<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Maritime Cyber Security &#8211; Mitek Cyber</title>
	<atom:link href="https://mitekcyber.com/category/maritime-cyber-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://mitekcyber.com</link>
	<description>Maritime Cyber Security</description>
	<lastBuildDate>Mon, 16 Sep 2024 15:52:02 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>

<image>
	<url>https://mitekcyber.com/wp-content/uploads/2019/05/cropped-FAV-32x32.png</url>
	<title>Maritime Cyber Security &#8211; Mitek Cyber</title>
	<link>https://mitekcyber.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>2020: What will change in maritime cyber security</title>
		<link>https://mitekcyber.com/2020-what-will-change-in-maritime-cyber-security/</link>
					<comments>https://mitekcyber.com/2020-what-will-change-in-maritime-cyber-security/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 16 Sep 2024 15:52:02 +0000</pubDate>
				<category><![CDATA[Maritime Cyber Security]]></category>
		<guid isPermaLink="false">http://mitekcyber.com/?p=1710</guid>

					<description><![CDATA[In its latest issue of Be Cyber Aware at Sea, Phish and Ships discusses the upcoming 2020 transition from the perspective of the finalization of cyber security plans by the IMO, which will improve safety communications and e-navigation in the year to come. Namely, the top priority in the following [...]]]></description>
										<content:encoded><![CDATA[<p>In its latest issue of Be Cyber Aware at Sea, Phish and Ships discusses the upcoming 2020 transition from the perspective of the finalization of cyber security plans by the IMO, which will improve safety communications and e-navigation in the year to come.</p>
<p><span id="more-1710"></span><br />
Namely, the top priority in the following year would be the implementation of cyber security measures as vessels are more and more connected and further integrated into corporate IT networks.</p>
<p>In addition, in the new year, shipping companies will assess their risk exposure and develop measures to include in their Safety Management Systems to mitigate cyber threats. The owners are called to not only to be in line with IMO&#8217;s regulations, -coming into force in January 2021- but to also ensure their assets, IT and operational technology is protected from rising cyber threats.</p>
<p>Year 2020 will bring many changes in the spotlight of the shipping industry, highlighted by IMO’s Sub-Committee on Navigation, Communications and Search and Rescue (NCSR) meetings on 13-24 January to discuss progress on modernising the Global Maritime Distress and Safety System (GMDSS) and performance standards for navigational and communication equipment.</p>
<p>The meeting will focus on improving Inmarsat&#8217;s GMDSS services and will continue with the implementation of IMO&#8217;s e-navigation strategy. The sub-committee will discuss the feedback from joint working groups on harmonising aeronautical and maritime search and rescue, and from International Telecommunications Union’s group on maritime radio-communications matters.</p>
<p>2020 will also focus on developing regulations about testing and operating maritime autonomous surface ships (MASS).</p>
<p>One of the first tests for MASS will come in September 2020 when Mayflower Autonomous Ship attempts the world’s first unmanned transatlantic crossing from the UK to Plymouth in the US.</p>
<p><em>Source: safety4sea.com</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://mitekcyber.com/2020-what-will-change-in-maritime-cyber-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Industry publishes updated cyber guidelines for vessels</title>
		<link>https://mitekcyber.com/industry-publishes-updated-cyber-guidelines-for-vessels/</link>
					<comments>https://mitekcyber.com/industry-publishes-updated-cyber-guidelines-for-vessels/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 16 Sep 2024 15:52:02 +0000</pubDate>
				<category><![CDATA[Maritime Cyber Security]]></category>
		<guid isPermaLink="false">http://mitekcyber.com/?p=1717</guid>

					<description><![CDATA[The updated guidance aims to improve the safety and security of seafarers, the environment, the cargo, and the ships and assist in the development of a proper cyber risk management strategy. Specifically, the guidelines aim to assist in the development of a proper cyber risk management strategy in accordance with [...]]]></description>
										<content:encoded><![CDATA[<p>The updated guidance aims to improve the safety and security of seafarers, the environment, the cargo, and the ships and assist in the development of a proper cyber risk management strategy.<br />
<span id="more-1717"></span><br />
Specifically, the guidelines aim to assist in the development of a proper cyber risk management strategy in accordance with relevant regulations and best practises on board a ship with a focus on work processes, equipment, training, incident response and recovery management.</p>
<p>The fourth version takes into consideration the threat as the product of capability, opportunity, and intent, and explains the likelihood of a cyber incident as the product of vulnerability and threat. Thus, the improved risk model offers explanation as to why still relatively few safety-related incidents have unfolded in the maritime industry, but also why this should not be misinterpreted and make shipping companies lower their guard.</p>
