{"id":843,"date":"2021-03-19T13:02:50","date_gmt":"2021-03-19T07:32:50","guid":{"rendered":"https:\/\/www.samdesindia.in\/blog\/?p=843"},"modified":"2021-03-19T13:02:53","modified_gmt":"2021-03-19T07:32:53","slug":"maritime-cyber-security-threats-and-consequences","status":"publish","type":"post","link":"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/","title":{"rendered":"MARITIME CYBER SECURITY THREATS AND CONSEQUENCES"},"content":{"rendered":"\n<p>by Captain Pankaj Kapoor, Master Mariner<\/p>\n\n\n\n<p>Many feel that majority of ocean-going vessels due their use of Industrial Control Systems (ICS) are unlikely targets to cyber-attacks. Barely do they realise that with the increased use of internet and satellites in Maritime Transport, shipping is a ripe playground for hackers.<\/p>\n\n\n\n<p>IMO comments that \u201cMaritime cyber risk refers to a measure of the extent to which a technology asset could be threatened by a potential circumstance or event, which may result in shipping-related operational, safety or security failures as a consequence of information or systems being corrupted, lost or compromised.<\/p>\n\n\n\n<p>Cyber risk management means the process of identifying, analysing, assessing and communicating a cyber-related risk and accepting, avoiding, transferring or mitigating it to an acceptable level, considering costs and benefits of actions taken to stakeholders<\/p>\n\n\n\n<p>The overall goal is to support safe and secure shipping, which is operationally resilient to cyber risks.\u201d<\/p>\n\n\n\n<p><strong>International Shipping is one of the oldest and recognised as world\u2019s FIRST TRULY GLOBAL industry. It is also the lifeblood of the global economy, accounting for the carriage of nearly 90% of world trade.<\/strong>&nbsp;<\/p>\n\n\n\n<p>The Maritime Transportation System (MTS) \u2013 is susceptible to cyber risks as any other industry. What the general public does not realise is that any disruption in shipping activities directly affects the global supply chain, as shipping contributes to a major chunk of international movement of goods. IMO has gone to extent of commenting that <em>\u201cany disruption in world shipping would result in half the world dying of hunger and the other half of cold\u201d.<\/em><\/p>\n\n\n\n<p>Public in general is unaware of the complexity of the MTS, and the impact that MTS disruptions pose to national security and economic stability. For most, ships are beautiful hotels, traveling to exotic destinations and full of excitement. No one ever imagines the phenomenal role they play in our daily lives. But, on sane level, when considering potential threats to the global transportation system, maritime risks are sadly often invisible till a marine disaster awakens the public from their slumber. Recent examples of that are Wakashio, New Diamond and Exon Valdez.<\/p>\n\n\n\n<p>UNCTAD in its recent report mentioned that \u201cGlobal maritime trade will plunge by 4.1% in 2020 due to the unprecedented disruption caused by COVID-19, UNCTAD estimates in its&nbsp;<a href=\"https:\/\/unctad.org\/webflyer\/review-maritime-transport-2020\">Review of Maritime Transport 2020<\/a>, released on 12 November.\u201d Current pandemic has compelled the industry to conduct even more operations digitally thus exposing it to greater cyber threats.<\/p>\n\n\n\n<p>Above is scary revelation of what impact can disruptions in shipping cause to global economy and one of the unseen threats which can cause such severe disruptions is cyber-attack. Such a probable incident should not be treated with kids gloves.<\/p>\n\n\n\n<p>In a BIMCO sponsored Maritime Cyber Security survey in 2020, some respondents went so far as to describe their company policy to OT cyber risk as \u201ccareless.\u201d<\/p>\n\n\n\n<p>Impact of cyber-attack on the World\u2019s Shipping Giant Maersk is not forgotten from human memory, where A.P. M\u00f8ller-Maersk, fell prey to Not Petya on June 27, 2017. Attackers spread the&nbsp;<a href=\"https:\/\/portswigger.net\/daily-swig\/malware\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a>&nbsp;after seizing control of the software update mechanism of M.E. Doc, a standard accountancy package for firms doing business in Ukraine, as part of a carefully planned operation.<\/p>\n\n\n\n<p>The impact was immediate and the recovery was slow. Company\u2019s network was crippled within few minutes of the attack. Severe damage was done within an hour of attack. It took nine days and close to 300 million dollars to restore the systems. Maersk was appreciated worldwide for sharing this incident with public and not giving in to the ransom demands of the hackers.