Cyber risk has emerged as a critical safety and reliability concern in the maritime sector, transcending traditional IT issues as operations increasingly rely on interconnected systems. Cyber threats exploit these connections, posing significant risks to shipping operations, terminals, and supply chains.
“Whether we are looking at this challenge through an operational or organisational safety lens, cyber risk is a critical business risk. An incident will impact everyone,” states Michael DeVolld, Senior Director of Maritime Cybersecurity at ABS Consulting.
The persistent menace of ransomware
Ransomware remains a significant threat despite the advancement of digital technologies on modern ships.
Michael DeVolld explains that while the systems are more sophisticated, the risk of ransomware attacks persists, disrupting operational and financial networks until a ransom is paid. Such disruptions have recently affected ports in North America, Australia, Europe, and Japan.
Expanding attack surface through integration
The integration of IT and OT for improved analytics and predictive care has widened the attack vectors
The integration of IT and operational technology (OT) for enhanced analytics and predictive maintenance has broadened the attack vectors, according to DeVolld.
This integration has increased external cyber threats, necessitating robust security measures.
Foundational cybersecurity practices such as software updates, network access limitations, and multi-factor authentication play a crucial role in safeguarding against these risks.
Underreporting incidents and new regulations
Despite a reported decrease in ransomware attacks, the costs associated with such incidents have risen. DeVolld emphasises that not all incidents are reported, which complicates collaborative efforts between regulators and the private sector to address these threats.
The US Coast Guard has highlighted the importance of transparency and collaboration in mitigating risks and protecting the global supply chain.
Potential threats to ship operations
DeVolld acknowledges the potential for cyber attacks to impact critical systems if security measures fail
While the idea of hackers steering ships might seem far-fetched, DeVolld acknowledges the potential for cyber attacks to impact critical systems if security measures fail.
He highlights the necessity of treating cyber risk on par with other navigation hazards, recommending the adoption of international standards like IACS UR E26/E27 and IEC 62443 to enhance system protection.
Impact on ports and supply chains
Network-connected OT systems in port facilities are vulnerable, often hampered by outdated software and insufficient access controls. These vulnerabilities can disrupt global trade and delay cargo deliveries, affecting customer relationships and broader industry operations.
DeVolld points to key European maritime chokepoints, such as the English Channel and the Strait of Gibraltar, where a single node outage can have cascading effects.
Regulatory frameworks and compliance initiatives
New regulatory frameworks, like the EU's NIS2 and the USCG's cybersecurity needs, are raising standards
New regulatory frameworks, like the EU's NIS2 and the USCG's cybersecurity requirements, are raising standards within the industry. These regulations mandate enhanced security measures, faster incident reporting, and structured cybersecurity plans.
ABS Consulting offers training to help maritime professionals meet these standards, supporting compliance and improving audit readiness.
Enhancing maritime cybersecurity training
To align with the updated MTSA requirements from the USCG, ABS Consulting provides role-based MTSA Compliance Training.
This training, available online or on-site, covers threat landscapes, MTSA-aligned controls, and incident reporting, offering certificates to support facility and vessel security officers, managers, and IT/OT personnel in maintaining compliance.
Maritime operations run on tight schedules and thin margins, and as ships, terminals and supply chains connect systems for visibility and efficiency, attackers gain paths to entry. Cyber risk has become an operational reliability and safety concern, not just an IT issue.
“Whether we are looking at this challenge through an operational or organisational safety lens, cyber risk is a critical business risk. An incident will impact everyone,” says Michael DeVolld, Senior Director of Maritime Cybersecurity at ABS Consulting.
The primary threat: Ransomware
“While it’s true that digital ships feature more sophisticated and secure technologies, the cyber risk has not changed: ransomware continues to pose a major threat,” explains DeVolld.
He describes ransomware as taking down an organisation’s computer systems, impacting its entire operational and financial networks, until a ransom is paid, pointing to recent disruptions across busy ports in North America, Australia, Europe and Japan.
The expanding attack surface
According to DeVolld, the push to integrate IT and operational technology (OT) for analytics and predictive maintenance has expanded the attack surface. With the industry increasingly reliant on digital systems, he warned, “there’s an increased risk of external cyber threats.”
Foundational controls still close the biggest gaps, says DeVolld, adding that patching and updating software, limiting network access and implementing multi-factor authentication are foundational cybersecurity measures that would go a long way toward safeguarding systems.
