Maritime Cybersecurity

What Is Maritime Cybersecurity? OT Systems, Networks and Cyber Risks Onboard Ships

Published 22/8/2026· OT Cyber Defence

I spent several years sailing as an Electro-Technical Officer (ETO), working directly with the electrical, automation and control systems that keep a ship running. Today, as a cybersecurity engineer, I see those same systems through another lens.

A PLC controlling machinery, an ECDIS receiving navigation data, or an engine monitoring system was never just a machine. But my current work allows me to look more closely at how the connectivity, interfaces and dependencies around these systems can also make them part of a ship’s cyber attack surface.

Having worked with these systems onboard and now working in cybersecurity gives me a practical perspective on where maritime OT can be vulnerable and, more importantly, how it can be secured.

In the maritime industry, a cyber incident is not limited to stolen passwords or unavailable office applications. Depending on the system affected, it can disrupt cargo operations, navigation, communications or other functions that support the safe operation of a vessel.

This is where maritime cybersecurity comes in.

What is Maritime Cybersecurity?

Maritime cybersecurity is the practice of protecting ships, ports, offshore assets and the wider maritime transportation ecosystem from cyber threats. It covers both Information Technology (IT) systems, such as email, crew internet and business applications, and Operational Technology (OT) systems used for navigation, machinery automation, cargo operations and industrial control.

Shipping carries more than 80% of world merchandise trade by volume, making maritime transportation a critical part of the global supply chain.1 At the same time, ships and ports are becoming increasingly digital and connected.

Onboard vessels, satellite connectivity such as VSAT and newer LEO services makes it practical to exchange operational data with shore in near real time. Ports are also adopting increasing levels of automation. A 2025 inventory identified 76 container terminals worldwide with some form of operational automation, representing roughly 9% of major container terminals.2

Automation itself does not mean that equipment is directly exposed to the Internet. The cybersecurity concern comes from the growing integration between OT systems, IT networks, remote-access services, vendor systems, cloud platforms and Internet-connected devices.

Scope of this article: Maritime cybersecurity covers both ships and shore-based maritime infrastructure such as ports and terminals. However, this article focuses primarily on shipboard OT cybersecurity, drawing on my experience working with electrical, automation, navigation and control systems onboard vessels. Port cybersecurity is introduced for context and will be covered separately in more detail.

Why is Maritime Cybersecurity Becoming So Important?

Ports are automating processes to improve efficiency, safety and cargo handling. This can involve automated cranes, terminal operating systems, sensors, remote-control systems and other technologies that require different IT and OT systems to exchange information.

Ships are going through a similar transition.

For decades, much of the operational technology onboard ships was relatively isolated. Engineers monitored machinery locally, navigators commonly received chart updates through physical media, and engine automation systems generally had limited interaction with shore-based business systems.

That model is changing.

Today, shipowners and fleet managers increasingly want near-real-time visibility into:

  • Fuel consumption
  • Engine performance
  • Vessel performance
  • Route optimization
  • Predictive and condition-based maintenance
  • Environmental and emissions data

These use cases require operational data to move beyond the equipment that originally generated it.

The result is not simply “more Internet on ships.” It is greater IT/OT convergence, and therefore a larger potential cyber attack surface.

A retrospective study of 46 significant maritime cybersecurity incidents between 2010 and 2020 similarly noted that increasing connectivity and convergence between IT and OT expose maritime operations to new threats.3

The publicly available Maritime Cyber Attack Database (MCAD) maintained by the Maritime IT Security research group at NHL Stenden University of Applied Sciences now contains information on more than 295 maritime cyber incidents, covering vessels, ports and other maritime facilities.4

Some Real Maritime Cyber Incidents

The risk is not purely theoretical. Maritime organizations and operational systems have already been affected by cyber incidents.

1. IRISL cyberattack — 2011

A cyberattack against the Islamic Republic of Iran Shipping Lines (IRISL) damaged data related to rates, loading, cargo numbers, dates and locations. According to a retrospective maritime cybersecurity study, the attack also disrupted the company’s internal communications and caused financial and cargo losses.5

The important point here is that an attack does not necessarily need to manipulate a PLC or navigation system to affect maritime operations. Compromising the information that an organization depends on can itself create serious operational consequences.

