The Maritime Industry's Slow Boat To Cybersecurity

Despite the critical role the maritime transportation system plays in the economic health of the United States, and despite its fairly recent embrace of all things automated, cranes, vehicles, surveillance and even vessels, the sector has been slow to warm to the need to protect its digital systems and assets.

Post 9/11, security concerns about the nation’s borders, air space and infrastructure, including ports, moved front and center for a brief moment before other concerns, like the search for victims and perpetrators, the cleanup of the site and city, and legislative debate over homeland security needs versus long-held citizen rights, pushed infrastructure to a back burner. Critics kept up a steady drumbeat of worry over the safety of the nation’s ports. In the ensuing years, as port automation grew, physical security was upgraded and nailed down, helped in part by the government’s Port Security Grant program.

Talk about cyber security plodded along under the radar until the publication of two damning reports that took the nation’s ports, the US Coast Guard and Homeland Security Department to task for not aggressively or adequately addressing port cyber vulnerabilities.

Published in 2013, the Brookings Institution’s “The Critical Infrastructure Gap: US Port Facilities and Cyber Vulnerabilities,” is still considered valid today.  Published in 2014 by US General Accounting Office, “Maritime Critical Infrastructure Protection” directed its critique primarily at the US Coast Guard, which it said had failed to conduct a risk assessment that “fully addressed cyber threats, vulnerabilities and consequences.” 

The General Accounting Office also complained that both maritime security plans required by law, and regulation generally, also did not identify or address those same issues.  

“...Two if by Sea”
Perhaps spurred by those two reports, concern about lax port cyber security exploded in 2015, as the alarm was sounded loudly one after another, by a raft of industry organisations, government agencies here and abroad, academia, insurance companies, standards groups, think tanks and researchers. 

Almost simultaneous, together they released a wave of reports, seminars, white papers, primers, strategic plans, directives, resolutions, and even some legislative calls for assessment and information sharing - all addressing what they saw as a deeply worrisome lack of awareness, concern and action addressing the cyber security vulnerabilities of the nation’s ports.
Particularly alarmed were participants in a Maritime Cyber Security Symposium hosted in 2015 by the Command, Control and Interoperability Center for Advanced Data Analysis (CCICADA), where speakers warned that “Maritime Cyber Attacks Occur in a World of the ‘Quick and the Dead,’ and that “Cyber Attacks on Ports and Ships Could be Catastrophic.”

Maritime executives too came in for their share of criticism for failing to take the lead in making cyber security a priority, while the sloppy cyber hygiene of employees on the front line got them labeled as the weakest link.

Wherever you looked, regardless of source, the message was loud and clear, do something about cyber security or face serious business consequences, even regulation. By 2016, the focus was squarely on education, especially crew, and raising awareness that cyber security was a real and pressing danger and that a cultural shift needed to take place, placing cyber security on the same plane as safety management.

Now two-thirds of the way through 2018, much of the preceding 2.5 years also has been spent publishing cyber security guides and checklists, strengthening regulatory directives, completing five-year facility security plans, conducting cyber risk assessments, deploying mitigation efforts, and building relationships in the far-flung, highly complex and competitive port community through participation, in part, in the USCG’s Area Maritime Security Committees (AMSC), and their cyber subcommittees, which can be found in most key port areas.  

ASMCs are comprised of representatives from the USCG, government agencies, law enforcement, shippers, port authorities, terminal operators, harbor vessels, even some clients, all working to identify and address security issues, as well as share information and create best practices, in their areas of operation.

Some of the changes we’ll see this year into next is a much greater emphasis on cyber risk management, resiliency and collaboration, as the cyber security community tries to defend against complacency (even the best security efforts will take a hit at some point) by getting maritime companies and ports to create contingency plans to enable them to recover as painlessly as possible from a successful attack, and to encourage them to work collaboratively on building best practices and sharing information about attempted and successful cyber-attacks.

MarineLink

You Might Also Read: 

COSCO Cyber Attack And The Importance Of Maritime Cybersecurity:

Cybersecurity At Sea:
 

« White House To Step Up Cyber Counter-Offensive
Insurance Experts Expect Higher Cyber Losses »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

BH Consulting

BH Consulting

BH Consulting we are a vendor independent consulting firm providing market leading range of information security services focused on data protection and cybersecurity.

Dataguise

Dataguise

Dataguise provides a data-centric security solution to detect, protect, and monitor sensitive data in real time across all data repositories, both on premises and in the cloud.

Packet Ninjas

Packet Ninjas

Packet Ninjas is a niche cyber security agency with specialized expertise in the use of digital intelligence to strengthen cyber security.

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute (SSPI)

Slovak Security Policy Institute is an independent non-governmental organization that focuses on research and analysis of security challenges including defence and cyber security.

totemo

totemo

Totemo offers solutions for the secure exchange of business information.

CETIC

CETIC

CETIC is an applied research centre in the field of ICT. Key technologies include Big Data, Cloud Computing, the Internet of Things, software quality, and trust and security of IT systems.

42Gears

42Gears

42Gears is a leading Unified Endpoint Management provider. Secure, monitor and manage tablets, phones, desktops and wearables.

Reliance Cyber

Reliance Cyber

Reliance Cyber (formerly Reliance ACSN) help to monitor and manage your organisation’s security infrastructure 24/7, so you can make sure all threats and issues are dealt with.

Valarian

Valarian

Valarian (formerly Worldr) is on a mission to build cutting-edge solutions that empower borderless collaboration in the new era of digital sovereignty.

BaaSid

BaaSid

BaaSid is next generation security technology for data security & security authentication based on De-centralized & Blockchain.

META-Cyber

META-Cyber

META-cyber was founded by engineers with experience in process and control-protection to provide cyber security for industrial infrastructure.

Paragon Cyber Solutions

Paragon Cyber Solutions

Paragon Cyber Solutions provides specialized security risk management and IT solutions to protect the integrity of your business operations.

Sequentur

Sequentur

Sequentur is an award-winning Managed IT Services company. We are SOC 2 certified and provide Managed IT Services and Cybersecurity services to businesses nationwide.

appNovi

appNovi

appNovi inventories everything to map the attack surface, identify missing security agents, and prioritize vulnerabilities based on exposure.

FatPipe Networks

FatPipe Networks

FatPipe’s network optimization solutions along with robust native security and SASE-based protection provides organizations all they need for super network performance and security.

Reclaim Security

Reclaim Security

Reclaim Security is your always-on force multiplier, empowering security teams to eliminate threat exposure using your existing security stack.