{"id":19039,"date":"2025-10-23T20:03:15","date_gmt":"2025-10-23T20:03:15","guid":{"rendered":"https:\/\/krogragg.com\/?p=19039"},"modified":"2025-10-23T20:03:15","modified_gmt":"2025-10-23T20:03:15","slug":"role-based-training-a-priority-to-combat-maritime-cyber-risks","status":"publish","type":"post","link":"https:\/\/krogragg.com\/?p=19039","title":{"rendered":"Role-based training a priority to combat maritime cyber risks"},"content":{"rendered":"<p>    Role-based training a priority to combat maritime cyber risks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Maritime operations run on tight schedules and thin margins, and as ships, terminals and supply chains connect systems for visibility and efficiency, attackers gain paths to entry. Cyber risk has become an operational reliability and safety concern, not just an IT issue.<\/p>\n<p>\u201cWhether we are looking at this challenge through an operational or organizational safety lens, cyber risk is a critical business risk. An incident will impact everyone,\u201d says <a href=\"https:\/\/www.marinelog.com\/views\/op-eds\/op-ed-rising-to-uscgs-new-maritime-security-directive\/\">Michael DeVolld,<\/a> senior director of maritime cybersecurity at ABS Consulting.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-primary-threat-ransomware\">Primary threat: ransomware<\/h4>\n<p>\u201cWhile it\u2019s true that digital ships feature more sophisticated and secure technologies, the cyber risk has not changed: ransomware continues to pose a major threat,\u201d explains DeVolld. He describes ransomware as taking down an organization\u2019s computer systems, impacting its entire operational and financial networks, until a ransom is paid, pointing to recent disruptions across busy ports in North America, Australia, Europe and Japan.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-the-expanding-attack-surface\">The expanding attack surface<\/h4>\n<p>According to DeVolld, the push to integrate IT and operational technology (OT) for analytics and predictive maintenance has expanded the attack surface. With the industry increasingly reliant on digital systems, he warned, \u201cthere\u2019s an increased risk of external cyber threats.\u201d<\/p>\n<p>Foundational controls still close the biggest gaps, says DeVolld, adding that patching and updating software, limiting network access and implementing multi-factor authentication are foundational cybersecurity measures that would go a long way toward safeguarding systems.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-underreporting-and-the-new-u-s-coast-guard-rules\">Underreporting and the new U.S. Coast Guard rules<\/h4>\n<p>Citing observations from the U.S. Coast Guard (USCG), DeVolld notes that while the number of reported ransomware attacks is down, the cost is up. The operative word, he stresses, is reported.<\/p>\n<p>\u201cNot all incidents are reported, which is a key issue since regulators and the private sector need to communicate and collaborate to tackle this threat together,\u201d he says. \u201cThe goal we all share is to protect the industry as a whole, and especially to safeguard the world\u2019s largest supply chain.\u201d<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-could-an-attacker-steer-a-ship\">Could an attacker steer a ship?<\/h4>\n<p>DeVolld answers that this is plausible but not likely due to the safety systems and human procedures built into commercial maritime operations. Even so, he cautions that modern ships tie navigation, propulsion, dynamic-positioning, ballast automation and cargo-handling into the same digital backbone that shoreside personnel can reach for analytics and remote support.<\/p>\n<p>If an attacker slipped through weak remote access or an unpatched workstation, \u201cthey could push legitimate-looking commands straight to safety-critical equipment and change a vessel\u2019s behavior in real time should all other safety and human oversight processes fail,\u201d he says.<\/p>\n<p>The answer is to treat cyber risk exactly like any other safety-of-navigation hazard, DeVolld says, by implementing International Association of Classification Societies Unified Requirements (IACS UR) E26\/E27 and International Electrotechnical Commission (IEC) 62443 controls and segmentation, enforcing multi-factor authentication on remote access, maintaining rigorous patching and continuously monitoring OT traffic.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-ports-vendors-and-the-wider-supply-chain\">Ports, vendors and the wider supply chain<\/h4>\n<p>Network-connected OT in port facilities and shore-side are being targeted, DeVolld confirms, explaining that many environments still rely on outdated software and protocols and insufficient access controls. Breaches can disrupt global trade flows, delay cargo deliveries and damage relationships with customers and partners, with consequences that \u201cextend far beyond immediate operational impacts.