Article Preview
0
Views

As Ships Become More Connected, Cyber Threats Move Offshore

Texas A&M expert discusses the rising cybersecurity threats in maritime shipping.

Published Nov 30, -0001 12:00 AM by The Maritime Executive

[By Texas A&M]

A Texas-bound oil tanker was recently boarded by the FBI amid fears that the ship’s networks had been compromised by hackers.

As ships and ports become increasingly dependent on connected technology, maritime cybersecurity is emerging as a critical defense against threats that could pose national security risks, said Dr. Amulya Gurtu, professor and department head of the Maritime Business Administration Department at Texas A&M University at Galveston.

“This problem has two sides: attackers and protectors,” Gurtu said. “Protectors must stay ahead of attackers 100% of the time. Cyberhackers can fail 99% of the time and still succeed in their mission, but a protector cannot afford to fail even 1% of the time. That is the challenge. Cybersecurity is no different from border or national security.”

Maritime shipping moves roughly 80% of world trade by volume, according to Gurtu. Hijacking just one ship could have a ripple effect on global supply chains, making maritime cybersecurity increasingly critical. Because ports are considered critical infrastructure and ships often operate in national and international waters, a cyberattack is not just a financial or business problem; it can become a national security issue.

“A cybersecurity breach/cyberattack does not stay digital. It can send a vessel off course, and if it has passengers, it becomes an even more serious problem,” Gurtu said. “Global cybersecurity spending across connected industries is projected to reach $500 billion by 2026, showing how serious the vulnerability is. The maritime cybersecurity market is valued at approximately $4 billion in 2026 and is expected to grow to over $10 billion by 2034.”

Ships and ports rely on interconnected systems for navigation, cargo tracking, scheduling and more. Hackers can manipulate GPS and AIS data to disrupt port operations or potentially redirect vessels, creating risks to supply chains and national security.

Gurtu said two main defenses for ships are prevention — including encryption, multi-factor authentication and zero-trust network design — and detection using machine learning to flag unusual behavior in real time. But prevention alone is not enough in an environment that is constantly moving and changing.

Once a hacker is in the system, they could divert the ship to a different destination, making search and rescue difficult, Gurtu said.

“Hackers can spoof GPS signals to send a vessel’s reported position to a false location or exploit network vulnerabilities to disrupt how a port coordinates ship movement,” he said. “Much of maritime cybersecurity still relies on the idea of a fixed network boundary, but ships and port vehicles are mobile, so they constantly cross in and out of different networks, and traditional security wasn’t built for that. On top of that, GPS and AIS, which vessels depend on for navigation, are susceptible to spoofing and jamming.”

Gurtu said researchers at Texas A&M at Galveston have several projects underway that could strengthen cybersecurity in the maritime industry.

“Dr. Dursun-Ozguven, assistant professor in the Maritime Business Administration Department, worked on a research project and has tested machine-learning methods for detecting cyberattacks on moving, GPS-tracked port equipment, using container terminal operations as a case study,” he said. “Dr. Daneshgar, also an assistant professor in the Maritime Business Administration Department, focuses on cyber resilience of organizations — the ability of organizations to recover from cyberattacks. It is equally critical and complementary to cybersecurity.”

Gurtu said cybersecurity education and research will remain essential to staying ahead of evolving threats.

“The maritime business department has a cybersecurity minor, which is growing. We also participated in maritime cybersecurity conferences and policy discussions alongside industry and government stakeholders,” he said. “We are trying to make every maritime student in our program aware of the risks and importance of cybersecurity in the maritime industry.”

The products and services herein described in this press release are not endorsed by The Maritime Executive.