testata inforMARE
22 October 2024 - Year XXVIII
Independent journal on economy and transport policy
10:30 GMT+2




Being a shipping IT professional can be frustrating. You recognise the need to invest in further cybersecurity, but your management team still treat it as a "compliance problem". But perhaps this is a result of the way cybersecurity has been presented to leadership. The dialogue needs to change. IMO 2021 could offer a unique opportunity to reposition cybersecurity as an important enabler of the wider business objectives.

At our recent virtual conference - CyberSecure at Sea - we asked ~120 shipping IT professionals what was holding them back from rolling out cyber security controls. ~50% pointed toward the struggle with providing their management teams the confidence that they are spending wisely on cyber security or that investing in additional resources to manage cyber risk is required at all. It is clear there is a misalignment between what IT professionals know is needed and what leadership believes is the risk.

Management teams in shipping believe cyber security is mainly a "compliance problem"

This is frustrating for the IT professional. But it isn't really a surprise.

Management's main concerns are driving up revenue and driving down cost. Maximise chartering at minimal expense. To run a tight ship, any investment that cannot visibly drive either of these twin goals is deprioritised. If the link is not clear, they don't believe it or they don't understand it, investing in it is a luxury. So the responsibility falls on the CIO or IT manager to help leadership understand the need and urgency.

But shipping IT professionals still find themselves stuck in a dialogue with management about how to do the bare minimum in order to comply with IMO 2021, instead of how to take steps to properly cybersecure.

From our discussions with shipping IT professionals, we find only 20% are actively engaging with their management to align cybersecurity strategy. In over 65% of cases, the dialogue is either focused purely on compliance or related to purchasing specific cybersecurity solutions. This means that for every 100 interactions that IT professionals have with their management team, 65 of them are either discussing compliance or a point solution.

Interestingly, none of the shipping IT professionals we speak to have a relationship with management where they agree to an annual budget and make the day to day decisions around cyber-security strategy and tactics. So management are making decisions on what cybersecurity controls to put in place on a case by case basis, rather than the IT professionals.

This is why cyber security in shipping is still commonly treated as a "compliance problem" - it is being presented as one.

This mindset is based on false assumptions

The most dangerous one is that shipping is not a targeted sector. If you still don't believe the threat landscape is shifting, then just look at the data - just within the first 5 months of 2020, there were public announcements of cyber attacks on MSC, Anglo Eastern, OSM and twice on Toll Group. While the amount of losses in revenue or remediation costs remain guarded secrets, they have all admitted to significant interruptions in operations.

Another false assumption is that we can achieve vessel digitalisation and worry about cyber security later. The evidence is clear that this simply isn't the case. Just to cite one example, a common assumption is that you can maintain separation of the business, crew and OT networks. So it should be impossible for an attacker to compromise a crew asset, then use that foothold to attack a critical business workstation or OT system.

In reality, in ~80% of vessels CyberOwl has deployed on, we find assets connected to the business network that the IT manager knows nothing about. They haven't identified them in their inventory, have no idea of their nature, did not sanction a connection, had no way of controlling or disconnecting them remotely. Sometimes it is not just 1 or 2 such assets, but 10s of them. In several cases, these unauthorised connections were later discovered to be OT devices linked to a bridge system, the engine room or auxiliary power system.

The relationship between IT and management needs to change. IMO 2021 is an opportunity to get "air time".

IMO 2021 presents a window of opportunity. Management teams have no choice but to make sure their fleet has a cyber risk management system that complies. Instead of approaching the dialogue as a compliance issue, this is the opportunity to frame cyber security as a business issue - an enabler to deliver overall business priorities. Whether this is business efficiency, vessel performance optimisation, remote control and management or crew welfare.

There are useful examples in recent history of leveraging compliance to strengthen overall cyber risk management. According to analysis by Marsh, companies successfully used GDPR as a catalyst, with 78% investing more in cyber security en route to GDPR compliance. A key finding in a 2019 UK government report was that as a result of GDPR, there was a significant increase in the number of businesses putting in place quarterly updates with senior management on cybersecurity, intensifying cybersecurity training and enhancing cybersecurity policies. Essentially, where the opportunity was taken, GDPR had a positive effect in improving executive attention that prompted the related investments.

This window of opportunity won't last forever. Don't squander it.

So how do shipping IT professionals make the most out of IMO 2021?