<\/p>\n\n\n\n<p><strong>As recent as April 2020 Swiss-based global shipping giant Mediterranean Shipping Company (MSC) confirmed that an outage of its websites was caused by a malware attack affecting its headquarters in Geneva.<\/strong><strong><\/strong><\/p>\n\n\n\n<p>MSC informed its customers that its website,&nbsp;<em>msc.com<\/em>, and its myMSC customer and vendor portal had become unavailable due to a network outage at one of the company\u2019s data centres. Company however did declare that it did not entirely rule out the possibility that the incident was caused by a piece of malware. Once the incident was resolved, company declared that \u201cAfter a thorough investigation, we confirm that it was confined to a limited number of physical computer systems in Geneva only and we have determined that it was a malware attack based on an engineered targeted vulnerability. We have shared as per industry standards the malware with our technology partners so that mitigations could be made available not only to us\u201d.&nbsp;<\/p>\n\n\n\n<p>Such incidents are not isolated ones as even IMO experienced a shutdown of much of the it\u2019s IT systems for nearly 48-hour period.<\/p>\n\n\n\n<p>\u201cThe interruption of web-based services was caused by a sophisticated cyber-attack against the organization\u2019s IT systems that overcame robust security measures in place,\u201d the IMO said in a statement regarding this first cyber-attack.<\/p>\n\n\n\n<p>Another incident was when the French container line CMA CGM a high-profile name in shipping was hit by hackers. It took the Marseille-based company nearly two weeks to get out of the ransomware attack.<\/p>\n\n\n\n<p><em>In yet another incident an oil tanker arrived in Singapore in June 2020 and reported her position to VTIS East. But, the VTIS failed to locate the ship on AIS. They served a notice to Master not to sail without the AIS repair. Owners immediately arranged a technician who boarded the vessel at anchorage. He checked and confirmed with the VTIS that all are in order. However, the AIS failure re-occurred after two days during departure and company had to take flag state dispensation.&nbsp;<\/em><em><\/em><\/p>\n\n\n\n<p><em>A new AIS was installed on arrival at next call Singapore. The technician verified with VTIS, and AIS was found satisfactory. However again after few days, the berthing Pilot reported the same issue and the vessel\u2019s sailing was postponed to facilitate service engineer\u2019s boarding at anchorage.&nbsp;<\/em><em><\/em><\/p>\n\n\n\n<p><em>Company again arranged service engineers to check the AIS. This time the attending technicians found that three other vessels were using vessel\u2019s MMSI number. This caused interference and intermittent failure of AIS transmission from the vessel.&nbsp;&nbsp;<\/em><em><\/em><\/p>\n\n\n\n<p><em>Owners informed the MPA Singapore, once they identified the actual problem. An investigation in the matter was launched and it was discovered that vessel\u2019s <\/em><em><\/em><\/p>\n\n\n\n<p><em>identity was being used by other vessels involved in possible illegal bunkering or sanction trade. This incident highlights, how easy it is to hack into ships systems.<\/em><em><\/em><\/p>\n\n\n\n<p>Even GPS signal is a relatively weak signal and can be easily jammed, spoofed or resent with delay There have been incidents where Masters have reported incorrect GPS signals showing vessel\u2019s position on land! AIS information is transferred using VHF radio with no encryption allowing valuable information to be easily obtained and it can be also altered or jammed.<\/p>\n\n\n\n<p>&nbsp;Cyber threats though invisible are present and need to be tackled seriously Knee-jerk reactions would not be sufficient to overcome them. IMO\u2019s Maritime Safety Committee, at its 98th session in June 2017,&nbsp;also adopted&nbsp;<a href=\"https:\/\/wwwcdn.imo.org\/localresources\/en\/OurWork\/Security\/Documents\/Resolution%20MSC.428(98).pdf\">Resolution MSC.428(98)<\/a>&nbsp;&#8211; Maritime Cyber Risk Management&nbsp;in Safety Management Systems. The resolution encourages administrations to ensure that cyber risks are appropriately addressed in existing safety management systems (as defined in the ISM Code) no later than the first annual verification of the company&#8217;s Document of Compliance after 1 January 2021. Taking cue from IMO\u2019s recommendations, most of the companies have now made it an integral part of their ISM manuals.