TL;DR — too long, didn’t read
Five agencies warned about Siemens PLCs, then told you to inventory Siemens PLCs. The advisory says the threat is broader than one vendor and its own action list narrows straight back to that vendor.
A tanker owner reported zero cyber incidents for 2025, and did the work that makes a zero mean something. Most owners who report a zero have not.
The AI Act has applied since 2 August, and the pitches have started. Some of what is being sold as AI Act compliance addresses a different regulation entirely.
Three things that matter this week
It says Siemens. It means all of you.
CISA advisory AA26-231A, 19 August 2026.
Five agencies put their names on it: NSA, CISA, FBI, DOE and EPA. That is unusual enough to be worth noticing on its own. The subject is an active threat to Siemens S7 series programmable logic controllers.
Then the executive summary does something I have not seen done this plainly before. It warns you not to read the title the way you are about to read it:
However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.
That is the authoring agencies telling you, before you have scrolled past the headline, that the vendor name is a sample and not a scope.
And then the first item on the mitigation list reads: Inventory all Siemens S7 Series programmable logic controllers.
I do not think that is carelessness. It is what happens when a warning about a class of equipment has to be written from evidence about one product line. But the effect on a reader is real. The summary widens the problem and the action list narrows it again, and a fleet or terminal engineer skimming for relevance will take the narrower of the two answers, because the narrower answer is the one that fits in the afternoon.
Why this matters for maritime: S7 controllers and their equivalents run the machinery that moves cargo and water. Ship-to-shore and yard cranes. Lock gates and dock gates. Bunkering and fuel transfer skids. Ballast water treatment. Ramp and door hydraulics on ro-ro tonnage. None of that appears in a CISA advisory aimed at industrial control systems generally, which is exactly why the maritime reader concludes it is somebody else's advisory.
The rest of the mitigation list is unremarkable and that is the point: patch, do not expose the controller to the internet, strengthen access control, monitor for unauthorised activity, harden protocols and ladder logic integrity, hunt for anomalies. Nothing there is vendor-specific. It is a description of how to look after a PLC.
What to do: Take the mitigation list and strike the word Siemens out of item one. Then answer the question that remains: how many programmable controllers do you own, of any make, across ships and shore assets, and who can produce that list this week. If the answer requires a phone call to an integrator, you have found the finding before anyone had to attack you. Ask the same question of the equipment you do not own but depend on: the terminal that loads you, the yard that repairs you.
A zero that was earned, and the zeros that are not
Scorpio Tankers reported no material data privacy breaches and no cybersecurity incidents for 2025. Written down like that it is the least interesting sentence in maritime cyber, because it is the sentence everybody writes.
What makes it worth reading is the paragraph around it. There are annual internal and external audits, and penetration tests that cover information technology systems both ashore and on board the vessels. Threat monitoring runs alongside them. A Head of IT Risk and Compliance has direct oversight of data privacy and cybersecurity, and training reaches crew at the pre-joining, onboard and post-assignment stages. An AI policy went in a year ago, in September 2025. The same report also discloses that AI-based computer vision has been extended to 25 ships to support navigation and situational awareness.
A company that pen-tests its onboard systems and then reports zero has said something. A company that reports zero without ever having tested has said nothing at all, in exactly the same words.
The distinction does not show up in the report. It does not show up in the ESG data table, it does not show up in a customer questionnaire, and it will not show up in whatever your charterer asks you next quarter. Both zeros look identical to the person reading them.
Contrast it with ESL Shipping, whose report landed the following day. The Finnish bulk operator describes process rather than score: annual IT risk assessments covering both shore systems and ships, cybersecurity controls written into the Safety Management System, mandatory guidance on the intranet, ISO 27001 certification targeted by the end of this year, and a fleetwide connectivity upgrade treated explicitly as a risk management decision rather than a bandwidth purchase. There is no headline number in it. There is a description of who checks what, and how often.
Why this matters for maritime: this newsletter spent August on the question of how you would find out, and a reported zero is the most comfortable available answer to it. Scorpio's own report, to its credit, does not present the absence of incidents as an endpoint. It places cybersecurity alongside privacy, responsible AI and operational technology as areas needing continuing oversight. That framing is the useful part, and it is the part that gets dropped when the number is quoted somewhere else.
What to do: If you are the one writing the number, put the method next to it in the same sentence: what was tested, by whom, ashore and afloat. If you are the one reading somebody else's number, ask one question before you accept it: what would have had to happen for this figure not to be zero. A supplier who can answer that is describing a control. A supplier who cannot is quoting a sentence somebody wrote for the report.
The AI Act applies to more of you than you think, and less of what is being sold
Regulation (EU) 2024/1689 entered general application on 2 August 2026.
Two things started this month. The obligations, and the sales campaign.
The obligations are real. General application arrived on 2 August, and the penalty tiers are the ones being quoted at you correctly: up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for breaches of operator obligations. Those numbers are accurate, and I have already seen them used accurately in a vendor approach this month.
What follows the numbers is where it goes wrong. In the approach I am thinking of, the proposed remedy was a live inventory of sensitive data across cloud and AI workflows, with redaction and access logs offered as governance evidence. It is a good product. It is not what the AI Act asks for.
The AI Act asks about the system, not the data. Risk classification. Conformity assessment where the use case is high risk. Technical documentation to Annex IV. Human oversight that can actually intervene. Transparency obligations under Article 50. Monitoring after the system is placed on the market. A record of which files a model touched answers a different regulation, and answers it well, but it will not be the thing an assessor asks for.