Shifting the emphasis of the discussion with management is an important start. Turn the conversation from "what we need to do to comply" to "how does cybersecurity support the way we want to work going forward." For example, the need for better remote access control becomes less about the fact it is an IACS recommendation, but more because it reduces the need to get an engineer onboard the vessel.
  • Use IMO 2021 as a catalyst for working more closely with your colleagues in technical, operations and quality. Get a good understanding of their ambitions for improving performance and reducing costs. Use this knowledge to demonstrate how cybersecurity could help them achieve that securely. Link your cybersecurity initiatives with their cost-savings or revenue-gain figures.
  • Quantify the risk within the context of these wider business objectives. Help management visualise the potential loss due to a cyber attack. But make this real to your own organisation and its digitalisation ambitions, rather than using high-level industry report figures. There are various well-recognised methods for quantifying the cyber risk to an organisation. One approach we like using at CyberOwl is the FAIR methodology.
  • Define some key cybersecurity metrics to start collecting and tracking. Begin with a pragmatic, small number that won't drown your resources. At minimum, these should measure the volume of system outages, volume of cyber incidents and some aspect of usage policy abuse, misconfigurations or suspicious behaviour. Gather benchmarks on these metrics from a friendly cybersecurity advisor or a collaborative network of other shipping IT professionals. Present the trends and benchmarks to your management, clearly explaining their implications.
  • Lean on your vendors to help you inform your cybersecurity strategy. It is part of the value and service they bring to you. When you perform trials, treat it as a learning exercise, not just a procurement exercise. Clearly set out what you are trying to learn about your current cybersecurity posture, where the risks are and how you are currently managing them. Share this "list of learning points" with your vendor. They should be helping you learn, rather than just proving to you their cybersecurity product is better than the competition.
Finally, it doesn't need to be a huge transformation programme. Start small and simple. Make some changes. Measure the improvement. Share any good news and small wins. Repeat.

How are you engaging with your management on IMO 2021? Get in touch with us here if you would like help or a free consultation on how to reposition the dialogue.


