Subscribe to our Mailing Lists (It's free!)
Friday, May 16, 2025
SAFETY4SEA
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    crew injury

    Lessons learned: Effective teamwork serves as a strong barrier

    Key trends in seafarer recruitment and retention

    Britannia: Preparing the crew for emergencies and claims

    pakistani seafarers

    India prohibits Pakistani seafarers to disembark from VLCC

    LR regulations

    LR outlines changes to mandatory statutory regulations

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    LNG terminal

    Greek LNG terminal upgrade aims for zero emission operations

    FuelEU

    Oceanscore: Shipping industry could profit €250M from FuelEU

    ABS ammonia

    ABS publishes safety insights for ammonia as a fuel

    Port of Gothenburg biomethane

    Biomethane gets successfully bunkered in Gothenburg port

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    ecdis

    MPA Singapore: Strengthening ECDIS and ENP competency

    DCSA eBL

    DCSA completes first interoperable eBL transaction

    remote pilotage

    Denmark launches world’s first test program for remote pilotage

    red sea houthis

    Windward: GPS jamming is a rising cyber threat in the Red Sea

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    PSC

    Black Sea MoU Annual Report: 4,587 inspections in 2024

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    Black Sea mou

    Black Sea MoU: 53 vessels detained during CIC period

    Panama Ship Registry

    Panama implements new screening process for vessels joining its registry

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    dry bulk market

    Baltic Exchange: Maritime market highlights 12-16 May

    cruise ship

    Watch: Where do cruise ships go when they die?

    female seafarer

    Program for female cadets promises to boost diversity

    10 trends influencing global commercial shipping

    Sea-Intelligence: Long transit times do not inherently cause problems

  • Columns
    supportive

    A supportive employer makes all the difference

    Human Element: Understanding the importance of seafarers’ soft skills

    Human Element: Understanding the importance of seafarers’ soft skills

    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
  • Home
  • Safety
    • All
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
    crew injury

    Lessons learned: Effective teamwork serves as a strong barrier

    Key trends in seafarer recruitment and retention

    Britannia: Preparing the crew for emergencies and claims

    pakistani seafarers

    India prohibits Pakistani seafarers to disembark from VLCC

    LR regulations

    LR outlines changes to mandatory statutory regulations

  • SEAFiT
    • All
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
    Book Review: Building leaders the MMMA way

    Book Review: How to avoid a climate disaster

    mental health

    MOL takes step to enhance the mental health of its crew

    Book Review: Building leaders the MMMA way

    Book Review: The Art Of War

    relax

    In the calm lies the cure: Exploring the parasympathetic nervous system

  • Green
    • All
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
    LNG terminal

    Greek LNG terminal upgrade aims for zero emission operations

    FuelEU

    Oceanscore: Shipping industry could profit €250M from FuelEU

    ABS ammonia

    ABS publishes safety insights for ammonia as a fuel

    Port of Gothenburg biomethane

    Biomethane gets successfully bunkered in Gothenburg port

  • Smart
    • All
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
    ecdis

    MPA Singapore: Strengthening ECDIS and ENP competency

    DCSA eBL

    DCSA completes first interoperable eBL transaction

    remote pilotage

    Denmark launches world’s first test program for remote pilotage

    red sea houthis

    Windward: GPS jamming is a rising cyber threat in the Red Sea

  • Risk
    • All
    • CIC
    • Detentions
    • Fines
    • PSC Focus
    • Vetting
    PSC

    Black Sea MoU Annual Report: 4,587 inspections in 2024

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    RISK4SEA unveils updated editions featuring worldwide data from the last 36M

    Black Sea mou

    Black Sea MoU: 53 vessels detained during CIC period

    Panama Ship Registry

    Panama implements new screening process for vessels joining its registry

  • Others
    • All
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
    dry bulk market

    Baltic Exchange: Maritime market highlights 12-16 May

    cruise ship

    Watch: Where do cruise ships go when they die?

    female seafarer

    Program for female cadets promises to boost diversity

    10 trends influencing global commercial shipping

    Sea-Intelligence: Long transit times do not inherently cause problems

  • Columns
    supportive

    A supportive employer makes all the difference

    Human Element: Understanding the importance of seafarers’ soft skills

    Human Element: Understanding the importance of seafarers’ soft skills

    Achilles

    Achilles: Improving supply chain transparency can have a bottom line benefit

    Trending Tags

    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • Events
  • Plus
No Result
View All Result
SAFETY4SEA

USCG: Cyber Trends and Insights in the Marine Environment 2023

by The Editorial Team
July 29, 2024
in Cyber Security
cisa cyber security

Credit: shutterstock

FacebookTwitterEmailLinkedin

USCG released its annual Cyber Trends and Insights in the Marine Environment (ME) report. This report aims to provide relevant information about best practices to secure critical systems.