<p>The report includes information on why and how cyber risks should be managed in a shipping context. The supporting documentation required to conduct a risk assessment is listed and the risk assessment process is outlined with an explanation of the part played by each component of cyber risk. This publication highlights the importance of evaluating the likelihood and threat in addition to the impact and vulnerabilities when conducting a cyber risk assessment.</p>
<p>Dirk Fry, chair of BIMCO’s cyber security working group and Director of Columbia Ship Management Ltd., commented that</p>
<blockquote><p>Cyber security is an arms race between the attackers and the defenders, where the attacker has the luxury of first choice of weapon. Because we can never be 100% secure in such circumstances, we must extract all the learnings we can from past events. We should be capable of quickly recovering from incidents because we know they will most likely occur at some point. Drawing on the most recent experiences from the industry and beyond, the new version of the guidelines will help us achieve just that.</p></blockquote>
<p>Concluding, the organizations that participated to the production of the fourth edition are BIMCO, Chamber of Shipping of America, Digital Containership Association, International Association of Dry Cargo Shipowners (INTERCARGO), Interferry, International Chamber of Shipping (ICS), INTERMANAGER, International Association of Independent Tanker Owners (INTERTANKO), International Marine Contractors’ Association (IMCA), International Union of Marine Insurance (IUMI), Oil Companies International Marine Forum (OCIMF), Superyacht Builders Association (Sybass), and World Shipping Council (WSC).</p>
<p><a href="https://safety4sea.com/wp-content/uploads/2020/12/BIMCO-Intermanager-IUMI-ICS-Intertanko-Intercargo-OCIMF-The-guidelines-on-cyber-security-onboard-ships-2020_12.pdf" target="_blank" rel="noopener noreferrer"><strong>Read more my clicking here.</strong></a></p>
<p><em>Source: safety4sea.com</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://mitekcyber.com/industry-publishes-updated-cyber-guidelines-for-vessels/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber security enters SMS: A new era from January 2021</title>
		<link>https://mitekcyber.com/cyber-security-enters-sms-a-new-era-from-january-2021/</link>
					<comments>https://mitekcyber.com/cyber-security-enters-sms-a-new-era-from-january-2021/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 16 Sep 2024 15:52:02 +0000</pubDate>
				<category><![CDATA[Maritime Cyber Security]]></category>
		<guid isPermaLink="false">http://mitekcyber.com/?p=1722</guid>

					<description><![CDATA[Every business and every individual can be subject to cyber threats. Cyber-crime is a massive business; hackers are very well-organized, and they put a lot of time and effort before launching a cyber-attack. The last couple years, cyber security has become a significant challenge for the maritime industry as well. [...]]]></description>
										<content:encoded><![CDATA[<p>Every business and every individual can be subject to cyber threats. Cyber-crime is a massive business; hackers are very well-organized, and they put a lot of time and effort before launching a cyber-attack. The last couple years, cyber security has become a significant challenge for the maritime industry as well. In this regard, IMO took the decision to embed cyber security into Safety Management Systems; not much time has left for this new requirement and one thing is for sure: from next year, a new era begins for ship operators.<br />
<span id="more-1722"></span></p>
<p>Even though we have witnessed several cyber attacks during the last years, cyber-criminal activities seem to have increased, exploiting the vulnerability of users working from home. In this context, The Nautical Institute hosted a Cyber Security webinar in November which referred to the new cyber-attack trends. These are the following: malware attacks, encrypted threats, crypto jacking, intrusion attempts, ransomware attacks and IoT malware. So, what shipping players should be doing in order to name themselves as cyber-secured?</p>
<h2><strong>The new IMO Requirement</strong></h2>
<p>According to Resolution MSC.428(98), operators need to ensure that their existing SMS appropriately address cyber risks by their 2021 annual verification. The risks as explained above are too many. With MSC-FAL 1/ Circ 3, IMO provides guidelines which consist of six pages and provide detailed recommendations on maritime cyber risk identification and management to safeguard shipping from current and emerging cyber threats and vulnerabilities.</p>
<p>The recommendations are designed to be incorporated into existing SMS manuals and procedures and associated ISPS systems so as to update and enhance these processes. ‘’The overall goal is to support safe and secure shipping, which is operationally resilient to cyber risks.’’, IMO explains.</p>
<p>In particular, IMO issued “Guidelines on Maritime Cyber Risk Management”, to provide the required guidance on how a Company should respond to MSC. 428 (98), with reference to the following:</p>
<ul>
<li>Guidelines on Cyber Security Onboard Ships issued by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI.</li>
<li>ISO/IEC 27001 standard on Information technology</li>
