Commercial ships play a decisive role in the maritime environment, interacting with numerous entities: Crew, Shipbuilders, Makers, Port Authorities, Inspectors, Cargo Owners, Charterers, and Telecommunication Providers. Any degradation, interruption, or malfunction of ship information systems can have serious consequences on the smooth operation of the ship and its ecosystem, making security management one of the most critical issues. 

The rapid evolution of technology and the adoption of new IT & OT connected systems are transforming the global maritime landscape, offering opportunities for safer and greener navigation. The benefits of adopting OT systems are significant: 

  • OT systems can operate semi-autonomously or fully autonomously, supporting or fully automating complex processes, enhancing efficiency, and reducing the need for human intervention. They reduce the time—and therefore the cost—of daily operations on board.

  • Digital technology is seen as a key enabler of maritime decarbonization strategies (as required by regulations).

  • Connected technologies are now considered vital for reducing greenhouse gas emissions through route optimization and other automations.

  • Digital technologies not only enhance sustainability but also improve physical and crew safety by automating complex processes, benefiting the safety of ports and navigation overall.

Modern commercial ships have transformed into “floating digital offices,” hosting and interacting with complex, heterogeneous information systems and relying on multiple providers (e.g., navigation equipment providers, cloud providers, telecom providers, etc.). As a result, they are exposed to numerous cyberattacks and vulnerabilities, making cybersecurity a critical aspect of business continuity for maritime organizations. This new reality introduces heightened cyber risks to both OT and IT systems on board:

  • Expanded Attack Surface Due to Connectivity: OT systems were traditionally isolated, operating in closed environments with limited external access. However, the growing automation and need to integrate with IT systems and/or cloud solutions have expanded the attack surface, exposing them to new threats and vulnerabilities

  • Lack of Adequate Security Measures in Legacy Systems: Many OT systems were not designed with modern security standards. The lack of built-in encryption and advanced access controls makes them vulnerable to eavesdropping, unauthorized access, and data breaches.

  • Supply Chain Risks: The supply chain is one of the most vulnerable aspects of OT systems, as software, equipment, and service suppliers may—intentionally or unintentionally—introduce security gaps.

The need to strengthen cybersecurity in OT systems is urgent. This environment demands more detailed mapping of IT & OT systems and their interdependencies, along with more thorough threat and risk analysis and management—especially in cases stemming from the adoption and integration of OT systems. The adoption of modern security protocols, the Purdue Model for network isolation, continuous network monitoring, and supply chain risk management are all key pillars for safeguarding OT systems against today’s threats.

To improve security and reduce the impact of potential incidents, several guidelines and best practices should be followed, such as:

  • IMO: MSC-FAL.1-Circ.3 “Guidelines on Maritime Cyber Risk Management”
  • OCIMF: “Tanker Management Self-Assessment v3”
  • BIMCO: “Guidelines on Cyber Security Onboard Ships v4”

The recent European NIS 2 Directive (and Greek Law 5160/2024) also contributes to this direction. It aims to enhance the security of essential and important entities (including shipping companies), setting out a range of requirements involving the implementation of technical and organizational measures for the prevention, detection, response, and recovery from security incidents.

Compliance with cybersecurity regulations is one of the greatest challenges for businesses, as the regulatory landscape is constantly evolving and becoming increasingly demanding. Organizations must interpret and implement complex regulatory requirements, manage the rising cost of compliance, and operate in a multi-regulatory environment.

Maritime Sector - ICT PROTECT

STORM GRC can serve as a holistic compliance tool for the security demands of the “new reality” in the maritime sector, enabling shipping company security teams to:

  • Identify and map IT & OT systems onboard using prebuilt IT & OT Asset Models available in STORM GRC

  • Record all dependencies between vessel and ashore systems

  • Identify, assess, and categorize risk areas within the organization using preloaded IT & OT threats in STORM GRC

  • Recognize the impact of serious incidents ashore and/or vessel operations
  • Conduct IT & OT risk assessments, as required by maritime regulations

  • Perform Technical Vulnerability Assessments

  • Select appropriate and reliable security controls to ensure confidentiality, availability, and integrity of data and services
  • Conduct Third Party Risk Management

  • Conduct Gap Analysis (e.g., NIS 2, ISO 27001, NIST CSF) and monitor compliance level
  • Create and track necessary audit evidence required by standards (ISO 27001, ISO 22301) and regulations (NIS 2, GDPR, IMO, TMSA)
  • Develop and maintain all required security procedures and policies