<\/p>\n\n\n\n<p>What exposes a vessel to probable cyber-attacks is the integration of Industrial Control Systems (ICS) to internet and satellite systems. So, what is ICS? Many parameters on a ship need to be controlled or monitored for example temperatures, pressure, level, viscosity, flow control, position of vessel, speed, torque control, voltage, current, machinery status (on\/ off), and&nbsp;equipment status (open\/ closed). With more advanced systems, ships are becoming exceedingly technology dependent with reduced manpower thus introducing increased automation. These advances have resulted in more and more vessels having Unmanned Machinery Spaces (UMS) class where ships engines can be controlled with automation without manual interference.<\/p>\n\n\n\n<p>A number of operations on a vessel are now fully automated and integrated like propulsion plant operation, power management operation of the auxiliary&nbsp;engines, auxiliary machinery operation, cargo loading\/unloading operation, navigation etc.<\/p>\n\n\n\n<p>Earlier ICS were stand-alone systems, with sometimes propriety technologies. Whereas presently ICS use Commercial Off the shelf (COTS) technologies which are then connected to other systems.&nbsp; Most of these COTS systems depend on network presence and use OS such as Windows, UNIX, Linnux thus making them vulnerable to cyber-attacks. Additionally, devices like Bring Your Own Devices (BYOD) for navigation, use of third-party USB\u2019s, introduce vulnerabilities if not properly configured.<\/p>\n\n\n\n<p>Present day ICS are connected to various company operated systems which rely on Internet accessibility for instance vessels email system or automatic updates of ECDIS received through emails. These features give asset owners and operators immediate benefits by extending connectivity and interoperability with other IT infrastructures. But at the same time, they lure hackers to attack the vessels systems with relative ease.<\/p>\n\n\n\n<p>Ethical Hackers have successfully proved that, an attack can be initiated to alter the ships position thus giving false information to the duty officer and compelling him to take incorrect actions. An Israeli cyber security company after conducting an Ethical Hacking exercise managed to hack into vessel\u2019s navigation system by just sending a simple mail. They commented that \u201cWe designed the attack to alter the vessel\u2019s position at a critical point during an intended voyage \u2013 during night-time passage through a narrow canal. During the attack, the system&#8217;s display looked normal, but it was deceiving the Officer of the Watch.\u201d<\/p>\n\n\n\n<p>\u201cThe actual situation was completely different to the one on screen. If the vessel had been operational, it would have almost certainly run aground.\u201d<\/p>\n\n\n\n<p>\u201cThe vessel\u2019s crucial parameters \u2013 position, heading, depth and speed \u2013 were manipulated in a way that the navigation picture made sense and did not arouse suspicion.\u201d<\/p>\n\n\n\n<p>\u201cThis type of attack can easily penetrate the antivirus and firewalls typically used in the maritime sector.\u201d<\/p>\n\n\n\n<p>IMO and various other organisations have warned that&nbsp;maritime cyber risk is ever present and with increased automation, this may result in shipping-related operational, safety, or security failures as a consequence of information or systems being corrupted, lost or compromised.<\/p>\n\n\n\n<p>Even those ships which still leverage legacy technologies using a blend of Information technology (IT) and Operational Technology (OT) are exposed to cyber risks due to use of these systems both by internal ships crew and third-party vendors and can be compromised by hackers or even insider threats.<\/p>\n\n\n\n<p>In conclusion, with more and more automation coming into the ship operations, it is advisable that the ships staff are adequately trained and made aware of the ever-present cyber threat. With growing use of different systems having inbuilt software, cyber security should now become a prominent feature in the training of ships staff. Cyber security training is essential not just for data protection but also reliable and smooth operations. All that is required for a disaster, is for one person, in a moment of weakness, becomes willing to compromise by opening an unwanted attachment.