
Each vessel at sea is in effect a floating industrial site. Propulsion, steering, ballast, power generation, cargo handling and navigation all run on operational technology (OT), the controllers, sensors and networks which keep a ship moving and a port working. Around 80% of world trade by volume travels this way yet these systems were never designed to be watched.
This is quiet a problem at the centre of maritime cybersecurity. The industry has spent years talking about awareness, policies and training, and rightly so. However, the harder, less visible gap is operational: most maritime OT is not being continuously monitored. We know when a firewall logs an event on the corporate network but we rarely know in real time what is happening on the controlled network of a ship a thousand miles from shore.
There are understandable reasons for this. The first is the air-gap myth. OT was long assumed safe because it was isolated. But in the digital age, satellite connectivity, remote maintenance, electronic navigation and crew devices have eroded that isolation while the assumption of safety and security lingers. A second issue is the lifecycle problem: on average a ship spends around 30 years in service and their systems stay in service for decade. The equipment on board is vendor-specific , most of the time unsupported, and much of it cannot be touched without risking certification and or breaching the safety management systems (SMS). Thirdly is the culture onboard.
On a vessel that cannot stop, anything that might interfere with a live control system is treated with suspicion which makes intrusive security tooling a hard sell. Furthermore there are the realities of the sea itself: intermittent connectivity, constrained bandwidth, and crew rotation make persistent, person-dependent oversight impractical.
Consequently, there’s a tendency in the maritime sector to keep hardcopies and resort to point-in-time thinking. Assurance in maritime has traditionally meant an audit, a survey or a certificate. A snapshot of the systems that is then safely stored in a binder until the next survey. Secure and assess by design principles were never taken into account. But threats do not wait for the annual survey and neither does drift.
Configurations change, temporary connections are made and forgotten or not logged, third parties experts come aboard without the relevant knowledge of ship’s systems, and a network that was compliant at inspection can look very different a month later. A certificate proves a point in time. It does not prove resilience over time.
Geopolitical developments, corporate espionage, attacks and the recognition of the regulatory bar set by the IMO Resolution MSC.428(98) requires cyber risk to be managed within a ship’s safety management system. The IACS unified requirements E26 and E27 bring cyber resilience into the design of vessels contracted for construction from July 2024. In the European Union, NIS2 draws many port and terminal operators into scope as essential entities. The common thread is a shift from “do you have a policy” to “can you demonstrate resilience”, continuously and on demand.
The future will stretch this further. Every development on the maritime roadmap increases the OT attack surface: autonomous shipping, greater connectivity from low-earth-orbit networks, new energy sources, electrification and new propulsion systems, increasingly automated ports where cranes, gates and terminal operating systems are tied together, remote and eventually autonomous operation, where the line between a control decision made on the bridge and one made ashore begins to blur. Each of these adds capability and each adds systems that must be watched without being disturbed.
So, what does good look like? Not bolting IT security onto OT and hoping. It means building visibility suited to the environment. Monitoring that observes rather than intrudes, watching the traffic to and from controllers, navigation and cargo systems without sitting in the control path; that copes with intermittent connectivity by holding data locally and reconciling when a link returns; and that does not depend on any one person being aboard. Above all, it means moving from fragmented, per-system checks to a single, continuous view across ships, ports and shore, so an anomaly is seen when it happens rather than discovered at the next audit and so evidence of resilience can be produced the moment a regulator, insurer or counterparty asks.
This form of monitoring can be achieved through the use of passive, non-intrusive security tools that do not disrupt safety-critical or continuous processes and provide managed detection and response capabilities. Much like a shore-based Security Operations Centre (SOC) used to protect the enterprise, analysts in a maritime SOC can collate this data, investigate incidents and provide compliance and third-party risk management, providing continuous monitoring and a single point of accountability. It’s a form of security that the industry has been requesting for years, as it extends testing results from the vessel and the terminal into a platform they can monitor continuously and evidence to a regulator.
None of this is simple. Maritime OT is diverse, distributed and unforgiving. The sector is right to be cautious about anything that touches a live system. But the direction is clear. The ships cannot stop, the ports cannot pause, and the threats will not slow down to match the survey cycle. The industry’s task for the next decade is to learn to watch what cannot stop: continuously, safely, and everywhere at once.
—-
About Remie Kalloe:
Remie Kalloe is Founder and CEO of Cyber.Dockside.ai BV, a maritime cyber resilience company, where his chief remit is assisting, designing and implementing bespoke solutions on behalf of clientele. He has extensive experience from working with global maritime and oil & gas industries and more than 15 years’ experience from within the telecommunications , software, datacenters, and information technology sectors.
Join our LinkedIn group Information Security Community!











