Cyber attack: A growing menace in maritime
With an estimated half of vessel operators being exposed to some form of cyber attack, defence against the onslaught is becoming an essential weapon in the marine armoury.
As head of Haven Knox-Johnston Commercial Malcolm Stewart says in our interview on P166, cyber security is now a major part of his insurance business.
And the irony is that if personal data is stolen by hackers it will be the vessel operator and not the hacker that runs the risk of getting prosecuted because of GDPR and government regulations.
In the UK, government-backed scheme Cyber Essentials, launched in tandem with the National Cyber Security Centre, offers a certification called Cyber Essentials Plus to firms that prove they have taken the necessary steps to get protected.
Cyber attacks, it says, can come in many forms, although the majority are quite rudimentary, carried out by unscrupulous individuals with limited skills – the digital equivalent of pushing at a door to see if it’s locked.
However criminal groups are becoming increasingly sophisticated and more capable of stealing money, information, or simply disrupting operations.
One of Europe’s largest marina groups, MDL Marinas, has just been awarded Cyber Essentials Plus certificate, which it says ‘shows that MDL Marinas guards against cyber threats’ to protect customer data.
“From its online visitor berthing booking system and Otium Rewards scheme to its new Falco Smart Wireless Technology, MDL Marinas’ operations are increasingly online based,” says the company. “The decision to better secure its IT systems against cyber attacks will prove a vital one as the business moves towards a digital set-up for the majority of its user-based systems.”
“A conservative estimate is that 50% of our clients who have cyber insurance policies in place have used it in one form another, even if they’ve just taken the advice,” says Malcolm Stewart.
With the rise in hacking coming from Russia, North Korea and China, he says, there are suggestions that other attacks are coming from Eastern Europe and Iran.
Key pointers are:
- · Don’t let anyone access your system who is not a employee
- · Never log on to insecure systems with work equipment
- · Update your systems as per manufacturer guidelines and updates
- · Change passwords every 6 months
- · Get cyber insurance.