2. Gulf of Mexico drilling rig — 2013

In another incident documented in the same study, virus-infected PCs and USB devices were connected to a local network on a drilling rig in the Gulf of Mexico. The malware disturbed communications between the dynamic positioning system and the thrusters, and drilling operations were halted.6

This is particularly relevant to OT cybersecurity because removable media is still required in many industrial environments for maintenance, software updates and data transfer.

3. GNSS spoofing in the Black Sea — 2017

At least 20 ships near Novorossiysk in the Black Sea reported navigation systems showing positions approximately 32 km away from their actual locations. The observations were assessed as likely being caused by GNSS spoofing.7

This is an important reminder that not every cyber or cyber-physical attack needs to enter the vessel through its Internet connection. Navigation systems depend on external signals as well.

4. TERPORT ransomware incident — 2025

In December 2025, Paraguayan terminal operator TERPORT was reported as a victim of the Lynx ransomware group.8

Incidents such as these show why maritime cybersecurity needs to cover the complete ecosystem: vessels, ports, shipping companies, service providers and the digital connections between them.

Many additional incidents and their sources can be explored through the public MCAD database.9

What OT Equipment is Used Onboard Ships?

I have worked directly with shipboard electrical, automation and control systems, and one thing worth understanding is that there is no single device called “ship OT.”

A vessel is a collection of systems from different manufacturers, generations and operational domains. Some are traditional industrial control systems, while others are navigation, communication or safety systems that interact with the vessel’s operational environment.

1. ECDIS — Electronic Chart Display and Information System

ECDIS is a computer-based navigation system used to display Electronic Navigational Charts (ENCs) together with information such as the vessel’s position, heading and speed. It is used for route planning and route monitoring and can receive data from other navigational sensors.10

2. RADAR / ARPA

RADAR supports target detection and collision avoidance. ARPA (Automatic Radar Plotting Aid) processes radar targets to help navigators assess their movement and collision risk.

3. GPS / GNSS

GNSS provides positioning information used by multiple bridge systems. GPS is one GNSS constellation; other constellations include Galileo, GLONASS and BeiDou.

4. AIS — Automatic Identification System

AIS exchanges vessel identity, position, course, speed and other information to support vessel traffic awareness and collision avoidance.

Communication Systems

1. Satellite communications

Ships use satellite communication systems for ship-to-shore connectivity. Depending on the vessel and service provider, this may include GEO-based VSAT systems and LEO satellite services such as Starlink.

2. GMDSS — Global Maritime Distress and Safety System

GMDSS is the internationally defined communications framework used for distress alerting, maritime safety information and search-and-rescue communications. It includes multiple terrestrial and satellite communication technologies rather than being a single piece of equipment.11

Engine and Machinery Automation

1. PLCs — Programmable Logic Controllers

PLCs are used throughout a vessel for controlling pumps, compressors, valves, auxiliary machinery and other automated processes.

2. IAS / AMS and SCADA-type systems

Integrated Automation Systems (IAS) and Alarm Monitoring Systems (AMS) provide centralized monitoring and, depending on the implementation, control of machinery and alarms. Some vessels also use SCADA-type architectures for specific systems.

3. Power Management System (PMS)

The PMS manages functions such as generator start/stop, synchronization, load sharing, load-dependent starting and preferential load shedding.

4. Sensors and condition-monitoring systems

Modern vessels may collect fuel-flow, pressure, temperature, vibration, power and other machinery data for onboard monitoring or transmission to shore-based analytics platforms.

Other cyber-relevant shipboard systems can include cargo control systems, ballast systems, dynamic positioning systems, propulsion and engine control systems, BNWAS, voyage data recorders, integrated bridge systems and vendor remote-maintenance interfaces.

The exact architecture varies considerably by vessel type, age and manufacturer.

