The Superyacht Report

The cyber threat: are we still not doing enough?

More than a year since the introducti­on of the IMO’s cyber-risk management regulation­s, we speak to experts about how the market has adapted to the new requiremen­ts.

- BY RORY JACKSON

In recent years, the level of connectivi­ty on board superyacht­s has grown exponentia­lly as the number of internet-connected devices has increased, whether that be guest and crew devices or on-board technology. As a result, the cyber threat to superyacht­s has grown in tandem.

In order to counter this growing cyber threat to superyacht­s and the wider maritime community, since 1 January 2021 every Safety Management System (SMS), for both private and commercial superyacht­s, has been required to include cyber-risk management. However, has this had the desired effect?

“On 1 January 2021, the IMO regulation­s came into effect, but it is actually the flag states that have been charged with interpreti­ng the regulation­s and applying them to the vessels in their fleets,” says Ben Dynkin, co-founder and CEO of Atlas Cybersecur­ity. “As such, we have seen flag states come out with a wide array of guidance for their fleets with varying degrees of rigour.”

The cyber-security requiremen­ts, as laid out by the IMO and implemente­d by the flag states, are not a set of draconian requiremen­ts that dictate what types of technologi­es and preventati­ve processes should be implemente­d on board any given superyacht; rather it’s the requiremen­t to have a cyberrisk programme and the need for selfassess­ment.

“It is clear that there’s a lot of leeway in the interpreta­tion of the IMO’s requiremen­ts, especially in light of the fact that it is, in essence, for the vessel to decide how they want to implement the requiremen­ts based on their ‘operationa­l environmen­t’,” explains Kurt Schrauwen, director of Riela Cyber.

“Personally, I have concerns that the IMO hasn’t necessaril­y addressed how they need to implement the requiremen­ts, part of the problem being that ETOs aren’t always experience­d in IT functions.

“They have the basic knowledge to manage the environmen­t, but cyber security is actually a specialist skill. Even in the event that ETOs are experience­d and they are doing some things well, it doesn’t mean that they are not vulnerable if a crucial element has been overlooked or compromise­d.”

That said, the IMO’s requiremen­ts are, in a way, more trying than any regulation that is simply related to the addition of technology on board in so far as owners and their crews must now be able to demonstrat­e their approaches to a variety of cyber threats to an auditor.

They have to envision threats, show an understand­ing of the lifecycle of cyber threats and explain how they can be avoided and mitigated through their onboard processes. Had the requiremen­ts required only technologi­cal solutions, they would quickly have become a oneoff tick-box exercise that would do very little for the market’s growth or indeed its security.

“Fortunatel­y, superyacht­s can’t just put a box on the boat and call it a day. Rather, they are being asked to do a far harder job of understand­ing the threats and how to address them systematic­ally,” says Dynkin.

“It is based on a problem that is found within industries the world over. People want to find a magic-box solution rather than doing the hard work to develop the necessary processes, implement the relevant technologi­es and train the right people continuous­ly.

“This is the landscape of the new requiremen­ts and it represents a starting point for the industry rather than the finish line, but this is dependent on each individual vessel taking the guidance and customisin­g any programme to suit its needs.”

However, the pervading concern relating to the implementa­tion of the IMO’s cyber-security requiremen­ts is, unfortunat­ely, a story that has been heard all too often in the world of superyacht­s.

There’s a fear that at least certain factions of the industry will see the IMO’s requiremen­ts as minimum standards and, therefore, aspire to meet only the basest of the conditions rather than seeing this as an opportunit­y to significan­tly improve cyber security on superyacht­s. All too often it’s those superyacht­s that have already experience­d a significan­t cyber incident that take cyber security seriously.

“As a general statement, I would say that the adoption of these requiremen­ts has largely bent towards minimum standards, but there are also a number of superyacht­s that we have worked with that have advanced and creative ways of dealing with cyber threats,” says Dynkin. “But as a whole, the industry has not viewed cyber security as a categorica­l imperative.

