Photo credit: Shutterstock/High Voltage
You have been either hacked or just didnt know you have been hacked!
ByGeorge Ward
(ECDIS Ltd.) I predict that the first catastrophic maritime cyber incident will not be the result of a direct attack on a safety critical specific piece of equipment. It will be the result of an infection on a random PC, perhaps an unassuming email to a crew member, whose PC is either connected to the vessels internal super highway or he transmits the infection internally whilst it lies dormant. Crypto locker, or Ransomware software (used by thousands of hackers) are easily available to download on the dark web, neither of which may necessarily attack the equipment they infect, they can lie dormant and infect connected equipment when nobody expects. You have been warned! Watch the video link at the end of this article to see an attack on maritime equipment in real time.
Cyber-attack is the current buzzword. It is known by some as an industry killer and even as the potential cause of the next world war, but thought by others to be a myth. So where does the maritime industry stand in all of this?
In the main, but certainly not universally, the maritime industry has a dismal record in its slow and painful transition from paper and analogue methods of shipping to new innovative technologies when compared to industry rivals like aviation. But why is this and how could it affect cyber security in the maritime arena? Or have some seafarers not even evolved enough to be talking about it yet, let alone implementing new cyber procedures on board ship. We have all met `that Captain` who is nervous about `the machines on his ship`.
Whilst the maritime Industry doesnt seem to have been strategically targeted in terms of the vessels themselves, there is now plenty of talk of `accidental` or naive seafarers accepting a generic phishing email that goes on to attack their computers.
Major corporations like Google and Yahoo have release statements stating they were deliberately hacked. The question is what will be first for the maritime industry, the deliberate or strategic hacking of an individual ship, or the shipping corporation as a whole.There has been a call for cyber specialists to come and give answers to the potentially very real dangers facing the industry that could not only damage reputations, but cause disruption to trade worth billions of pounds to the industry. Not all is lost though, as long as we can move the industry forward to cope with the digital world we live in today.
Cyber Security was a hot topic in 2016 however now we are in 2017, and the seafaring community are becoming more aware of what can potentially happen. There is a real threat for cyber activists to start gaining and changing sensitive shipping data from our onboard equipment. Such as changing the vessels route to cause a grounding, gaining access to digitally controlled engine rooms and causing alarm mute whilst an engine fails or even catches fire due to a manual overload by the hacker.
With more and more companies looking for insight into how to stop attacks from occurring, the main area of concern is the lack of security awareness by both companies and employees as they have been taken aback by the swift rise in the industrys threat level from cyber security; almost non-existent just a few years ago to todays high alert. It is expected that shipping companies and independent vessels could be next on the list for major cybercrime activity as it is as yet mainly unexplored territory for hackers who are only now starting to realise its huge potential as a target. Attacks now have the capability to obtain sensitive ECDIS, AIS and GPS data, to name but a few, so it is vital that the correct procedures and processes are in place to stop the worst from happening.
The scary part; 51% of US adults suffered some kind of data security incident between December 2015 and December 2016. In 2015 there were 781 reported major company data breaches in the US alone due to cyber-attacks which combined cost companies $400 billion. These are only the reported data breaches. Sadly there is often an element of sweeping under the carpet in all industries. This total will continue to rise if the maritime industry, where the proportion of those of digital native age is far lower, do not adapt to ever changing technology and the major security threats it brings with it. Overall, the predicted cost of cyber-attacks in 2019 is estimated at a colossal $2.1 trillion.
The issue, alongside a lack of awareness by employees and users of operating systems, is the development speed of technology. This digital age of super computers, 4D printing and nano technology is like no other and is proving to be self-accelerating, i.e. one technology is put into operation while the next generation, more powerful and innovative, is being produced, thereby creating an always expanding, developing and aggressive cycle. But, due to the speed of production, this process can lead to an unstable, unsecure and untrusted platform, as it is not able to keep up with ever changing threats. After years of this development, technology companies are starting to adapt to the issue by developing and applying software updates weekly which try to manage security flaws within the software, while changes to future developments can help manage the constantly increasing cyber-crime threat; until the next global threat takes place or takes over.