Why this matters for maritime: the reflex in this industry is that none of it applies, because we do not build AI. Look again at Story 2. One tanker owner has computer vision on 25 ships supporting navigation and situational awareness, and wrote an internal AI policy a year ago. Route and voyage optimisation is standard. Port terminals run analytics over CCTV. Mooring, berthing assistance and engine-room anomaly detection are all shipping in production today. Very little of it was procured under the heading "artificial intelligence", which is precisely why it is missing from the list when somebody asks whether you deploy any.
So the exposure runs in both directions at once. Owners who are certain the Act does not reach them are often deploying systems that it does. And the same owners are being offered compliance for it in the form of a product that addresses something else. Both errors are about scope, and both are comfortable.
What to do: Before you evaluate a single tool, write down every system in your fleet and your shore operation that makes or ranks a decision automatically: navigation, route, maintenance, cargo, access control, crewing, surveillance. That list is the beginning of a risk classification and you can draft it without buying anything. Then, when a vendor tells you their product delivers AI Act compliance, ask which article they mean. The good ones will name one.
In case you missed it
Seven attacks on a virtual ship: COONTEC ran seven live cyberattack scenarios against a virtual vessel testbed, aimed at owners and managers preparing for IACS UR E26. Testbeds are how the newbuild requirements stop being paperwork, and this is the second sign this month that class-driven cyber work is moving from documents to demonstrations.
Connectivity bought as a risk decision: ESL Shipping moved its fleet to multi-channel connectivity, combining low-earth-orbit satellite with mobile networks, and reported it inside the cyber and IT risk programme rather than as a communications upgrade. Where a purchase gets filed says something about who signed it off.
Coming up
BSPC Annual Conference, Lübeck, 30 August. Baltic Sea parliamentary conference with a cyber track. Worth watching for how the Baltic states frame maritime cyber politically rather than technically.
DNV Maritime Cybersecurity Summit, Hamburg, 1 September, and SMM Hamburg opens the same day. The class society running its cyber summit against the week the industry is in town is not an accident.
NMIOTC Conference on Cyber Security in Maritime, Chania, 23 September. Tenth edition, and the call for papers is still open.
World Maritime Day, Panama, 24–25 September. I will be there, running a cyber incident exercise for the Universidad Marítima Internacional de Panamá with MTCC Latin America. Saying so plainly because you should know when the person writing your newsletter has a commercial interest in an event on the calendar.
Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech
Number of the week
25 — ships at one tanker owner now running AI-based computer vision in support of navigation, disclosed in the same report as an unremarkable zero. The industry's working assumption is that it does not deploy artificial intelligence. One company's sustainability report, read carefully, says otherwise about 25 hulls.
Scuttlebutt
Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.
Single-source: A leak site listed Global Terminal Services on 19 August, with a claim of 470 GB taken. GTS operates the Dörtyol terminal on Turkey's Mediterranean coast and describes itself as the largest independent oil storage terminal in the region. Its published service list includes bunkering, transit operations, storage and dangerous cargo handling. If the claim holds, the records at risk are operational as much as commercial. Terminal scheduling, tank allocation and cargo documentation are what tell a tanker where to berth and what she is loading.
Single-source: Channels listed AmSpec on 22 August. AmSpec is a testing, inspection and certification business whose work includes marine fuels and cargo quantity and quality determination. Inspection findings are what cargo and bunker disputes are settled on, which makes the integrity of that data a shared problem for owners, charterers and suppliers who were nowhere near the incident.
Neither has been confirmed by the named party. We will settle both in a future issue, in the usual way: confirmed and graduated, or unconfirmed and dropped.
Resource of the week
Annex III of the EU AI Act, the list that settles whether a system is high risk.
Story 3 asks you to write down every system in your operation that makes or ranks a decision. Annex III is what you check that list against. It runs to eight headings and a page and a half, it is written in plain enough language to read over a coffee, and it is the difference between assuming the Act does not reach you and knowing it.
Two of the headings will matter to most readers here. Critical infrastructure, which covers safety components in the management and operation of critical digital infrastructure, road traffic, and the supply of water, gas, heating and electricity. And employment, which covers systems used in recruitment, task allocation and monitoring of workers. Read them against your bridge, your terminal gate and your crewing system before anybody sells you anything.
Readable version, cross-linked to the recitals: https://artificialintelligenceact.eu/annex/3/ (a reference site, not the official text; for that, the Regulation is 2024/1689 on EUR-Lex).
Want more depth?
Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.
Read of the week
"The Unthinkable: Who Survives When Disaster Strikes and Why" by Amanda Ripley.
Ripley spent years asking why people behave the way they do in fires, floods and collapsing buildings, and the answer that runs through the book is uncomfortable. The first thing most people do in an emergency is not panic. It is nothing. They gather belongings, they finish a phone call, they wait to be told this is real. She calls it the denial phase and it kills people.
I am putting it in an issue about scope for a reason. Every document in this week's newsletter offers a way to spend the denial phase productively: check the vendor name, quote the zero, decide the regulation is for somebody else. The reflex is not stupidity. It is the same reflex that makes a person in a smoke-filled corridor go back for a laptop bag.
There is no maritime chapter. Read it anyway, then look at your muster of who decides what during an incident and ask how much of your first hour is designed for people who do not yet believe it is happening.