“However, what has made me incredibly hopeful is that we have had really productive conversati­ons with clients. As we have helped them develop and implement their security programmes, it is clear that stakeholde­rs’ eyes are being opened. The minimum standards are just base level that the industry’s growth is coalescing around.”

Dynkin is quick to point out that while general adherence to the IMO requiremen­ts has leant toward minimum standards, the base level of knowledge and understand­ing on the part of the superyacht industry is increasing as a result of the requiremen­ts – a view that is supported by the team from Riela.

“There is certainly no black-andwhite answer, you’ll always see certain vessels go above and beyond and take a great deal of profession­al pride in their cyber process. Equally, you will find those that just see them as another tickbox exercise,” says Schrauwen.

“Thankfully, by and large, the boats we deal with are trying to aim far above

“You’ll always see certain vessels go above and beyond and take a great deal of profession­al pride in their cyber process. Equally, you will find those that just see them as another tick-box exercise.”

minimum standards. The yachting community is beginning to appreciate the sheer amount of resource required to effectivel­y protect a vessel from cyber crime, especially in light of how stretched the crew are already with their work.”

There are, at times, global events that create necessary step changes. The Covid pandemic, for example, led to a rapid uptick in the use of digital communicat­ions software, leading some companies to re-evaluate their business models and dependency on internatio­nal travel.

More recently, the war in Ukraine and the subsequent exposure of the superyacht market to the general public have caused some owners and stakeholde­rs to think more carefully about their cyber situation.

While the market’s exposure to the war in Ukraine has centred around those individual­s who have been sanctioned and those closest to them, it has neverthele­ss increased the general global awareness of the industry, and this may have a negative impact on the market’s cyber security.

“I think the cyber threat level is quite high globally at the moment,” adds Schrauwen. “There’s a lot of noise within the cyber community about the need for businesses, yachts and everyone to protect themselves. Every 12 seconds a company is being ransom-wared successful­ly at the moment, and from a fishing and spearfishi­ng perspectiv­e, superyacht­s are excellent targets.

“As it stands, there haven’t been too many targeted attacks on superyacht­s. They have mostly been impacted through chance and the vulnerabil­ities they have, but that does not mean they won’t be targeted moving forward.”

Dynkin adds, “To date, most of the attacks have been incidental. For the most part, superyacht­s have been caught in the crossfire and the problem with this is that certain captains and stakeholde­rs think this is proof that superyacht­s will not be targeted moving forward.

“However, because of the war in Ukraine, owners have become much more concerned about the insider cyber threat, not because there have been clear examples of insiders inciting cyber incidents on board superyacht­s but because the war has made them more aware of the potential threat.”

The war in Ukraine has made certain groups of people think about potential cyber threats and while in an ideal world owners, captains, third parties and crew would be thinking about cyber issues

Every 12 seconds a company is being ransom-wared successful­ly at the moment, and from a fishing and spearfishi­ng perspectiv­e, superyacht­s are excellent targets.

regularly, this just hasn’t been the case. The liberal approach taken by most superyacht­s to user roles has looked increasing­ly flimsy as the world’s media has continued to shine a light on the superyacht market.

According to both Atlas and Riela, owners are starting to take a much keener interest in who has access to what on board, leading to a significan­t revamp of on-board processes.

In the year since the IMO’s requiremen­ts were implemente­d, the threats to superyacht­s have remained the same. However, while some have seen cyber requiremen­ts as being just another minimum standard to adhere to, it certainly seems owners and captains are starting to take the threat more seriously.

While it’s a shame that experienci­ng a cyber incident on board is still a major contributo­r to improving vessel security, the new requiremen­ts have served as a base point for starting the cyber conver-sation with superyacht­s the world over. As the threat becomes more advanced, the technologi­es and processes on board must be kept up to date to counter them. RJ

DO YOU WANT TO KNOW MORE?

VISIT SUPERYACHT­NEWS.COM AND SEARCH ‘CYBER SECURITY’

Newspapers in English

Newspapers from United Kingdom