, temperatures)
- Ballast control systems
- Propulsion control systems
Administrative Systems (IT)
- Ship-to-shore email (often via VSAT)
- Planned maintenance systems
- Crew management software
- Document management systems
- Crew welfare internet access
On many vessels, all of these systems share network infrastructure. The firewall separating crew internet from navigation systems may be a single point of failure—or may not exist at all.
Real-World Attack Vectors
The USB Problem
ECDIS systems require regular chart updates. On many vessels, these updates arrive on USB flash drives. The same USB ports are used by crew for personal data, by port agents for documentation, and by service engineers for system maintenance.
The NotPetya attack in 2017 demonstrated how malware can spread through legitimate business channels. Maersk lost an estimated $300 million after NotPetya propagated through their network. The malware entered through Ukrainian tax software updates—a supply chain attack that no one anticipated.
VSAT Vulnerabilities
Most maritime VSAT systems use shared infrastructure. The same satellite link that carries navigation system updates also carries crew social media traffic. Phishing attacks targeting crew members can provide initial access to the vessel's network.
More critically, many VSAT terminals have management interfaces exposed to the internet. Security researchers have documented default credentials, unpatched vulnerabilities, and configuration weaknesses across major maritime VSAT providers.
Service Engineer Access
OT systems require periodic maintenance by manufacturer engineers. These engineers often connect their laptops directly to critical systems. A compromised service laptop can introduce malware to navigation or propulsion systems.
The Stuxnet attack on Iranian nuclear facilities demonstrated that even air-gapped OT systems can be compromised through service personnel. Maritime OT systems, which are rarely air-gapped, are substantially more vulnerable.
Consequences of IT/OT Compromise
The convergence of IT and OT means that attacks can cross boundaries that vessel operators assumed were secure:
| Attack Entry Point | Potential Impact |
|---|---|
| Phishing email to crew | Ransomware spreads to navigation systems |
| Infected USB chart update | ECDIS compromise, position spoofing |
| VSAT management interface | Complete network access, data exfiltration |
| Compromised service laptop | Engine control system manipulation |
| Crew welfare device | Lateral movement to administrative systems |
A successful attack could result in:
- Loss of navigation capability (ECDIS, radar display failures)
- Incorrect position data (GPS/AIS spoofing)
- Engine monitoring failures (loss of alarms, incorrect readings)
- Operational paralysis (ransomware encrypting critical systems)
- Safety system compromise (ballast control, fire detection)
Network Segmentation: The First Defence
IACS UR E26 mandates network segmentation—separating critical OT systems from less-critical IT systems. But effective segmentation is harder than it sounds:
Zone Architecture
A properly segmented vessel network should have distinct zones:
- Safety Zone: Navigation, GMDSS, fire detection—no external connectivity
- Control Zone: Engine monitoring, cargo control—restricted connectivity
- Business Zone: Ship-shore communication, maintenance systems—monitored connectivity
- Crew Zone: Welfare internet—isolated from all other zones
Enforcement Mechanisms
Zone boundaries require enforcement through:
- Hardware firewalls (not just software firewalls on Windows systems)
- VLAN segmentation with proper access control lists
- Unidirectional security gateways for critical data flows
- Physical separation where network controls are insufficient
USB Control: A Practical Approach
Complete USB prohibition is impractical—chart updates, planned maintenance data, and classification documentation often require physical media transfer. Instead, implement controlled USB procedures:
- Dedicated scanning station: A standalone system that scans all USB media before use on critical systems
- Approved media policy: Company-issued USB drives that are tracked and scanned regularly
- Port disabling: USB ports on critical systems disabled except during authorised updates
- Audit logging: All USB insertions logged and reviewed
The Path to Secure Convergence
IT/OT convergence is irreversible. The economic benefits of connected systems are too significant to abandon. The solution is not to retreat to isolated systems but to manage convergence securely:
- Asset inventory: You cannot protect what you do not know exists. Document every networked system aboard.
- Network mapping: Understand actual traffic flows, not assumed boundaries. Network traffic analysis often reveals unexpected connections.
- Risk assessment: Evaluate each connection point. What happens if this link is compromised?
- Segmentation implementation: Build zones based on risk assessment, not convenience.
- Monitoring: Even well-segmented networks can be breached. Detect anomalies before they become incidents.
Next in the Series
Network segmentation is a regulatory requirement under IACS UR E26. The next article in this series will provide practical guidance for achieving compliance—including what classification societies actually look for during surveys.
This is the second article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.