\u00a0 97% of attacks actually consist in tricking a user by using social engineering techniques. Phishing and social engineering, unintentional downloads of malware, etc., are common issues.<\/p>\n\n\n\n<p><span style=\"text-decoration: underline;\">Author Bio:<\/span> Capt. Pankaj Kapoor, Master Mriner, B.Sc(Naut Science), PG Maritime Law, LL.B, AFNI, is a Maritime lawyer and a Sr. Partner in India Law Offices LLP (amongst the top 100 law firms of India) heading the firms Maritime Law division. He is an ex member NITI Aayog committee for drafting &#8220;National Maritime Policy&#8221;. Besides Maritime Law practice he is also adjunct Professor at various National law colleges and universities.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Captain Pankaj Kapoor, Master Mariner Many feel that majority of ocean-going vessels due their use of Industrial Control Systems [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[46],"tags":[356,353,358,354,357,355,113],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v14.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>MARITIME CYBER SECURITY THREATS AND CONSEQUENCES | SAMDES INDIA&#039;S BLOG<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MARITIME CYBER SECURITY THREATS AND CONSEQUENCES | SAMDES INDIA&#039;S BLOG\" \/>\n<meta property=\"og:description\" content=\"by Captain Pankaj Kapoor, Master Mariner Many feel that majority of ocean-going vessels due their use of Industrial Control Systems [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\" \/>\n<meta property=\"og:site_name\" content=\"SAMDES INDIA&#039;S BLOG\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-19T07:32:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-19T07:32:53+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#organization\",\"name\":\"SAMDeS India\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#logo\",\"inLanguage\":\"en\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/wp-content\/uploads\/2020\/04\/samdes_logo02.png\",\"width\":188,\"height\":188,\"caption\":\"SAMDeS India\"},\"image\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#website\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/\",\"name\":\"SAMDES INDIA'S BLOG\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.samdesindia.in\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#webpage\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\",\"name\":\"MARITIME CYBER SECURITY THREATS AND CONSEQUENCES | SAMDES INDIA'S BLOG\",\"isPartOf\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#website\"},\"datePublished\":\"2021-03-19T07:32:50+00:00\",\"dateModified\":\"2021-03-19T07:32:53+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/\",\"name\":\"MARITIME CYBER SECURITY THREATS AND CONSEQUENCES\"}}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#\/schema\/person\/333f12b5ab292947204bb28e64249979\"},\"headline\":\"MARITIME CYBER SECURITY THREATS AND CONSEQUENCES\",\"datePublished\":\"2021-03-19T07:32:50+00:00\",\"dateModified\":\"2021-03-19T07:32:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#webpage\"},\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#organization\"},\"keywords\":\"AIS,cyber security,IMO,Maritime Law,MMSI,ports,Shipping\",\"articleSection\":\"Articles\",\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.samdesindia.in\/blog\/maritime-cyber-security-threats-and-consequences\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#\/schema\/person\/333f12b5ab292947204bb28e64249979\",\"name\":\"SAMDeS India\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.samdesindia.in\/blog\/#personlogo\",\"inLanguage\":\"en\",\"url\":\"https:\/\/www.samdesindia.in\/blog\/wp-content\/wphb-cache\/gravatar\/cc1\/cc165fea0b770c2248db9a12b569cc97x96.jpg\",\"caption\":\"SAMDeS India\"},\"description\":\"SAMDeS India View more\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/posts\/843"}],"collection":[{"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/comments?post=843"}],"version-history":[{"count":0,"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/posts\/843\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/media?parent=843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/categories?post=843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.samdesindia.in\/blog\/wp-json\/wp\/v2\/tags?post=843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}