Atlantic Council examines maritime cybersecurity gaps
A policy report analyzes systemic cyber risks across the Maritime Transportation System, highlighting vulnerabilities in ships, ports, and cargo systems stemming from poor cyber hygiene, legacy OT, and social engineering.
The Atlantic Council has published a comprehensive research report examining cybersecurity vulnerabilities across the Maritime Transportation System (MTS), framing it as a complex 'system of systems' comprising ships, ports, and cargo infrastructure. The report identifies two primary categories of systemic risk: human factors (social engineering, inadequate cyber hygiene, unauthorized access, and overcomplicated technology) and systems vulnerabilities (attacks on OT/SCADA systems, IT infrastructure, positioning/navigation systems, and ransomware). The analysis notes that while the maritime industry demonstrated agility in responding to physical piracy threats in the late 2000s, it has been slow to proactively address emerging cyber threats despite the sector's growing digitalization and interconnectedness.
The report catalogs multiple real-world incidents illustrating these vulnerabilities, including the 2017 NotPetya attack on Maersk, COSCO's 2018 ransomware disruption, social engineering campaigns targeting vessel crews, widespread use of default passwords on satellite communications systems, and GPS spoofing operations. It emphasizes that ransomware has emerged as a particularly acute threat, with attacks on maritime targets increasing 900 percent over three years. The Atlantic Council's analysis concludes that securing the MTS requires addressing vulnerabilities across entire life cycles of ships, ports, and cargo systems, and highlights the need for improved cybersecurity training, education, and certification for maritime operators.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/cooperation-on-maritime-cybersecurity-a-system-of-systems
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free