Underreporting and the New U.S. Coast Guard Rules
Citing observations from the U.S. Coast Guard (USCG), DeVolld notes that while the number of reported ransomware attacks is down, the cost is up. The operative word, he stresses, is reported.
“Not all incidents are reported, which is a key issue since regulators and the private sector need to communicate and collaborate to tackle this threat together,” he says. "The goal we all share is to protect the industry as a whole, and especially to safeguard the world’s largest supply chain.”
Could an attacker steer a ship?
DeVolld answers that this is plausible but not likely due to the safety systems and human procedures built into commercial maritime operations. Even so, he cautions that modern ships tie navigation, propulsion, dynamic-positioning, ballast automation and cargo-handling into the same digital backbone that shoreside personnel can reach for analytics and remote support.
If an attacker slipped through weak remote access or an unpatched workstation, “they could push legitimate-looking commands straight to safety-critical equipment and change a vessel’s behaviour in real time should all other safety and human oversight processes fail,” he says.
The answer is to treat cyber risk exactly like any other safety-of-navigation hazard, DeVolld says, by implementing International Association of Classification Societies Unified Requirements (IACS UR) E26/E27 and International Electrotechnical Commission (IEC) 62443 controls and segmentation, enforcing multi-factor authentication on remote access, maintaining rigorous patching and continuously monitoring OT traffic.
Ports, vendors and the wider supply chain
Network-connected OT in port facilities and shore-side are being targeted, DeVolld confirms, explaining that many environments still rely on outdated software and protocols and insufficient access controls.
Breaches can disrupt global trade flows, delay cargo deliveries and damage relationships with customers and partners, with consequences that “extend far beyond immediate operational impacts."
Europe’s chokepoints multiply impact
DeVolld highlights high-volume corridors where a single node outage can cascade. The English Channel and Dover Strait funnel North–South Atlantic traffic. The Strait of Gibraltar is a narrow neck for Asia, the Americas and Northern Europe flows.
Northwest gateway ports, like Rotterdam, Antwerp-Bruges and Hamburg, move a large share of containerised imports as well as refined products, liquefied natural gas (LNG) and chemicals. “Even a 24-hour cyber stoppage at Rotterdam’s Maasvlakte terminals would strand tens of thousands of twenty-foot equivalent units (TEU),” he underscores.
Each node couples dense physical traffic with complex, network-connected terminal operations, so resilience should be treated as a shared critical-infrastructure obligation, supported by OT hardening, drills and transparent information-sharing under the EU’s Network and Information Systems Security Directive 2.0 (NIS2). Vessel traffic service (VTS) centres are also key dependencies in these corridors, he notes.
Regulations are raising the baseline
“Regulatory frameworks set a baseline and targets for where we need to go on the cybersecurity journey,” says DeVolld. Objective, third-party safety-focused organisations like ABS and its affiliated company, ABS Consulting, add to that by bringing forward standards interpretation, guidance and compliance support to:
- Protect life, property and the environment; and
- Support the maritime community in operating safely, reliably, efficiently and in compliance with applicable regulations and standards.
DeVolld’s maritime cybersecurity team helps clients understand how to navigate global maritime regulations.
Minimum cybersecurity requirements
The International Maritime Organization’s (IMO) Resolution MSC.428(98) mandates cyber risk management in the Safety Management System (SMS) for cargo ships 500 gross tonnage (GT) and above.
In the European Union (EU), NIS2 tightens incident reporting timelines and strengthens supply-chain security, requiring measures from cryptography and multi-factor authentication to incident handling and business continuity.
In the United States, the USCG’s final rule (effective July 16, 2025) establishes minimum cybersecurity requirements for US-flagged vessels, Outer Continental Shelf (OCS) facilities, and facilities regulated under the Maritime Transportation Security Act (MTSA), mandating cybersecurity plans, designated officers and structured detection, response and recovery.
Training for MTSA-regulated facilities
To support the USCG’s updated MTSA requirements, ABS Consulting offers role-based MTSA Compliance Training for Facility Security Officers, Vessel Security Officers, operational managers and IT/OT personnel.
Tracks cover the current threat landscape, MTSA-aligned implementation and controls, and incident categories and reporting under 33 CFR, with practical exercises. Courses are available online or on site and include role-specific certificates to support audit readiness.