Some Maritime software manufacturers have used a physical security method of locking out their systems in order to intercept physical security threats altogether, however this ironically increasing the complication of applying security software updates! This restriction can complicate a shipping companys decision to have an integrated bridge system due to issues with syncing and communication between different software manufacturers; also meaning only specialised engineers and trained software technicians are allowed to apply updates, causing additional issues. Restrictions like these could mean that your system is 80% more susceptible to cyber threats.
First off, the solution is simple; but it will cost you, which no one likes to do unless its necessary. Only some companies feel that cyber security is important enough to invest into it. Nevertheless you will watch multiple companies become complacent and unconcerned about the real threat in the water, until it becomes a reality, and the organisation comes grinding to a halt. In reality, if you spend as much on coffee as you do on cyber security measures, you will be hacked. It is alleged that almost every company in the World has already been hacked, or if not, will be soon. The Director of the FBI, James Comey had the following to say on Chinese hackers: There are two kinds of big companies in the United States. There are those whove been hacked by the Chinese and those who dont know theyve been hacked by the Chinese.
This is the world as it is and therefore we need to change with it, not be ten steps behind. First, we know the industry is struggling from sector to sector, but cyber attacks will only make it worse, so the first move is ensuring everybody is educated in cyber security awareness. Preferably starting from the top and working down so the entire seafaring community can spot a cyber-attack and know what action to take in response. Experienced educational companies exist that offer in-depth, classroom based courses in the subject of cyber security. ECDIS Ltd also offers the first maritime based cyber security awareness course with the aim of bringing the industry up to speed. Elements of all their BTM, BRM and even ECDIS courses now include cyber prevention and awareness modules.
Countless companies are missing the correct procedures when it comes to security. A robust IT security policy is highly recommended, as this allows employees and users of all IT equipment to be clear as to how company data and information should be used on IT equipment. Its not just small companies either that struggle in this war against cyber activists. Large corporations are also at major exposure risk, primarily due to not having a dedicated IT and security team. It is recommended that a company appoints a cyber security chief to implement and respond to all cyber security related issues or system flaws that may be found. This is so one person has ultimate responsibility for implementing and maintaining all cyber security measures within the company thus ensuring consistency of approach. Cyber security attacks are incorrectly thought of as attacks that occur just over the internet due to the wrong security measures being taken; however lack of physical security can also be a major factor in the cause of industry changing attacks. During the twentieth century a majority of attacks occur due to people not taking the correct measures to keep our IT equipment safe, another reason why we need everyone to be aware of whats coming. It really is as easy as someone to come into your reception and ask you to print off a copy of their CV from a USB stick, which is actually infected with multiple viruses, this could ultimately allow someone else complete control of your businesses entire network and therefore most likely, thereby destroying it.
In summary, cyber security isnt an issue we can ignore, it may not be heard of yet as giving direct threats towards our vessels but this will come in time when noticed by any cybercrime activists who either want to damage the industry or cause major damage to infrastructure or even human life. It can be averted. Many, if not all, shipping companies have some form of internal networked server that allows for all of their computers to communicate and send and save files between them, and therefore also connect to the internet, so with the improper procedures in place it could be easy for anyone keen to infect an auxiliary piece of equipment that connects to the primary. Think of the random software updates that happen every day, for example to an engine room sensor test, or to the bridges digital anemometer that may appear non safety critical, but they are connected to safety critical systems. We often concentrate and develop robust procedures purely for the few safety critical pieces of equipment, but the attack will take place on a tertiary system that is connected to it.