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-europe-s-chokepoints-multiply-impact\">Europe\u2019s chokepoints multiply impact<\/h4>\n<p>DeVolld highlights high-volume corridors where a single node outage can cascade. The English Channel and Dover Strait funnel North\u2013South Atlantic traffic. The Strait of Gibraltar is a narrow neck for Asia, the Americas and Northern Europe flows. Northwest gateway ports, like Rotterdam, Antwerp-Bruges and Hamburg, move a large share of containerized imports as well as refined products, liquefied natural gas (LNG) and chemicals. \u201cEven a 24-hour cyber stoppage at Rotterdam\u2019s Maasvlakte terminals would strand tens of thousands of twenty-foot equivalent units (TEU),\u201d he says,<\/p>\n<p>Each node couples dense physical traffic with complex, network-connected terminal operations, so resilience should be treated as a shared critical-infrastructure obligation, supported by OT hardening, drills and transparent information-sharing under the EU\u2019s Network and Information Systems Security Directive 2.0 (NIS2). Vessel traffic service (VTS) centers are also key dependencies in these corridors, he notes.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-regulations-are-raising-the-baseline\">Regulations are raising the baseline<\/h4>\n<p>\u201cRegulatory frameworks set a baseline and targets for where we need to go on the cybersecurity journey,\u201d says DeVolld. Objective, third-party safety focused organizations like ABS and its affiliated company, ABS Consulting, add to that by bringing forward standards interpretation, guidance and compliance support to:<\/p>\n<ul class=\"wp-block-list\">\n<li>Protect life, property and the environment; and<\/li>\n<li>Support the maritime community in operating safely, reliably, efficiently and in compliance with applicable regulations and standards.<\/li>\n<\/ul>\n<p>DeVolld\u2019s maritime cybersecurity team helps clients understand how to navigate global maritime regulations.<\/p>\n<p>The International Maritime Organization\u2019s (IMO) Resolution MSC.428(98) mandates cyber risk management in the Safety Management System (SMS) for cargo ships 500 gross tonnage (GT) and above. In the European Union (EU), NIS2 tightens incident reporting timelines and strengthens supply-chain security, requiring measures from cryptography and multi-factor authentication to incident handling and business continuity.<\/p>\n<p>In the United States, the USCG\u2019s final rule (effective July 16, 2025) establishes minimum cybersecurity requirements for US-flagged vessels, Outer Continental Shelf (OCS) facilities, and facilities regulated under the Maritime Transportation Security Act (MTSA), mandating cybersecurity plans, designated officers and structured detection, response and recovery.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-training-for-mtsa-regulated-facilities\">Training for MTSA-regulated facilities<\/h4>\n<p>To support the USCG\u2019s updated MTSA requirements, ABS Consulting offers r<a href=\"https:\/\/www.abs-group.com\/Solutions\/Cybersecurity\/Maritime-Cybersecurity\/Maritime-Cybersecurity-Compliance-to-Industry-Regulations\/MTSA-Cybersecurity-Training\/\">ole-based MTSA compliance training <\/a>for facility security officers, vessel security officers, operational managers and IT\/OT personnel.<\/p>\n<p>Tracks cover the current threat landscape, MTSA-aligned implementation and controls, and incident categories and reporting under 33 CFR, with practical exercises. Courses are available online or on site and include role-specific certificates to support audit readiness.\u201d<\/p>\n<p>The post <a href=\"https:\/\/www.marinelog.com\/news\/role-based-training-a-priority-to-combat-maritime-cyber-risks\/\">Role-based training a priority to combat maritime cyber risks<\/a> appeared first on <a href=\"https:\/\/www.marinelog.com\/\">Marine Log<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Marine Log Staff<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.marinelog.com\/news\/role-based-training-a-priority-to-combat-maritime-cyber-risks\/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=role-based-training-a-priority-to-combat-maritime-cyber-risks\">Go to marinelog<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Role-based training a priority to combat maritime cyber risks Maritime operations run on tight schedules and thin margins, and as ships, terminals and supply chains connect systems for visibility and efficiency, attackers gain paths to entry. Cyber risk has become an operational reliability and safety concern, not just an IT issue. \u201cWhether we are looking [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1146,6766,1148,192,6767,199],"tags":[193],"class_list":["post-19039","post","type-post","status-publish","format-standard","hentry","category-abs-consulting","category-cybder-riks","category-cybersecurity","category-marinelog","category-michael-devolid","category-news","tag-marinelog"],"_links":{"self":[{"href":"https:\/\/krogragg.com\/index.php?rest_route=\/wp\/v2\/posts\/19039"}],"collection":[{"href":"https:\/\/krogragg.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/krogragg.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/krogragg.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/krogragg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19039"}],"version-history":[{"count":0,"href":"https:\/\/krogragg.com\/index.php?rest_route=\/wp\/v2\/posts\/19039\/revisions"}],"wp:attachment":[{"href":"https:\/\/krogragg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19039"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/krogragg.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19039"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/krogragg.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}