Shipping is one of society’s vital functions and the backbone of the global economy. At any given time, approximately 50,000–60,000 vessels are at sea or in port, and their operations increasingly rely on digital and networked systems. An attacker does not need to target a ship directly: a cyberattack can spread from a shipping company’s onshore IT systems to the ship’s critical OT systems.
The central idea of the White Paper is to view shipping as a system of systems. Shipping is not a single, unified system but a collection of independent parts, such as ships, ports, logistics and shipping companies, which are interconnected and partly interdependent. This perspective explains why a cyberattack can spread from one part to another. It also shows how to defend against such attacks: because the parts depend on each other, protection cannot be built piecemeal. Instead, the system must be examined as a whole, with particular attention to the interfaces between its parts.
The publication covers topics such as:
🔹 ship systems and the ship-to-shore interface: bridge, propulsion and OT systems
🔹 port systems, port services and stakeholders
🔹 vulnerabilities, as well as threat actors’ motives and key attack methods
🔹 cyberattacks that have targeted ports, shipping companies and vessels, from NotPetya to GNSS jamming
🔹 frameworks and regulation: IMO, BIMCO, IACS UR E26/E27, NIS2 and the USCG
🔹 cyber resilience management and future challenges, such as artificial intelligence, autonomous vessels and interference with satellite navigation
GNSS jamming and spoofing are no longer isolated incidents. They are becoming a permanent feature of key shipping routes, and the number of incidents rose by around 50% in early 2026. Spoofing is particularly dangerous because systems continue to operate on false information, and conventional information security measures may detect nothing.
The publication takes a holistic approach to managing cyber security and resilience, encompassing cyber threat management, cyber risk management and cyber resilience management. It is intended for maritime and port management, experts, authorities and anyone interested in the topic.
We hope this publication will improve maritime operators’ preparedness for cyber threats and, in doing so, strengthen the cyber resilience of the society as a whole.
We wish you an enjoyable and thought-provoking read!