Watch the following YouTube clip to see a live attack on standard maritime equipment:
See more here:
Watch: Impressive High Seas Evacuation from Tall Ship - GCaptain
- High Seas Forecast (Tropical Atlantic) [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- International waters - Wikipedia, the free encyclopedia [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- high seas | maritime law | Britannica.com [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- Radiofax Charts - New Orleans [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- High Seas Alliance | highseasalliance.org [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- High Seas Fleet - Wikipedia, the free encyclopedia [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- Web Design & Mobile App Developer San Francisco CA | HIGH SEAS [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- knit/lab high seas - Kieran Foley [Last Updated On: June 21st, 2016] [Originally Added On: June 21st, 2016]
- Protecting Ocean Life on the High Seas - Pew Trusts [Last Updated On: June 27th, 2016] [Originally Added On: June 27th, 2016]
- Convention on the High Seas - Wikipedia, the free encyclopedia [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Ultima Online: High Seas - UOGuide, the Ultima Online ... [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- High Seas - Science NetLinks [Last Updated On: July 10th, 2016] [Originally Added On: July 10th, 2016]
- High Seas Fleet - Wikipedia [Last Updated On: November 12th, 2016] [Originally Added On: November 12th, 2016]
- United Nations Convention on the Law of the Sea [Last Updated On: November 27th, 2016] [Originally Added On: November 27th, 2016]
- Ocean Prediction Center-Coastal, Offshore and High Seas ... [Last Updated On: December 15th, 2016] [Originally Added On: December 15th, 2016]
- Global High Seas Marine Preserve A non-profit dedicted ... [Last Updated On: February 2nd, 2017] [Originally Added On: February 2nd, 2017]
- New centre for high seas visitors in Angus - The Courier - The Courier [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Naval Presence on High Seas Underscored - Financial Tribune [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Pirates Face Push Back On The High Seas - American Media Institute [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Queen Mary 2 to Host High Fashion on the High Seas - Cruise Hive - Cruise Hive [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Nigeria Rescues Oil Tanker From High-Seas Pirates - OilPrice.com [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- High Tea on the High Sea by Searoad Ferries Services [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Conflict and Diplomacy on the High Seas - Focus News [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Cabin cam shows the hilarious frustration of rolling on the high seas - Pickle [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Ransomware Gangs Have Become the High-Seas Pirates of the Internet - On the Wire (blog) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Suspect in high-seas homicides hospitalized, putting case on hold - Sacramento Bee [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- To Boldly Cruise Where No Couple Has Cruised Before - Bloomberg [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Sailing the high seas: Top cruises for first-timers, families and excursions in 2017 - Malay Mail Online [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- All aboard for Cosplay on the high seas - The New Paper [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Star-Studded Broadway on the High Seas 8 Sets Sail Feb. 17 - Playbill.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- The Cold War returns to the high seas - CNN [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- 'The internet is like the high seas' - Deutsche Welle [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Greg McQuade discovers life on the high seas aboard USS Dwight D. Eisenhower - wtvr.com [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- In Dramatic High Seas Rescue, Four Fishermen Rescued By Good Samaritans Off Galveston, Texas, Coast - Patch.com [Last Updated On: February 19th, 2017] [Originally Added On: February 19th, 2017]
- Escape to the high seas at the National Aviary - NEXTpittsburgh [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Scapa Flow German High Seas Fleet scrap sites explored - The ... - The Orcadian [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Two boats towed in harbor in high seas - Cayman Compass [Last Updated On: February 24th, 2017] [Originally Added On: February 24th, 2017]
- Take to the high seas with Condor Sailing Adventures - Pensacola News Journal [Last Updated On: February 25th, 2017] [Originally Added On: February 25th, 2017]