How Ship Networks Traditionally Looked

On many older or less-connected vessels, the network providing Internet and business connectivity was largely separate from the operational systems controlling or monitoring the ship.

A simplified architecture could look like this:

Simplified traditional ship network architecture showing the ship IT network separated from OT systems

Figure 1: Simplified example of a more isolated shipboard network. Actual vessel architectures vary significantly.

The VSAT connection reached the ship’s router or firewall and then the onboard IT network. Different logical networks could be used for business systems, crew Wi-Fi and onboard PCs.

Meanwhile, machinery automation, navigation equipment and other OT systems could remain on separate networks with little or no routine connectivity to shore.

In such an environment:

  • Engine automation remained primarily onboard.
  • Shore offices had limited real-time visibility into machinery systems.
  • ECDIS chart updates could be transferred using removable media such as USB devices.
  • Maintenance often required someone to physically access the equipment.

This reduced some remote attack paths, but isolated did not mean secure.

Malware could still enter through removable media or maintenance laptops. GNSS spoofing and jamming could affect navigation without compromising the vessel’s internal network. Insider activity and physical access also remained possible attack vectors.

How Modern Connected Ships Exchange Data

Modern vessels increasingly exchange operational data with shore systems.

A simplified connected architecture could look like this:

Simplified modern connected ship network showing navigation and engine data integrated with shore services

Figure 2: Simplified conceptual architecture of a connected vessel. The diagram illustrates connectivity rather than a recommended security architecture.

For example:

  • A chart-management platform may deliver ENC updates through an onboard gateway to ECDIS.
  • Engine-performance systems can collect machinery data and send selected information ashore.
  • IoT or industrial gateways can aggregate data from sensors and control systems.
  • Fleet operation centres can monitor vessel performance from shore.
  • Equipment vendors may provide remote diagnostics and support.

Systems such as NAVTOR’s NavBox are examples of this type of ship-to-shore digital integration, including distribution of navigational content and data between vessels and shore systems.12

This connectivity provides clear operational benefits. The cybersecurity question is how that connectivity is designed, restricted and monitored.

Where is the Cyber Attack Surface on a Connected Ship?

A common mistake is to think that placing a firewall between networks automatically makes OT secure.

The firewall is an important control, but security depends on the complete architecture: firewall rules, segmentation, identity management, remote access, endpoint security, system hardening, vendor access, removable media controls and monitoring.

An attacker also does not necessarily need to attack the PLC directly.

Entry point or weakness Possible consequence
Compromised crew or business laptop Malware propagation or attempted lateral movement
Incorrect firewall or VLAN configuration Unintended communication between IT and OT networks
Compromised remote-maintenance account Unauthorized access to operational systems
Infected USB or maintenance laptop Malware introduced into an otherwise isolated system
Vulnerable ship-to-shore gateway Potential path toward connected operational data or systems
GNSS spoofing or jamming Incorrect or unavailable positioning data without compromising the internal network
Compromised vendor or third-party service Supply-chain path into shipboard systems
Weakly protected IoT gateway Pivot point between sensors, OT networks and external services

The important concept is attack-path thinking.

Suppose an engine PLC itself has no Internet connection. Its data may be read by an engine monitoring system, which communicates with an IoT gateway, which in turn sends information to a shore platform.

The PLC is still not “on the Internet.” But a chain of trusted connections now exists around it.

That does not automatically make the architecture insecure. It means every connection, trust relationship and gateway needs to be considered during the cybersecurity design.

This is why network segmentation, least-privilege communication, secure remote access, monitoring, removable-media controls and properly configured firewalls are important in maritime OT environments.

Maritime OT Cybersecurity: The Challenge Ahead

The idea that ships are completely “air-gapped” is becoming increasingly difficult to apply to modern vessels.

At the same time, it would also be incorrect to assume that every PLC, ECDIS or machinery controller is directly connected to the Internet. In practice, ship architectures vary widely, and operational systems are often connected through several intermediate networks and gateways.

That distinction is important.

The challenge for maritime OT cybersecurity is not to prevent every connection. Modern shipping increasingly depends on data exchange.

