SOC status:Duty analyst on shift

UK Cyber Defence

Sectors · Maritime and logistics

Ships, ports and lorriesdo not stop for a patch window.

Vessel operators, ports and terminals, freight forwarders, hauliers and 3PLs. We watch shore-side IT and the systems that talk to operational technology, test what is exposed from the internet and the quayside, and report in terms a fleet manager understands.

IMO MSC.428(98)ISPS CodeUK MCAMTS-ISAC intelligenceOT and IT

01The threat picture

Disruption is the point: a compromised terminal is measured in reroutings and demurrage.

Ransomware against port operators and logistics platforms — the Anubis intrusion at the Adriatic Port Authority, with its ten-million-dollar demand and weeks of downstream delay, among them — shows how quickly a cyber event becomes a physical one. Access usually comes through the VPN concentrators and remote-management tools used to reach vessels and remote sites, through telematics and terminal operating systems, or through phishing themed on port-community and shipping-line correspondence. GPS and GNSS spoofing at chokepoints, state interest in maritime infrastructure and the compromise of shared vendors round out the picture. Our weekly maritime and logistics report tracks the operators, the vulnerabilities in the equipment the sector actually runs, and the actions that reduce exposure without stopping operations.

Frameworks
IMO cyber risk management in the SMS (MSC.428(98)) · ISPS Code · UK MCA guidance · NIS Regulations for ports
Estate
Vessel OT and SATCOM · terminal operating systems · telematics and routing · warehouse automation · shore-side IT
Intelligence
MTS-ISAC · NCSC · CISA KEV · our own honeypots and IP Insights
Weekly report
Maritime and logistics — every Friday

What we watch for

Where the sector gets hit

01Initial access

Remote-access concentrators

VPN and gateway defects exploited to reach onboard networks, terminals and depots.

02Operations

Terminal and telematics platforms

TOS, fleet-management and routing systems as high-impact targets for extortion.

03OT

Vessel OT and SATCOM

Bridge, engine and communications systems that must be segmented and watched rather than patched.

04BEC

Port-community phishing

Look-alike domains and invoice pretexts aimed at shore-side finance and operations.

05Navigation

GNSS spoofing

Navigation interference at chokepoints; an operational indicator to coordinate with vessel masters, not an IT alert.

06Supply chain

Vendor compromise

Shared software and service providers as the route into many operators at once.

Weekly report

Maritime and logistics threat intelligence

All insights →

Questions

What operators ask us

Can you monitor vessels and remote sites?

We monitor the shore-side and cloud systems and the gateways that reach vessels and sites; for onboard OT we work with your integrators on segmentation and passive visibility rather than agents.

How does this fit with the IMO requirements?

The IMO expects cyber risk to be addressed in the safety management system. The detection, response and testing records SOC365 produces are the evidence that it is.

We are a haulier, not a shipping line. Is this for us?

Yes. Telematics, routing, warehouse systems and customer portals face the same operators; the report and the services cover logistics as well as maritime.

Start a conversation

Keep the cargo moving.

Thirty minutes on your estate, your vendors and where an attacker would start.