Subscribe to our Mailing Lists (It's free!)
Saturday, March 25, 2023
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    safety alert

    USCG: Adherence to instructions for inflatable boats is crucial

    MPA Singapore to step down the remaining COVID-19 measures

    MPA Singapore to step down the remaining COVID-19 measures

    maritime law

    MNWB: UK’s new law will boost seafarer welfare

    Ship dislodged in Edinburgh dockyard injuring 35 people

    Ship dislodged in Edinburgh dockyard injuring 35 people

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

    Life coaching tips: How to maintain a good work-life balance

    Life coaching tips: How to maintain a good work-life balance

    Wabi sabi

    Wabi Sabi: Imperfection makes perfection at work

    sexual abuse

    Sexual abuse at sea: Where we stand

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    Anglo-French alliance signs MoU for green corridor on Dover Strait

    Anglo-French alliance signs MoU for green corridor on Dover Strait

    Maersk signs MoU on methanol bunkering with Shanghai Port

    Maersk signs MoU on methanol bunkering with Shanghai Port

    CapLab decarbonization center established at Molo Giano

    CapLab decarbonization center established at Molo Giano

    EIA LNG

    EIA: Europe was the main destination for U.S. LNG exports in 2022

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    Ports of Stockholm

    Ports of Stockholm to focus on the safety aspects of autonomous ships

    NAPA: Simulation software aids in predicting CII

    NAPA: Simulation software aids in predicting CII

    Canada, UK join forces for R&D digital project on decarbonization

    Canada, UK join forces for R&D digital project on decarbonization

    technology

    How a joined-up approach to technology drives people performance

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
    australia sea mines

    AMSA imposes 90-day ban on Dutch vessel

    Singapore

    Eco Spark arrested in Singapore

    Liberia

    Liberia: key guidance for machinery space deficiencies

    orange county oil spill fines

    Taiwan’s Wan Hai Lines to pay $950,000 in civil penalties

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
    MPA Singapore to step down the remaining COVID-19 measures

    MPA Singapore to step down the remaining COVID-19 measures

    Ports of Stockholm

    Ports of Stockholm to focus on the safety aspects of autonomous ships

    SAFETY4SEA, Europort once again join forces to present a set of 15 prestigious awards

    SAFETY4SEA, Europort once again join forces to present a set of 15 prestigious awards

    IMO wishes for further extension of the Black Sea Grain Initiative

    IMO wishes for further extension of the Black Sea Grain Initiative

  • Columns
    WSC: Minimising accidents is at the top of liner shipping’s agenda

    WSC: Minimising accidents is at the top of liner shipping’s agenda

    technology

    How a joined-up approach to technology drives people performance

    SCMA: Maritime arbitration is expected to rise in prominence

    SCMA: Maritime arbitration is expected to rise in prominence

    Trending Tags

    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Resilience
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    safety alert

    USCG: Adherence to instructions for inflatable boats is crucial

    MPA Singapore to step down the remaining COVID-19 measures

    MPA Singapore to step down the remaining COVID-19 measures

    maritime law

    MNWB: UK’s new law will boost seafarer welfare

    Ship dislodged in Edinburgh dockyard injuring 35 people

    Ship dislodged in Edinburgh dockyard injuring 35 people

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Why sleep and mental health go hand-in-hand

    Why sleep and mental health go hand-in-hand

    Life coaching tips: How to maintain a good work-life balance

    Life coaching tips: How to maintain a good work-life balance

    Wabi sabi

    Wabi Sabi: Imperfection makes perfection at work

    sexual abuse

    Sexual abuse at sea: Where we stand

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    Anglo-French alliance signs MoU for green corridor on Dover Strait

    Anglo-French alliance signs MoU for green corridor on Dover Strait

    Maersk signs MoU on methanol bunkering with Shanghai Port

    Maersk signs MoU on methanol bunkering with Shanghai Port

    CapLab decarbonization center established at Molo Giano

    CapLab decarbonization center established at Molo Giano

    EIA LNG

    EIA: Europe was the main destination for U.S. LNG exports in 2022

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    Ports of Stockholm

    Ports of Stockholm to focus on the safety aspects of autonomous ships

    NAPA: Simulation software aids in predicting CII

    NAPA: Simulation software aids in predicting CII

    Canada, UK join forces for R&D digital project on decarbonization

    Canada, UK join forces for R&D digital project on decarbonization

    technology

    How a joined-up approach to technology drives people performance

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
    australia sea mines

    AMSA imposes 90-day ban on Dutch vessel

    Singapore

    Eco Spark arrested in Singapore

    Liberia

    Liberia: key guidance for machinery space deficiencies

    orange county oil spill fines

    Taiwan’s Wan Hai Lines to pay $950,000 in civil penalties

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
    MPA Singapore to step down the remaining COVID-19 measures

    MPA Singapore to step down the remaining COVID-19 measures

    Ports of Stockholm

    Ports of Stockholm to focus on the safety aspects of autonomous ships

    SAFETY4SEA, Europort once again join forces to present a set of 15 prestigious awards

    SAFETY4SEA, Europort once again join forces to present a set of 15 prestigious awards

    IMO wishes for further extension of the Black Sea Grain Initiative

    IMO wishes for further extension of the Black Sea Grain Initiative

  • Columns
    WSC: Minimising accidents is at the top of liner shipping’s agenda

    WSC: Minimising accidents is at the top of liner shipping’s agenda

    technology

    How a joined-up approach to technology drives people performance

    SCMA: Maritime arbitration is expected to rise in prominence

    SCMA: Maritime arbitration is expected to rise in prominence

    Trending Tags

    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Resilience
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

Common software and communication vulnerabilities on ships

by The Editorial Team
January 11, 2023
in Cyber Security
software vulnerabilities on ships

Credits: Shutterstock

FacebookTwitterEmailLinkedin

GTMaritime published a guide to highlight some of the problems that can occur using equipment and operating systems likely to be found on ships in operation.