The challenge is to connect operational systems without creating uncontrolled paths into safety- and operations-critical environments.

As connectivity improves, the maritime industry is likely to make greater use of:

  • Remote diagnostics
  • Condition-based and predictive maintenance
  • Shore-based vessel-performance monitoring
  • AI-assisted route and fuel optimization
  • Cloud-based fleet management
  • Increasingly autonomous and remotely supported operations

Each of these can provide operational value. Each also introduces dependencies that need to be understood from a cybersecurity perspective.

Final Thoughts

Maritime cybersecurity is no longer only an IT issue. It sits at the intersection of navigation, marine engineering, networking, automation and operational technology.

My own perspective on these systems has changed as my career moved from operating and maintaining shipboard equipment to working in cybersecurity. The machinery has not suddenly become dangerous because it is digital. What has changed is the number of systems, networks and external services that can now interact with operational environments.

Whether the task is protecting ECDIS-related data flows, securing a PLC network controlling auxiliary machinery, managing remote vendor access or preventing ransomware from disrupting a port terminal, the objective is ultimately the same:

Keep maritime operations safe, reliable and resilient while still gaining the benefits of digital connectivity.


References

Footnotes

  1. UN Trade and Development (UNCTAD), Review of Maritime Transport. Maritime transport carries over 80% of world merchandise trade by volume. https://unctad.org/topic/transport-and-trade-logistics/review-of-maritime-transport ↩

  2. Port Economics, Management and Policy, Automated Container Terminals, 2025. https://porteconomicsmanagement.org/pemp/contents/part6/terminal-automation/fully-semi-automated-container-terminals-total-hectares/ ↩

  3. P. H. Meland, K. Bernsmed, E. Wille, Ø. J. Rødseth and D. A. Nesheim, A Retrospective Analysis of Maritime Cyber Security Incidents, TransNav, 2021. https://www.transnav.eu/files/A_Retrospective_Analysis_of_Maritime_Cyber_Security_Incidents,1144.pdf ↩

  4. NHL Stenden University of Applied Sciences, Maritime Cyber Attack Database (MCAD). https://maritimecybersecurity.nl/info ↩

  5. P. H. Meland, K. Bernsmed, E. Wille, Ø. J. Rødseth and D. A. Nesheim, A Retrospective Analysis of Maritime Cyber Security Incidents, TransNav, 2021. https://www.transnav.eu/files/A_Retrospective_Analysis_of_Maritime_Cyber_Security_Incidents,1144.pdf ↩

  6. P. H. Meland, K. Bernsmed, E. Wille, Ø. J. Rødseth and D. A. Nesheim, A Retrospective Analysis of Maritime Cyber Security Incidents, TransNav, 2021. https://www.transnav.eu/files/A_Retrospective_Analysis_of_Maritime_Cyber_Security_Incidents,1144.pdf ↩

  7. P. H. Meland, K. Bernsmed, E. Wille, Ø. J. Rødseth and D. A. Nesheim, A Retrospective Analysis of Maritime Cyber Security Incidents, TransNav, 2021. https://www.transnav.eu/files/A_Retrospective_Analysis_of_Maritime_Cyber_Security_Incidents,1144.pdf ↩

  8. Maritime Cyber Attack Database (MCAD), TERPORT incident record. https://maritimecybersecurity.nl/incident/gyVz7NZmxX ↩

  9. NHL Stenden University of Applied Sciences, Maritime Cyber Attack Database (MCAD). https://maritimecybersecurity.nl/info ↩

  10. International Maritime University learning material / IMO-aligned ECDIS definition. https://www.imu.edu.in/imunew/uploads/files/exams/studymaterial/DLM_Sem3_28032025.pdf ↩

  11. International Maritime Organization (IMO), Global Maritime Distress and Safety System (GMDSS) Manual. https://wwwcdn.imo.org/localresources/en/OurWork/Safety/Documents/II970E.pdf ↩

  12. NAVTOR, digital navigation and ship-to-shore services. https://www.navtor.com/ ↩