<li>United States National Institute of Standards and Technology&#8217;s Framework for Improving Critical Infrastructure Cybersecurity (the NIST Framework).</li>
</ul>
<p><strong>Key Items to be addressed</strong></p>
<p>Safety Management System is the key document of every shipping company, explaining how to conduct safe operations, based on the ISM code and the required policies for safe operations, protection of people, ship, cargo and environment. In essence, SMS are dynamic systems, meaning that they need to adapt to new requirements and address current needs and possible risks.</p>
<p>Addressing cyber risks in Safety Management System, requires additional focus, a new approach and more interaction between company and vessels. The real focus point of the system is to achieve the protection of Company (office) and onboard installed systems from cyber threats (of any kind). The aim is to have specific procedures in place and a cyber security culture to minimize the possibility of being attacked or affected by an attack. Additionally, operators can create response technics to overcome challenges from a cyber attack, ensuring continuity of operations.</p>
<p>The new IMO requirements can either addressed as a stand-alone system (Cyber Security Management Plan as part of existing SMS) or a revised SMS which will incorporate all required steps.</p>
<p><strong>Steps required</strong></p>
<ol>
<li>Set the policy for cyber security. This is the base of cyber structure. It is a declaration of Company’s setting targets and main actions for cyber security. It may cover additional items (like General Data protection) as all such items are related.</li>
<li>Conduct a thorough assessment both in office and on-board ships, in order to identify related systems that may be subject to cyber threat. Systems are to be identified, listed, prioritized on vulnerability as critical or not. All systems should be approved to be used for specific tasks. The supportive software should be authentic, updated and installed by competent personnel.</li>
<li>Implement procedures for cyber policy. The procedures should include the actions for everyone related to above identified systems, setting the privileges, the authority levels and specific actions (in form Dos and Don’ts) for each position. Procedures should include as minimum:
<ol>
<li>Privileges and authority, including access level for each system</li>
<li>Password instructions</li>
<li>Removal media instructions</li>
<li>Third party access to systems instructions (eg agents, constructors, system technicians, pilots, terminal personnel and any other individual or organization that requires to be granted access to shore or on board systems)</li>
</ol>
</li>
<li>Set an effective response system. The system should have immediate response actions, backup procedures, rectification procedures and alternative ways of conducting day to day routine in order to retain a flawless operation.</li>
<li>As per shipping industry’s culture, all related incidents should be investigated, and lessons learnt and best practices to be used for avoiding similar issues in the future.</li>
<li>Conduct periodical assessment of systems and procedures through audit / management review in order to check effectiveness.</li>
</ol>
<p><strong>Office/Ship interaction</strong></p>
<p>It is highly recommended to follow the practice of ship shore drills with cyber scenarios. The Guidelines on Cyber Security Onboard Ships produced and supported by BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI, version 4.0 include useful real life incidents that can be used as sample scenarios for such drills.</p>
<p>Additionally as COVID-19 outbreak has altered operations, more and more Companies now use remote inspections and audits to monitor their managed vessels. These actions require procedures that can affectively produce monitoring results but simultaneously protect the systems used to conduct such operations.</p>
<p><strong>Actions required</strong></p>
<p>Ship Managers should:</p>
<ul>
<li>Revise existing SMS to include cyber risk management and related procedures</li>
<li>Verify implementation of policies and procedures both ashore and on board</li>
<li>Provide all required resources for equipment (hardware) and/or software upgrades in order to support procedures</li>
<li>Provide ashore and on-board training to personnel for cyber threats/risks and best practices to address them.</li>
</ul>
<p>Seafarers and Office personnel should:</p>
<ul>
<li>Follow the procedures and guidance on cyber risk management</li>
<li>Do not use personal equipment on Company’s systems (ashore or onboard)</li>
<li>Be aware of all risks and threats related to cyber</li>
<li>Notify immediately authorized Company’s personnel for any suspicious or identified cyber issue in order to initiate response actions.</li>
</ul>
<p>The industry is currently fighting with the thought whether operators are ready or not to comply. One way or another, from January 1st of January 2021, SMS will feature a new requirement, resulting to increased awareness over cyber security which is a critical issue as we have accelerated our path towards digitalization.</p>
<p><em>Source: safety4sea.com</em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://mitekcyber.com/cyber-security-enters-sms-a-new-era-from-january-2021/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
