IMB: Guard Against Threat of Cyber Attacks

By Joseph R. Fonseca
Thursday, August 21, 2014
IMB Guard against threat of cyber attacks

 

The International Maritime Bureau (IMB) is calling for vigilance in the maritime sector as it emerges that shipping and the supply chain is the ‘next playground for hackers’.

IMB said, “Recent events have shown that systems managing the movement of goods need to be strengthened against the threat of cyber-attacks.

“It is vital that lessons learnt from other industrial sectors are applied quickly to close down cyber vulnerabilities in shipping and the supply chain.”

The threat of cyber-attacks on the sector have intensified in the past few months, with cyber security experts and the media alike warning of the dangers posed by criminals targeting carriers, ports, terminals and other transport operators.

They argue that while IT systems have become more sophisticated and thus enabling companies to better protect themselves against fraud and theft, it has also left them more vulnerable to ‘cyber criminals’.

Speaking at the TOC Container Supply Chain Europe Conference in London recently, TT Club’s insurance claims expert Mike Yarwood said, “We see incidents which at first appear to be a petty break-in at office facilities. The damage appears minimal – nothing is physically removed.”

He added; “More thorough post incident investigations however reveal that the ‘thieves’ were actually installing spyware within the operator’s IT network.”.

Yarwood said that more commonly targets are individuals’ personal devices where cyber security is less adequate.

Hackers often make use of social networks to target truck drivers and operational personnel who travel extensively to ascertain routing and overnight parking patterns. The criminals were looking to extract information such as release codes for containers from terminal facilities or passwords to discover delivery instructions.

“In instances discovered to date, there has been an apparent focus on specific individual containers in attempts to track the units through the supply chain to the destination port. Such systematic tracking is coupled with compromising the terminal’s IT systems to gain access to, or generate release codes for specific containers. Criminals are known to have targeted containers with illegal drugs in this way; however such methods also have greater scope in facilitating high value cargo thefts and human trafficking,” Yarwood revealed.

Whilst it is difficult to get hold of exact numbers and statistics, the risks should not be underestimated, and in June the US Government Accountability Office warned about the possible threats to US ports.

In a stinging report, the organisation said that the actions taken by the Department of Homeland Security and two component agencies, the US Coast Guard and Federal Emergency Management Agency, as well as other federal agencies, to address cybersecurity in the maritime port environment have been limited.

KPMG warns that hackers are the new open sea pirates. Wil Rockall a director in the organisation’s cyber security team highlights that the cyber security of maritime control systems are controlled by engineers and not chief information security officers (CISOs) or chief information officers (CIOs). Lacking security controls, these systems are vulnerable to hackers.

“Most ports and terminals are managed by industrial control systems which have, until very recently, been left out of the CIO’s scope. Historically, this security has not been managed by company CISOs and maritime control systems are very similar.

“As a consequence, the improvements that many companies have made to their corporate cyber security to address the change in the threat landscape over the past three to five years have not been replicated in these environments. Instead engineers have often been left to implement and manage these systems – people who focus normally on optimising processes efficiency and safety, not cyber and security risks. It has meant that many companies and their clients are sailing into uncharted waters when they come to try and manage these risks,” he said.

Rockall added; “We have found that one of the main blockers in improving this is a real translation problem when corporate IT security teams attempt to impose their standards on industrial control systems or maritime control systems. KPMG’s work with the operator of one of the largest fleets of crude oil and oil products tankers and liquefied natural gas carriers in the world, found that bridging that gap and coming up with pragmatic solutions to improve industrial control systems security without compromising process efficiency or safety, are vital to the success of industrial control systems cyber risk management.”
 

