TL;DR too long, didn’t read

  • A Japanese insurer has launched the first cover for economic losses caused by interference with ship navigation. To qualify, owners do not have to buy anything. They have to train their crews.

  • North Carolina's three ports ran on manual gate processing for two days after a cyberattack. Operations slowed. They did not stop, because there was a written plan and somebody activated it.

  • Six passengers reached the public address system on a 3,502-passenger cruise ship and announced that the captain had lost control of the vessel.

In none of the three was the technology the problem.

Three things that matter this week

An insurer just priced GPS jamming, and asked for training

Sompo Japan has launched what it describes as the shipping industry's first insurance cover aimed specifically at economic losses caused by radio interference with ship navigation systems. It became available this month.

The cover pays when interference with satellite positioning leaves a vessel unable to operate even though the ship has suffered no physical damage. The examples the insurer gives are ordinary and expensive: a ship prevented from entering port, a ship detained, a ship forced to delay departure.

That gap is real. Sompo's existing marine cyber product, introduced last November, covers physical hull damage and liability resulting from cyberattacks. It does nothing for a vessel that is undamaged, uncollided, and simply cannot work. Conventional hull policies have carried cyber exclusions that left genuine uncertainty over whether a casualty caused by GPS spoofing would be covered at all.

To take the cover, owners are required to put participating seafarers through a ClassNK Academy maritime cybersecurity course covering cyberattack risks, defensive measures, and the safe use of onboard devices and removable media.

No anti-jamming receiver. No redundant positioning system. No segmentation project. The condition of being paid is that the crew has been taught.

This is the first time I can recall a marine insurer making a specific training programme a condition of cover, and it is worth more than the product itself. Insurers are not sentimental about where they put requirements.

What to do: Ask your broker one question at your next renewal: what would our premium and our terms look like if we could evidence crew competence on navigation interference. If the answer is "no difference", you have learned something about your broker. If the answer is anything else, you have found a budget line that does not have to come out of the security budget.

Three ports went manual for two days, and it held

Late on Tuesday 4 August, the North Carolina State Ports Authority discovered that its IT system had been, in its own words, "hacked by an outside actor or group". The breach affected all three of its facilities: the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port.

The IT team activated the agency's Cybersecurity Contingency Plan immediately. Wilmington delayed its gate opening and switched to manual gate processing, which freed the IT team to work on recovery instead of firefighting operations. Signs went up outside the gates: "Operations Alert: System Issues. Expect Delays." State and federal partners were brought in the same day, including the North Carolina Department of Transportation, the state Department of Information Technology, and the US Coast Guard.

The breach was contained on the day it was found. By Thursday the gates were on a normal schedule. As of Friday, operations were still being processed manually while an outside forensics team worked through the systems.

Wilmington and Morehead City moved 4.4 million short tons of bulk and breakbulk cargo last year. Wilmington alone handles more than 5,000 container gate moves in a normal week. For two days, those moves happened on paper.

There is a lot we still do not know. No group has claimed the attack. The authority did not answer when asked whether it was dealing with ransomware. And it has not disclosed whether vessel operations, cargo-handling equipment or rail services were affected at all — which is to say, we do not know whether this stayed in IT or reached anything that moves.

One thing to be careful about, because the coverage invites the mistake: Iran and China both appear in reporting around this incident, and neither is an attribution. The Iranian reference belongs to a separate string of attacks on US water systems. The Chinese reference belongs to standing Coast Guard bulletins about port cranes. Nobody has attributed this.

What to do: Find out whether your terminal or your vessel has a written fallback for the systems that gate the movement of cargo, and when it was last exercised by the people who would have to run it at two in the morning. A plan nobody has rehearsed is a document, not a capability. North Carolina had both.

Six passengers, one PA system, 3,502 people

In the early hours of Thursday 30 July, MSC Divina was sailing from Marmaris in Turkey towards Naples, on the last leg of a seven-night Eastern Mediterranean cruise.

Six young men, travelling in two cabins, got past the controls on the ship's restricted intercom and public address system. They then broadcast an announcement across public areas on two decks telling passengers that the captain had lost control of the vessel and that the ship was adrift.

The ship carries 3,502 passengers. There was panic.

When Divina reached Naples, officers from the Naples Border Police and the Italian Coast Guard boarded and traced the broadcasts to the six. They were put ashore, and several outlets report they now face charges.

Nobody wrote an exploit. There is no CVE. The PA was described as restricted, and six young men on holiday got into it anyway, because a public address system on a passenger ship is treated as an operational convenience rather than a safety control.

Sit with what that announcement was capable of doing. Three in the morning, three and a half thousand people asleep, and a voice over the speakers saying the master has lost the ship. That is a mass casualty mechanism and it needs no malware at all. You do not fix it with a firewall. You fix it by knowing exactly who can address the ship, and being able to take that away from them inside a minute.

What to do: List every system aboard that can address passengers or crew directly: PA, cabin displays, muster screens, entertainment overlays, digital signage. For each one, answer two questions. Who can reach it, and how fast can we take it away from them. If either answer takes more than a minute to produce, that is the finding.

In case you missed it

  • India held its second National Port Security Conference, with the Ports, Shipping and Waterways Ministry pressing for a technology-led upgrade of port cyber security across a fast-growing portfolio of facilities, framed against the ISPS Code.

  • Senator Tom Cotton wrote to the Treasury Secretary this week asking for investment in modernising American operational technology, naming water systems, power facilities and industrial plants as underfunded and outdated.

Coming up

  • Maritime Security West — San Diego, 31 August to 2 September. Port cyber security, operational technology and Coast Guard cooperation, which is the exact territory of Story 2.

  • DNV Maritime Cybersecurity Summit — Hamburg, 1 September, immediately before SMM Hamburg on 1–4 September.

  • 10th NMIOTC Conference on Cyber Security in the Maritime Domain — Chania, Crete, 23–24 September.

  • Maritime HR & Crew Management Summit — London, 15–16 October. Crew training and human factors. Not usually a cyber event, and after this week's reading that may be the point.

Number of the week

  • 0 (zero) — the number of pieces of equipment a shipowner has to buy to qualify for Sompo's new cover.

Resource of the week

The US Coast Guard Navigation Center GPS Problem Report, and the GUIDE tool that publishes what comes in navcen.uscg.gov

Story 1 creates a question that does not usually come up in a security conversation: if interference stops your ship from working, how do you prove it happened. NAVCEN is where mariners file GPS problem reports, and the GPS Operations Center reviews each one against the constellation, space weather, and any authorised testing in the area. The GUIDE tool then publishes what has been reported and how it was classified.

Read the disclaimer as carefully as the map. The Coast Guard states plainly that these reports do not validate or verify any degradation of the GPS constellation, and that the visualisation is representative only. That is a real limitation. It is also beside the point if what you need is a report filed with somebody outside your company on the day it happened.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"The Checklist Manifesto" by Atul Gawande — a surgeon works out that the difference between a good outcome and a disaster in a complex system is often a piece of paper somebody wrote down in advance and somebody else actually used. North Carolina's ports had that piece of paper and reached for it within hours. The book is about medicine and aviation, and it reads this week like it was written about a container gate.