Fincantieri, cutting off the first sheet of the first of two ultra-luxury cruise ships for Regent Seven Seas Cruises
It will be delivered in 2026
Mercitalia Rail starts transport of the new Frecciarossa 1000 of Trenitalia from Pistoia to the Czech Republic
They are headed to the Velim Test Center
New ro-ro traffic at the San Cataldo Container Terminal in the port of Taranto
Two ships have landed more than 1,500 vehicles
Uiltransport urges the Venice AdSP to review the ban on temporary port work
Verzari : umpteenth attempt to unload the current balance in the national port system
Concluded the first start-up phase of the Port Community System of the AdSP of the Straits
On 23 and October 24 meetings with stakeholders for the further development of the system
Guido Grimaldi confirmed president of the Logistics Association of Sustainable Intermodality
ALIS celebrates eight years of life
File the charges against four employees of the AdSP of the South Tyrreno and Ionian
Joy Tauro
The Gip of the Palmi Tribunal in Palmi has been definitively established.
In the third quarter, new orders to the ABB group grew by 1.8% percent.
Revenue up 2.3%
Visual Sailing List
Departure ports
Arrival ports by:
- alphabetical order
- country
- geographical areas
Visit by Giani, Guerrieri and Macii to the Darsena Europe shipyard in the port of Livorno
Livorno / Florence
In the port of Piombino inaugurated the new plaza in front of the quay of the regasification ship
Gruber Logistics opens its own first headquarters in the Middle East
Initially the new Dubai branch will focus on cargo project and air and sea transport.
Delivery of works for the completion of the port of Tremestieri
They are expected to be completed in two years
Spediporto has organized a two-day trip on the Green Logistic Valley and Italy-China trade
In the third quarter of 2024, container traffic in the port of Hong Kong decreased by -7.1%
Hong Kong
In the first nine months of the year, the decline was -5.7% percent.
CEVA Logistics constitutes a joint venture with Saudi Almajdouie Logistics
It will operate the transport-related and logistical activities carried out by the two companies in Saudi Arabia
Concern of the Spezia's maritime agents for the possible curb to cruise traffic in port
The Spezia
APSEZ completes the acquisition of 95% of the company that operates the Indian port of Gopalpur
The port climber has a traffic capacity of 20 million tonnes per year
Fit Cisl La Spezia, no to the passing of the Carrara port management at the AdSP of the Northern Tirreno Northern
The Spezia
The Tuscan port has benefited from substantial financial resources from the Via del Molo.
Changed Risso enters the capital of Maritime Maritime Agency Ravennate
Ravenna / Genoa
Established a joint venture joint venture
Minerva Bunkering has purchased the US Bomin Bunker Oil
The American company has been ceded by Germany's Mabanaft
Approved the new safety regulation of the port of Genoa
Processed by the Capitaneria in Porto with the involvement of port operators, it will enter into force on the first November
Evergreen's trend of revenue growth continues, Yang Ming and WHL
Taipei / Keelung
In September 2024, however, a double-digit percentage decline was recorded compared to the previous month.
Ferfreight's proposals for the infrastructural development of the last mile and for the resolution of criticalities
High-automation drones to surveil the areas of Interporto Padua
They take off and land in a "robotic hangar"
Italian Ports:
Ancona Genoa Ravenna
Augusta Gioia Tauro Salerno
Bari La Spezia Savona
Brindisi Leghorn Taranto
Cagliari Naples Trapani
Carrara Palermo Trieste
Civitavecchia Piombino Venice
Italian Interports: list World Ports: map
ShipownersShipbuilding and Shiprepairing Yards
ForwardersShip Suppliers
Shipping AgentsTruckers
Spediporto has organized a two-day trip on the Green Logistic Valley and Italy-China trade
It is scheduled on 22 and October 23
In Mantua the annual meeting of the European Federation of Inland Ports
››› Meetings File
Russia and India join forces in the Arctic, leaving China aside
The Overlooked Legacy of Black Dockworkers: Forging Justice On America's Waterfronts
››› Press Review File
FORUM of Shipping
and Logistics
Relazione del presidente Nicola Zaccheo
Roma, 18 settembre 2024
››› File
Rexi : Financial will not introduce increases in the cost of diesel for self-transport
They are not expected-he assured-changes to the current tariffs
In Mantua the annual meeting of the European Federation of Inland Ports
Tomorrow the international workshop "HyMantoValley project Creation of the Hydrogen Valley in the Valdaro inland Port"
Joy Tauro, possible further extension of the Agency for the administration of labour in port
Joy Tauro
Agostinelli : It will be required in the event of failure of the next meeting for the establishment of the ex art enterprise. 17
In the port of Gioia Tauro, 280 kilos of cocaine were seized
Reggio Calabria
More than 40 million euros could have been made in the market.
Baker Hughes to renounce industrial settlement in the port of Corigliano Calabro
Joy Tauro
Agostinelli : who did not want this project to enjoy this tragic victory!
VARD will build a Commissioning Service Vessel to Navigate Capital Partners
Trieste / Ålesund
It will be delivered in the second quarter of 2027
Liguria, Piedmont, Lombardy, Apulia, Calabria and Liguria have signed up to the Mit.
The Regions integrate with own resources the state appropriation
Fatal accident in the port of Naples
A worker lost his life overwhelmed by a mechanical means
Partnership of Magellan Circle and EETRA to promote sustainability in the port and logistics sectors
Agreement for the design and realization of a new maritime railway station in Savona
The link between the Savona Parco Doria station and the new plant is expected to be adapted.
In the third quarter, the revenues generated by the OOCL container business grew by 73.7%
Hong Kong
Volumes of truckloads transported increased by 3.6%
On Wednesday, Padova will take over the third edition of Green Logistics Expo
Among the appointments, the States Generals of the Logistics of the North East and Mercintrain
Three new appointments to top executives of TESYA group companies
Pierre-Nicola Fsheep new general manager of group, Flavio Castelli new CEO of CLS E Vincent Albasini new CEO of CGTE
Rixi : winning idea for a maritime country is the possibility of having foreign shareholdings with concessions in extra-European ports
They would be useful-he explains-to stabilize the logistical lines in every geopolitical condition
Port of Spezia, in mid-2025 the electrification of the Molo Garibaldi will be completed
The Spezia
In recent days in Estonia the test of the robot from the quay will connect the power grid to the ship.
New training project of Assologistics in collaboration with Randstad Italia
Creation of a digital platform to facilitate management and fruition of training courses
A Vietnamese delegation in Geneva to increase cooperation with MSC
Proposal participation in the project of the new deep-water port in Lien Chieu (Da Nang)
A strike blocks the ports and airports of Corsica
Protest against the assumption of entrusting its management through a contest
The Transport Regulatory Authorities of Italy and France have started a cooperation
Paris / Rome
T&E, the only system based on a Global Fuel Standard is not enough to decarbonize shipping
The organization highlights the need for it to be accompanied by the application of a global tax on emissions
The AdSP of the East Ligurian Sea completes acquisition of 2.4% of the capital of CEPIM-Parma Interport
The Spezia
Buy the share of the Municipality of La Spezia and of the Riviere Chamber of Commerce in Liguria
- Via Raffaele Paolucci 17r/19r - 16129 Genoa - ITALY
phone: +39.010.2462122, fax: +39.010.2516768, e-mail
VAT number: 03532950106
Press Reg.: nr 33/96 Genoa Court
Editor in chief: Bruno Bellio
No part may be reproduced without the express permission of the publisher
Search on inforMARE Presentation
Feed RSS Advertising spaces

inforMARE in Pdf