As well as deliberate cyberattacks, the guide considers how even supposedly safe and routine matters such as a system update can create difficulties on board a vessel.

The question of automatic updating and its hazards is considered and also included in the guide is a section on the human element as this is the area where most failings can occur and where deliberate attackers most frequently target

System updates

The frequency of updates reflects the growing cyber threat that users face and should be recognised as such. Although intended to protect the machine from attack and to improve performance, the updates can sometimes contain bugs and can cause problems with applications that previously ran faultlessly. Usually this is due to a driver or application compatibility issue. Another issue is that downloading and installing the updates will cause the device to become unavailable for a period – often lengthy.

RelatedNews

Anglo-French alliance signs MoU for green corridor on Dover Strait

SAFETY4SEA, Europort once again join forces to present a set of 15 prestigious awards

This last point can be annoying as it impacts workflow, but on a ship, it could even make essential systems suddenly unavailable. It is possible to turn off this automatic updating feature, but that in itself could mean that the system is no longer protected by the security updates introducing other vulnerabilities.

To avoid system availability issues but at the same time ensuring security updates are received, it may be an idea to disable the automatic update feature of the operating system and perform a manual update.

This manual update can be done when the ship is less likely to be compromised such as immediately after arrival in port. After performing this update, a check should be carried out on essential system availability as comprehensively as possible. Any issues should be reported to head office and to the equipment system maker so that the information can be disseminated to other ships in the fleet.

Chinks in the armour

The vast extent of today’s shipping software market can be judged by the number of organisations taking stands at the major exhibitions where for several years now whole halls have been devoted to digital technologies.

In addition to these commercial offerings there are many more apps developed by seafarers or maritime specialists that can be downloaded for use on apple and android devices that crew may use on board.

Just as with the main operating systems, these apps are likely to update on a regular basis and this can be done either automatically or manually once notification of an update has been transmitted.

This updating can be a source of vulnerability to cyber attacks and should be carefully monitored. The updating procedure can also create problems if interrupted – an ever present threat for ships where the internet connection may be fragile under some circumstances – and cause the application to cease operating or to malfunction.

When it comes to vulnerabilities of shipboard networks, one of the factors often overlooked are the various devices attached to or integrated within the network. These can be mice and touchpads, keyboards, monitors, speakers, microphones,

Human element

According to the Verizon 2022 Data Breach Investigations Report, 82% of data breaches involve a human element, like a user clicking a link in a phishing email. That is pretty damning for the humans involved, but it ignores the fact that of the many millions of cyberattacks made daily, the majority are unsuccessful due to human alertness.

Familiarisation should ensure that a new crew member is fully acquainted with the ship, the equipment that they will be required to use as part of their duties, and the ISM procedures that affect them. While the first two may be addressed albeit to a sometimes limited extent, familiarisation with procedures is often little more than a box ticking exercise as the crew member would have almost no chance to absorb the whole of the ISM system procedures in the short time allowed.

Another factor is that familiarity with equipment comes quite naturally to crew who would likely have encountered the same or very similar kit on numerous vessels. Familiarity with procedures is less easy to gain as the processes can be very different from ship to ship. It would be of great benefit to protect from cyberattacks against ships if operators worked together to adopt a common industry wide standard for procedures.

Crews and shore personnel need training in practising good digital hygiene and guidance on what to be alert for. This training can be a combination of discussion meetings or workshops on board at regular intervals and also some form of testing whereby harmless spoof messages are sent from shore that encourage recipients to click through on a link in the same way that a phishing email does. Crew who are repeatedly caught out by these messages can be identified and given further training and guidance.

EXPLORE MORE at gtmaritime’s cyber security guide

Tags: cyber securitycyber threatdigitalizationmaritime softwarereports

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

safety alert

USCG: Adherence to instructions for inflatable boats is crucial

March 24, 2023
MPA Singapore to step down the remaining COVID-19 measures

MPA Singapore to step down the remaining COVID-19 measures

March 24, 2023

SEAFiT Poll

What is the biggest obstacle for the social life onboard?

Stay tuned for the results!

MARITIME EVENTS

Explore

  • Safety
  • Green
  • Smart
  • Risk
  • Others
  • Events
  • Plus

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Contact

RISK4SEA Facts

Did you know that Handymax had an increase in detention rate in Paris MoU? 39% increase in detention rate within 2020 vs. Last3Y.

Learn more risk4sea.com

© 2021 SAFETY4SEA

No Result
View All Result
  • Safety
    • Alerts
    • Accidents
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Reports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Opinions
    • Career Paths
    • Industry Voices
    • Maripedia
    • Maritime History
    • Seafarers Stories
    • SeaSense
  • Events
  • Plus

© 2021 SAFETY4SEA

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Disclaimer.