A new research paper from BIMCO examined how the maritime industry can develop effective geopolitical strategies to address growing cyber security challenges in an increasingly unstable global environment.
The shipping industry’s reliance on digital technology has transformed the way companies operate, but it has also introduced new cyber security challenges. Modern maritime IT systems are increasingly complex and interconnected, with companies integrating digital solutions across a wide range of activities.
To improve efficiency, reduce costs, strengthen safety, and support sustainability goals, companies can either develop their own digital infrastructure or rely on solutions provided by external technology suppliers. However, this growing dependence on third-party providers can create vulnerabilities, particularly as businesses often work with multiple vendors to achieve greater operational efficiency.
The paper, “Managing Geopolitical Cyber Security Risks” which was authored by Aude Chocard under the supervision of Jakob Larsen, BIMCO’s Chief Safety & Security Officer, explores the relationship between national cyber security strategies and the potential risks they may create for shipowners operating across international waters.
Key findings
Digitalisation is transforming the shipping industry on a global level. Modern ships have become interconnected, and maritime stakeholders use complex technologies that involve multiple third parties from all around the world. From then on, external vendors are in control of IT systems used on board and on shore. A shipping company will rely on their services, which creates dependencies with the vendors.
Therefore, those IT systems can present geopolitical cyber vulnerabilities. Existing cyber security weaknesses because of systems that are not adequately secure, are more likely to be exploited in a tense geopolitical context. Cyber security threats arise when hackers have the capability but also the intent to intentionally harm the company’s business, whether the company is targeted or indirectly affected through its suppliers.
This framework will give an overview of the status of international relations in the maritime sector and help to assess cyber geopolitical risks. Considering the technological competition between China and the US, it is essential to consider their national strategies, resources and allies. Companies from distinct countries that operate together can imply rivalries and opposite requirements at a higher level. There is a possibility that governments and proxy groups take advantage of commercial relations in their own interests and leverage data from critical digital elements. Following their own jurisdictions on software, cloud storage or AI, States could also threaten to suspend the provision of digital services to achieve geopolitical ambitions. Dependencies and hostile intents increase the likelihood of a cyber geopolitical event will occur.
To anticipate cyber-attacks and geopolitical conflicts, a shipping company should establish its profile based on commercial and geographical characteristics but also by identifying the jurisdictions they follow. Then, the company needs to check compliance with its vendors, diversify the suppliers to avoid dependencies, and identify the people responsible for maintaining its systems. Assessing the risk also goes through a risk acceptance profile to determine the extent to which a risk is acceptable and if cyber security policies are considered as sufficient.
Risk management is essential regarding cyber security incidents in a geopolitical context
The risk management process includes factors such as impact, likelihood, vulnerability, threat, capability, opportunity and intent of malicious actors to conduct cyber-attacks.
Assessing the threat depends on the characteristics of a malicious actor. From a geopolitical perspective, it is directly linked to assessing the intent. A hostile intent can emerge when you are seen as an adversary due to territorial, economic or military conflicts.
Related to digitalisation, the technological competition can increase the hostile intent. On the other hand, when the relation between two actors is based on trust, cooperation and good faith, it is less likely than one considers the other as a threat, because actions are reliable and predictable. This intent relies on how one actor is perceived by the other. It can be identified in the national strategy, based on specific goals and targets indicated by a State or non-State actor.
Capability then addresses the resources and technical skills from a cyber security aspect. The more a State or non-State actor invests in cyber security means, the most likely they can be efficient and used to serve the intent. Capability also refers to policies, regulations and standards implemented to govern strategic actions in cyber space.
Opportunity finally relates to the conditions that can favour the threat of an attack. Capability and Opportunity are the reasons a threat can be effective and must be considered seriously. However, they primarily depend on whether there is an intent from the malicious actor.
Assessing the vulnerability is important because it relates to what can make an attack less feasible and attractive. If there is no vulnerability and in this case no dependence, the likelihood of an incident occurring is zero. Even if the threat is high, it must be put into perspective as the lack of vulnerability prevents the threat from occurring in the end.
However, this assessment of the likelihood can often vary and must be done regularly. Depending on whether the threat is seen as more real and factual, the degree of vulnerability may differ. Geopolitical alliances and the stability of proxy groups, but also the cyber infrastructure, with ships connected to the Internet or with an insufficient network segregation, can represent weaknesses and reasons for an actor to target another one.
…the paper highlights.
The impact factor finally relates to the potential material and human consequences, the individuals involved, and the ultimate shock on the company’s operations. This variable will determine whether there is a risk for a specific company or ship.
After doing an assessment of the likelihood, the shipowner needs to consider the impact of the risk to evaluate if it needs to be considered.