Maritime Reporter September 2014 Digital Edition
FREE Maritime Reporter Subscription
Latest Maritime News    rss feeds

News

Rederij Groen Takes Delivery of 7-Waves

Rederij Groen’s entire SRSV fleet built by Damen Maaskant Shipyards Stellendam. Dutch offshore services company Rederij Groen has taken delivery of the 7-Waves,

UASC Targets Expansion to Beat Container Market Blues

UASC expects to reach volume of 2.35 mln TEU in 2014 Global carriers still struggling with weak conditions United Arab Shipping Company (UASC) is on a major expansion drive,

Ecoships Claims 15% Ship Efficiency Gain

Ecoships introduced a customized version of the Six Sigma DMAIC approach to process and performance evaluation in order to optimize the energy-efficiency of the vessels under its management.

Electronics

General Dynamics is Link Govt-level Security to Consumer Smartphone

General Dynamics C4 Systems recently received the Defense Mobile Classified Capability (DMCC) contract from the National Security Agency (NSA). As part of the contract,

Transas to Supply TechSim Solutions to SUNY Maritime

The Navsim Services and Transas Americas Team, have been awarded contracts for supply of a combination of full mission, classroom and cloud based Transas Technical

Iridium Partners with Trimble to Support Expansion

Iridium Communications Inc. announced an agreement with Trimble that expands the company's use of satellite communications in its core Transportation and Logistics

Maritime Safety

U.S. Navy Contracts 12 Rapid Response Skimmers

Kvichak Marine won a US Navy contract for 12 30-ft.Rapid Response Skimmers (RRS) for delivery over the next 18 months, with options for up to 30 additional skimmers to be delivered through 2019.

General Dynamics is Link Govt-level Security to Consumer Smartphone

General Dynamics C4 Systems recently received the Defense Mobile Classified Capability (DMCC) contract from the National Security Agency (NSA). As part of the contract,

Three Dead in Offshore Platform Accident

Three workers were killed and one is still missing after an accident at one of the offshore oil and gas platforms in the Caspian Sea in Azerbaijan, Azeri state energy company SOCAR said on Thursday.

Communication

General Dynamics is Link Govt-level Security to Consumer Smartphone

General Dynamics C4 Systems recently received the Defense Mobile Classified Capability (DMCC) contract from the National Security Agency (NSA). As part of the contract,

Gazprom to Counter Negative Global Market Trends

The Gazprom Board of Directors took note of the information on the Company's financial strategy under the conditions of negative trends in the global financial

Iridium Partners with Trimble to Support Expansion

Iridium Communications Inc. announced an agreement with Trimble that expands the company's use of satellite communications in its core Transportation and Logistics

Software Solutions

Ecoships Claims 15% Ship Efficiency Gain

Ecoships introduced a customized version of the Six Sigma DMAIC approach to process and performance evaluation in order to optimize the energy-efficiency of the vessels under its management.

General Dynamics is Link Govt-level Security to Consumer Smartphone

General Dynamics C4 Systems recently received the Defense Mobile Classified Capability (DMCC) contract from the National Security Agency (NSA). As part of the contract,

GOST Security System thwarts Break-in

GOST (Global Ocean Security Technologies), announced that its GOST Insight HD GPS Security System was instrumental in foiling the theft of electronics onboard a powerboat in Aventura, Florida.

Logistics

Singapore Bunker Meter Mandate Targets 'Frothy Fuel'

Singapore, the world's biggest bunkering port, plans to end the so-called "cappucino effect" in ship fuelling through new meters designed to stop suppliers from short-changing customers,

Antwerp Port Achieves Highest Throughput

The port of Antwerp handled a freight volume of 148,344,168 tonnes during the first nine months of this year. That’s 3.7% more than the same period last year. Both

Containers, Cruises Help Boost Marseilles Fos

Container throughput at French port Marseilles Fos reached 876,711 teu for the period January to September, an increase of 6% on the first nine months last year.

 
 
Maritime Security Navigation Offshore Oil Pipelines Pod Propulsion Port Authority Salvage Ship Electronics Ship Simulators Winch
rss | archive | history | articles | privacy | terms and conditions | contributors | top maritime news | about us | copyright | maritime magazines
maritime security news | shipbuilding news | maritime industry | shipping news | maritime reporting | workboats news | ship design | maritime business

Time taken: 0.1649 sec (6 req/sec)