Since December 2020, CGCYBER rapidly developed resources, capabilities, and partnerships to protect the ME from increasing cyber threats. 

The observations and findings in this report provide Coast Guard units and port partners with relevant information to identify and address cyber risks. Coast Guard Cyber Protection Teams (CPTs) and the Maritime Cyber Readiness Branch (MCRB) identified these findings through technical engagements conducted with ME partners throughout 2023.  

RelatedNews

Sea-Intelligence: Long transit times do not inherently cause problems

ABS publishes safety insights for ammonia as a fuel

As U.S. Coast Guard missions expand into the cyberspace domain and across the global maritime commons, CGCYBER remains strategically postured to protect maritime critical infrastructure from advanced cyber threat actors.

…Rear Admiral Jay Vann, Commander, Coast Guard Cyber Command said.

Four Key Takeaways from the report: 

  1. Many of the same findings/recommendations discussed in the CTIME 2021 and 2022 reports were observed again in 2023. 
  2. Emerging technologies create new attack paths into the ME. 
  3. Ransomware attacks and Advanced Persistent Threats (APTs) continue to target the ME.
  4. Timely information sharing is the most effective way to increase defenses against adversaries.  

What’s New in 2023?

In 2023, the ME saw an increase in industry reporting of Nation-State actors targeting U.S. Critical Infrastructure. In response, CGCYBER focused CPT resources towards finding these actors and focused on incorporating OT in CPT missions. 2023’s CTIME report reflects the change in priority with the added sections for Hunt & Incident Response RECAP and Securing OT. CGCYBER continued to build capacity to support the growing demand from partners in the ME seeking CPT assistance. The 2003 CPT reached Initial Operating Capability in August of 2023 and is expected to reach Full Operating Capability in 2024. Additionally, CGCYBER established a Reserve Component CPT, 1941 CPT, which will supplement the Active Duty CPTs and provide specialized expertise to support and augment operations.

In 2023, MCRB and local Coast Guard units conducted 46 investigations on reports of cyber incidents. This included several incidents which significantly affected large-scale international organizations. Though the overall number of reported incidents has decreased since 2022, MCRB believes many incidents go undetected or unreported by organizations who are fearful of the public’s perception as a result of a cyber incident. NationState actors and opportunistic cybercriminals consistently target the ME, given more than 90% of U.S. imports and exports flow through U.S. maritime ports annually.

MCRB categorizes reported cyber incidents into three categories.

  1. Ransomware: A type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access.
  2. Phishing/Spoofing: Phishing is a technique for attempting to acquire sensitive data, such as bank account numbers, or access to a larger computerized system through a fraudulent solicitation in email or on a web site. The perpetrator typically masquerades as a legitimate business or reputable person. Spoofing is a technique for faking the sending address of a transmission to gain illegal/unauthorized entry into a secure system.
  3. Other Cyber Incidents: Any incident that does not fall into the above categories such as: Business Email Compromise, Structured Query Language (SQL) Injection, etc.
USCG: Cyber Trends and Insights in the Marine Environment 2023
Credit: USCG

