Under attack: Tugs prime target of cyber criminals

With costs of $100,000 a day for a stranded ship, the growing threat of cyber hackers is a growing concern to industry, which needs to step up its defence, speakers at a session at last week’s Europort said.

Cyber attack

Any vessel with a computer system is under a growing threat from cyber attackers, DNV Regional Business Development director Aakaash Dua said after the session, and no vessel was immune.

It’s an extremely expensive business: while most ransomware was actually unsuccessful, he said, the costs of legal defence were often greater than the ransom, not to mention the cost of a ship lying idle. While the average cost of a cyber attack to a shipping company is around $500,000, there have been cases where it has been far higher.

“In 2017 there was a $300 million cyber attack,” he said. “In 2018 there was a $210 million attack. Other cases include nuclear installations in 2025, and one incident involving an Iranian tanker and 116 vessels.

“Tugs are a prime target and although we can’t name specific incidents it has happened many times.

“It can take 57 days on average to close an incident out. There are 70-80 incidents a year – and most are delivered by USB.”

Expanding digitisation – expanding vulnerabilities

Øyvind Berget, CTO of NORMA Cyber, said the maritime industry’s expanding operational and digital footprint had opened new vulnerabilities.

“The world is changing – green requirements, globalisation – but the world’s cargoes are still being transported around,” he said. “Connectivity around the world is so good and everyone wants connectivity. Some of the incidents have been the driving forces that have brought people together to do something about it.” But the underlying problem continues to escalate: “Cyber warfare is only getting smarter and more dangerous,” he said.

Michiel-Louwerse_-Manager-Digital-Products-at-Damen-Shipyards

Michiel Louwerse, Damen Shipyards

In tug operations, a short interruption can have long consequences, leaving ships stranded and parts of ports inoperable.

From a vessel-building perspective, Michiel Louwerse, Manager Digital Products at Damen Shipyards, said rapid digitalisation was a double-edged sword.

“The world is getting better because we have more software,” he said. “Vessels are getting more complex and the software is helping us out. But the software needs connectivity and that needs cyber security.”

Integrating protective systems, however, has been a learning curve.

“We have implemented security in the last few years. It was challenging. Digital and software is new.”

Defence needed multiple layers, he said, beginning with the ID of a user, and only using machines for their intended use, not other functions such as gaming.

It’s not just the vessels themselves that need to be protected: third party suppliers also need to get their own houses in order, said Youri Hart, vice president Products & Solutions at Marlink.

“Everyone wants access to the vessel’s system – suppliers of thermostats, cameras, etc – but what are they doing to solve their own problems?” he asked.

‘Kindergarten’ compliance

Basic cyber hygiene remains a weak point across the industry.

“Compliance is very basic,” said Aakaash Dua. “It’s almost like kindergarten for cyber security hackers. The EU, Asia and America are all different as well. For passenger vessels that are 50 years old it’s like putting on a Band Aid. There are no cyber drills, no regulation for them, and basic education is missing on the shore side as well.”

aakash-dua-300x300

Aakaash Dua, CNV

“Bad links, for example, should be contained on one specific machine,” Hart said. “Video games should not be installed. The use of a device should be limited to what you need it to do. Prevention is better than a hit. But most owners are not educated in cyber hygiene.”

Crews, he said, used company email addresses for private use, such as for Netflix, and re-used personal and business passwords – one of the most fundamental risks to take.

“The average cost of a ship delayed at port is $100,000 dollars per day,” said Hart. “The cost of being secure is much less – Starlink, for example is about $1,000 dollars a month.”

Cyber regulations: NIS2 and what applies to maritime

Shipping is increasingly covered by cyber security frameworks, but implementation varies widely between regions. In the EU, the NIS2 Directive significantly strengthens cyber security requirements for “essential and important entities,” including port authorities, ship management companies and many maritime service providers.

NIS2 obliges organisations to implement risk management measures, incident reporting, supply-chain security checks and oversight of third-party technology systems — all areas that directly affect tug operators and port service fleets.

For vessels themselves, the IMO cyber risk management requirement, in force since 2021, requires cyber risks to be addressed within the ISM Code’s Safety Management Systems. A broader set of IMO rules for 2026–27 is expected to apply ‘to everything’, as Dua said, and ia likely to set minimum global standards for the next two to three decades.

But industry speakers agreed that rules alone are not enough. With tugs playing a critical role in manoeuvring high-value ships through tight waterways, a single compromised vessel could halt an entire port. As Berget warned, cyber warfare ‘is only getting smarter and more dangerous’, and for tug operators, the cost of being unprepared may be far greater than the investment required to stay secure.

For more information on the cyber security regulations, click here.