- Aging high-seas murder suspect out of hospital and back in court - Sacramento Bee [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Masters of the waves talk of high seas, thrills & spills - The New Indian Express [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Campbell River Sea Cadet off to England to hit the high seas - Campbell River Mirror [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Survival on the high seas (From The Northern Echo) - The Northern Echo (registration) [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Industry 4.0 on the High Seas - MarineLink [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- New Pirates Of The Caribbean: Dead Men Tell No Tales Trailer Brings Us More Action On The High Seas! - LRM Online (press release) (blog) [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Eco-warriors meet government authority on Ballina's high seas ... - Echonetdaily [Last Updated On: March 6th, 2017] [Originally Added On: March 6th, 2017]
- Tech on the high seas: Fred Olsen IT chief chats cloud, connectivity and security - www.v3.co.uk [Last Updated On: March 6th, 2017] [Originally Added On: March 6th, 2017]
- Why newbie Drusilla is preparing for life on the high seas - The Wharf - The Wharf [Last Updated On: March 7th, 2017] [Originally Added On: March 7th, 2017]
- Bhang Travel Inc. Brings Cannabis Networking to the High Seas - PR Web (press release) [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- Drama on the high seas: East Kilbride couple reveal dramatic rescue after boat sinks in Gulf - Scottish Daily Record [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- French, Irish yacht sailors survive high seas off Australia's coast - TRT World [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- Journey through the high seas - Manila Standard - The Standard [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- High Seas Yacht Service | Specializing in Marine Propulsion Alignments [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- High Seas Adventure With Bunn And Molina's 'X-Men: Blue' - ComicsAlliance [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Fun on the high seas - Dallas Voice [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Freedom on high seas - nation.lk - The Nation Newspaper [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Limerick cancer survivor returns to the high seas - Limerick Post [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- At ease on high seas, woman pilot storms into male bastion | Kolkata ... - Times of India [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Meeting on High Seas Fisheries in the Central Arctic Ocean - The Arctic Journal [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Shell Looks to Lower The Cost of Drilling on The High Seas - Chem.Info [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Indians work on high seas but yet to take a cruise | Goa News ... - Times of India [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Cubans Still Fleeing on the High Seas, Months After Obama Nixes Wet Foot/Dry Foot - Breitbart News [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Narcosis Brings Terror Comes to the High Seas on March 28 - Dread Central [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Duncan high takes class to the 'high seas' - Duncan Banner [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Cardboard vessels take to the 'high seas' at MCA - News Item [Last Updated On: March 27th, 2017] [Originally Added On: March 27th, 2017]
- Skating a halfpipe on the high seas - GrindTV [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- SEAS: The Art Of Sound Perfection [Last Updated On: March 31st, 2017] [Originally Added On: March 31st, 2017]
- Helping save a life on the high seas warmed the heart of one Craig woman - Craig Daily Press [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- A dining odyssey on the high seas - Detroit Free Press [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- High Stakes for High-Seas Gaming - TravelPulse [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- High life on the high seas - THE BUSINESS TIMES [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Captain Cannonball sails the high seas as a pirate - Destin.com - Destin Log and Walton Log [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Real 'Pirate Women' On The High Seas Of Old | On Point - WBUR - WBUR [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- Trekr Racing makes its debut on the high seas - Washington Blade - Washington Blade [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- No clean boats on the high seas | Kochi News - Times of India - Times of India [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Cruise Operators Continue to Hide Behind the Death on the High ... - Cruise Law News [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Master of the high seas: Pomp, patriotism and politics as Navy's newest ship gets a name - Wicked Local Wellesley [Last Updated On: April 10th, 2017] [Originally Added On: April 10th, 2017]
- Young family moves from high desert to life on the high seas - Grand Junction Daily Sentinel [Last Updated On: April 10th, 2017] [Originally Added On: April 10th, 2017]
- Master of the high seas: Pomp, patriotism and politics as Navy's ... - Wicked Local Quincy [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Orphans turn sailors for fun day on the high seas - Pattaya Mail [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- High-Seas Adventure Game, Oceanhorn, Gets Nintendo Switch Preview - COGconnected (press release) [Last Updated On: April 17th, 2017] [Originally Added On: April 17th, 2017]