Findings

  • Phishing for Information: Phishing for Information is related to the Phishing Technique (T1566); however, instead of attempting to use the email for malicious code execution, Phishing for Information is used to gain useful information, such as a username and password, from the phished user. During assessments, CPTs sent emails masquerading as various agents from the partner’s organization (generally from the IT Department) with a link that would send users to a simulated malicious login portal created by the CPTs to capture user credentials. 10.8% of all phishing emails sent during threat emulation resulted in a click by a user. Additionally, of those who clicked the link, 6.7% of users provided credentials when requested. 
  • Valid Accounts: The most common initial access technique used during Assess missions was Valid Accounts. On CPT missions, Valid Accounts were gathered from publicly available sources, Gather Victim Identity Information: Credentials (T1589.001), or from using related techniques such as Phishing for Information, Adversary-in-theMiddle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001), or Steal or Forge Kerberos Tickets: Kerberoasting (T1558).
  • Adversary-in-the-Middle: CPTs found that organizations remain vulnerable to LLMNR/NBT-NS Poisoning and SMB Relay attacks. These attacks leverage legacy protocols used for host identification to harvest credentials from within a network. LLMNR/ NBT-NS Poisoning consists of an attacker inside the network responding to LLMNR (UDP 5355)/NBT-NS (UDP 137) and directing traffic to an adversary-controlled system. Then, once a legitimate user attempts to access the portion of the network that is redirected to the adversary-controlled system, the adversary can use a myriad of techniques to directly obtain hashed or even sometimes plaintext credentials.
  • Brute Force: Password Cracking: The National Institute of Standards and Technology (NIST) Special Publication 800-63 Digital Identity Guidelines20 recommends password policies include password length and password complexity requirements. Additionally, the NIST 800-63 provides suggestions for enforcement and consequences when not followed. Across the CY23 CPT missions, CPTs had little to no difficultly cracking passwords with a length of 12 characters or less.
  • Patch Management: Vendors regularly release patches and updates to address existing and emerging security threats. These patches address various levels of risk, which are evaluated using the Common Vulnerability Scoring System (CVSS). The CVSS assigns vulnerabilities a score based on their severity. Failure to apply the latest patches can leave the system open to attack from publicly available exploits. The risk presented by missing patches and updates can vary; however, the most critical of vulnerabilities are those that are proven to be exploitable. These vulnerabilities are listed in CISA’s KEV Catalog.

EXPLORE MORE AT USCG’S CYBER TRENDS REPORT

USCG: Cyber Trends and Insights in the Marine Environment 2023USCG: Cyber Trends and Insights in the Marine Environment 2023
USCG: Cyber Trends and Insights in the Marine Environment 2023USCG: Cyber Trends and Insights in the Marine Environment 2023
Tags: cyber securitydigitalizationreportstrendsUSCG
Previous Post

Lessons learned: Heavy cargo items deserve extra attention

Next Post

Gender Diversity in Maritime: Positive strides made but challenges still exist

Related News

women in maritime
Diversity in shipping

IMO WISTA Survey: Falling numbers for women in maritime

May 16, 2025
DCSA eBL
Smart

DCSA completes first interoperable eBL transaction

May 16, 2025
LR regulations
Regulation

LR outlines changes to mandatory statutory regulations

May 16, 2025
PSC
PSC Focus

Black Sea MoU Annual Report: 4,587 inspections in 2024

May 16, 2025
Panamanian seafarers
Seafarers

Panama sees 12% seafarer employment increase in early 2025

May 15, 2025
bulk carrier
Shipping

BIMCO: Dry bulk carrier recycling falls by 24%

May 15, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Explore more

No Result
View All Result
MARITIME EVENTS

Explore

  • Safety
  • SEAFiT
  • Green
  • Smart
  • Risk
  • Others
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

Useful Links

  • About
  • Disclaimer
  • Editorial Policies
  • Advertising
  • Content Marketing
  • Contact

© 2025 SAFETY4SEA

No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA

Manage your privacy
We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}
No Result
View All Result
  • Safety
    • Accidents
    • Alerts
    • Loss Prevention
    • Maritime Health
    • Regulation
    • Safety
    • Seafarers
    • Security
  • SEAFiT
    • Intellectual
    • Mental
    • Physical
    • Social
    • Spiritual
  • Green
    • Arctic
    • Ballast
    • Emissions
    • Fuels
    • Green Shipping
    • Pollution
    • Ship Recycling
    • Technology
  • Smart
    • Connectivity
    • Cyber Security
    • E-navigation
    • Energy Efficiency
    • Maritime Software
    • Smart
  • Risk
    • CIC
    • Detentions
    • Fines
    • PSC Case Studies
    • PSC Focus
    • Vetting
  • Others
    • Diversity in shipping
    • Maritime Knowledge
    • Offshore
    • Ports
    • Shipping
    • Sustainability
    • Videos
  • Columns
    • Book Review
    • Career Paths
    • Human Performance
    • Industry Voices
    • Interviews
    • Maripedia
    • Maritime History
    • Opinions
    • Regulatory Update
    • Resilience
    • Seafarers Stories
    • SeaSense
    • Tip of the day
    • Training & Development
    • Wellness Corner
    • Wellness Tips
  • SAFETY4SEA Events
  • SAFETY4SEA Plus Subscription

© 2025 SAFETY4SEA