- Keywords: Technical, Maritime
Cyber security is a complex subject and, sadly, cannot be fixed simply by purchasing a “magic box”. Neither can it be qualified in one single index or grade of security/risk. For illustrational purposes, cyber security can be divided into three categories: People, Technology and Processes. Each category is equally important and needs to be addressed on a continuous basis for your company to be(come) safer. Indeed, trying to solve the problem by working with only one or two of the categories will be much more expensive than working with all three of them for the same level of security/safety improvement. With that said, some attention to one or more of the categories is a lot better than no attention.
People make mistakes, and in many of the cases where hackers have breached company defence mechanisms, employees or colleagues are the point of entry. What we often see when we are asked to help our customers assess and test their cyber security is that the impact from small mistakes made by crew or employees is bigger than our customers are aware of. The everyday actions of employees and not just some remote criminal hackers present one of the greatest risks to your organization and your customers.
The commitment of your people to protect your organization is a critical component of a strong cyber resilience. In other words, focus on the human aspects of your organization – on developing a positive security culture and attitudes, evident in the actions ashore and on board, and which is practiced by walk-the-talk management. Hence, when working with cyber security in your company, raising cyber security awareness among your staff is probably the most effective prevention.
Technology is becoming increasingly complex, also for the maritime industry. Today’s vessels are no longer composed of several stand-alone control systems. Rather, the systems are all connected, dependent on each other and constantly online. Changes to requirements and continuous software upgrades are contributing to making the security of technology more difficult (and expensive). Still, it is of great importance that the technology side of things is also included in your cyber security strategy (keywords: network segregation, hardening, anti-virus, software patching, etc.).
Most companies today have a good overview of their assets, and they have processes in place for maintaining their systems, but how much attention do you pay to your systems’ cyber risks?
The link between people and technology is processes. IMO has given ship owners and managers until 1 January 2021 to incorporate cyber risk management into their Safety Management System (SMS) or else ships risk being detained by port state control.
On a general basis, we observe that processes are not in place, or what is in place is not enough to give proper guidance in the day-to-day operation or, worse, in case of cyber security events.
Developing procedures to cover cyber security in addition to those already in place for operations, maintenance and safety would seem like yet another paper mill, but it is vital for you company’s safety. We advise you to keep the procedures straightforward with uncomplicated language and make people understand why they are necessary. Furthermore, we recommend you integrate cyber security-related policies, processes and procedures into the present SMS and Planned Maintenance System on vessels, rather than creating independent documents and tools.
10 simple steps to become more cyber-resilient
- Think before you click on links and attachments.
- Protect your passwords.
- Make sure external drives and USBs are clean.
- Be aware when third parties enter your location, systems or data.
- Never connect personal items to the ship/company-critical systems.
- Never use external Wi-Fi for company emails or downloads unless protected by VPN.
- Learn how to install and use two-step authentications.
- Plan for the unknown – learn how to back up and restore.
- Always report errors and mistakes.
- Educate yourself on cyber risks and how it affects your workplace, colleagues and you personally.
Our main concern, as seen from a class perspective, is the lack of awareness when it comes to putting these three elements together. For example, you will not have good safety if you focus solely on making the technology bulletproof and your crew then finds the processes hard to follow or even inadequate.
DNV GL has summarized all these best practices in a video which is freely available for you on our website The video has been produced together with the insurance company GARD and is a great means to enhance awareness and build best practices on board and ashore. We recommend all companies to use the video and supporting materials in their efforts to prevent any cyber-related incidents in future.
- Cyber security awareness video: dnvgl.com/csvideo
- Maritime cyber security services and solutions
- Recommended practice: Cyber security resilience management
- Maritime Cyber Security Awareness E-learning
- DNV GL cyber security class notation (from 1 July 2018)
Email us at email@example.com
How to make your company and ships more cyber-resilient
DNV GL has been addressing cyber security together with our clients for years. Even though we see the risk increasing every year, we believe that many companies and their assets are not prepared. This technical news summarizes some common-sense recommendations on how to make your company – and your ships – more cyber-resilient.
Concentrated inspection campaigns focusing on MARPOL VI, auxiliary machinery and open lifeboats
Different PSC regimes have announced their concentrated inspection campaigns (CICs) for auxiliary machines starting 1 June and for MARPOL VI from 1 September. The US Coast Guard carries out a CIC from May 2018 to 2019 on open lifeboats of US-flagged ships. This PSC news summarizes DNV GL’s considerations on how to prepare for the upcoming inspections.
Canada arctic pollution prevention certificate replaced by the polar code certificate
After entry into force of the Polar Code, the Canadian flag administration has repealed their requirements for an Arctic Pollution Prevention Certificate. This statutory news explains the transfer from the Arctic Pollution Prevention Certificate to the Polar Code Certificate.
Practical advice for IMO DCS data collection starting 1 january 2019
Both EU MRV (Monitoring, Reporting and Verification) and IMO DCS (Data Collection System) requirements are mandatory, and are the first step in a process to collect and analyse CO2 emission data for the shipping industry. EU MRV data collection already started from 1 January 2018, while IMO DCS data collection on fuel consumption to comply with the IMO DCS regulations starts 1 January 2019. This statutory news provides practical advice on IMO DCS compliance.
The IMO adopts greenhouse gas reduction strategy
The IMO’s vision is to phase out greenhouse gas (GHG) emissions as soon as possible within the end of this century. The aim is to reduce total emissions from shipping by 50% in 2050, and to reduce the average carbon intensity by 40% in 2030 and 70% in 2050, compared to 2008.
Ballast water management and port state control – checklist for preparation of PSC inspections
The international Ballast Water Management Convention (BWMC) came into force on 8 September 2017. In Paris MoU alone, the Port State Control (PSC) issued more than 70 deficiencies regarding BWM in the last four months of 2017; worldwide more than 160 deficiencies were identified up to March 2018. This PSC news provides you with an overview of the main categories of deficiencies raised during the first seven months of BWMC entering into force and provides a checklist for preparation of PSC inspections regarding BWM systems, their operation and maintenance.
Shaft alignment and propeller shaft aft bearing performance – recent trends call for action
Recent experience reflects concerns on propeller shaft aft bearing performance on some oil lubricated installations, e.g. ships with single stern tube bearing, during turning conditions involving hard-over steering angles in the upper speed range (MCR). This also coincides with evolving trends comprising of larger and heavier propellers operating at a lower RPM and different types of stern tube lubricants. This technical news aims to elaborate the basic logic, criteria and recommendations associated with propeller shaft aft bearing performance.
Cold conditions call for extraordinary measures for ships, equipment and crew
Canada and other areas close to the Arctic are currently experiencing extremely low temperatures, and owners calling at ports in these areas are obliged to prepare accordingly. This includes paying particular attention to safety and navigation-related equipment which may be damaged or impeded from working properly under such conditions. This PSC news summarizes the most important measures to be assessed for cold climate navigation.