Coast Guard Warns Shipping Firms of Maritime Cyberattacks

Robert Lemos

A commercial vessel suffered a significant malware attack in February, prompting the US Coast Guard to issues an advisory to all shipping companies: Here be malware.

In February 2019, a large ship bound for New York City radioed the US Coast Guard warning that the vessel was “experiencing a significant cyber incident impacting their shipboard network.” 

The Coast Guard led an incident-response team to investigate the issue and found that malware had infected the ships systems and significantly degraded functionality. Fortunately, essential systems for the control of the vessel were unimpeded.

To continue reading, please click here.

Source: darkreading.com

The MCERT and Lampe & Schwartze launch Maritime Cyber Insurance Partnership

An industry first – Leading marine underwriter Lampe & Schwartze join the advisory board of the Maritime Cyber Emergency Response Team (MCERT) and announce their new Ship Owner’s Marine Cyber Cover (SOMCC) covering exclusion Clause 380.

Leading marine underwriter Lampe & Schwartze has joined the advisory board of the Maritime Cyber Emergency Response Team (MCERT). Today’s announcement took place at a reception for insurance brokers and vessel operators hosted by Lampe & Schwartze at the Hafen Club in Hamburg. Guest speakers included Norton Rose Fulbright, Verein Hanseatischer Transportversicherer (VHT), and from the MCERT, Wärtsilä and Templar Executives.

The MCERT partnership underpins the formal launch of Lampe & Schwartze Marine Unit’s (L&S MU) new Ship Owner’s Marine Cyber Cover (SOMCC) covering exclusion Clause 380, and provides the basis for a joint approach to protect the maritime industry, especially shipowners, from cyber attacks. MCERT is one of the first companies providing a trusted platform for industry wide collaboration on cyber incident reporting and response and sharing of threat intel, especially for the maritime sector.

‘We are delighted to welcome Lampe & Schwartze onto our Advisory Board. This is the culmination of months working together to incorporate MCERT as an integral part of the process for the cyber cover eligibility,’ said Andrew Fitzmaurice, CEO at Templar Executives.

Mark Milford, VP Cyber Security at Wärtsilä added, ‘This exciting partnership with Lampe & Schwartze brings a new dimension and is a great example of how the MCERT is enabling collaboration and adopting solutions by leading industry players for the industry.’

Anu Khurmi who has been leading the MCERT collaboration with Lampe and Schwartze commented, ‘‘At a time when digitisation and automation are shaping the future of the maritime industry, the spectre of cyber attacks is becoming ever more prominent. Marine insurance has a critical role in facilitating and safeguarding international maritime trade especially if it enables best practices in cyber hygiene and resilience throughout the entire ecosystem.  Lampe & Schwartze are leading experts in complex transport and maritime risks, providing highly specialised insurance concepts such as their ground-breaking SOMCC offering’.

‘Our Ship Owner’s Marine Cyber Cover provides certainty in scope of insurance cover and is a standalone insurance policy covering the exclusions of the clause 380 in hull & machinery policies. Our exciting partnership with MCERT will provide international cyber incident reporting and response and ensure due diligence on vessel operators taking out the SOMCC. In addition, the MCERT has a key role in providing daily alerts and global threat intel which will further help in loss prevention and cyber risk mitigations.’  stated Hans-Christoph Enge, Managing Partner of L&S MU.

In case of a claim or incident, a co-operation between the MCERT and Verein Hanseatischer Transportversicherer (VHT), the tried and tested Hull & Machinery Claims Organization of the German Market, will guarantee a combination of technical, nautical and cyber security know-how thus giving a holistic 24/7 response line. The insurance capacity for the cover is provided by renowned German direct insurer and reinsurers.

Source: templarexecs.com

Hack The Sea: Bridging the gap between hackers and the maritime sector

Zeljka Zorz

There’s a not a lot of researchers probing the security of computer systems underpinning the maritime industry.

The limitations that keep that number low are obvious: both the specialized knowledge and equipment is difficult to come by. And, as Ken Munro of UK-based Pen Test Partners told us a year ago, not many people move from shipping into pentesting (and into information security in general).

But things are looking up for those who are interested: at this year’s DEF CON conference in Las Vegas, a maritime hacking village dubbed Hack The Sea will welcome them and offer all kinds of help.

To continue reading, please click here.

Source: .helpnetsecurity.com

New Cyber Security Clause From BIMCO

BIMCO’s Documentary Committee has agreed a new standard Cyber Security Clause that requires the parties to implement cyber security procedures and systems, to help reduce the risk of an incident and mitigate the consequences should a security breach occur.

In the wake of recent costly cyber security incidents involving large shipping companies, cyber security has become a major focus in the maritime industry.

To continue reading, please click here.

Source: hellenicshippingnews.com

New maritime cyber-security centre launched

Zhaki Abdullah

It aims to strengthen security through early detection, monitoring, analysis, response to potential cyber attacks

The Maritime and Port Authority of Singapore (MPA) has a bulwark against cyber attacks with its new Maritime Cybersecurity Operations Centre, launched officially yesterday.

The centre, which has been operating since last November, aims to strengthen Singapore’s maritime security through early detection, monitoring, analysis and response to potential cyber attacks.

To continue reading, please click here.

Source: straitstimes.com

ClassNK Releases Cyber Security Management System for Ships

By Baibhav Mishra

Leading Classification Society ClassNK has released its Cyber Security Management System for Ships.

As part of the ClassNK Cyber Security Series, ClassNK regularly releases guidelines and standards that outline cyber security measures based on the recently-released ClassNK Cyber Security Approach that outlines ClassNK’s basic approach to ensuring onboard cyber security for ships.

To continue reading, please click here.

Source: seanews.co.uk

Naval Dome Cautions Shipping Industry on Cyber Attack

By Baibhav Mishra

The maritime sector is being targeted by highly motivated cyber criminals and the shipping industry should be on the highest alert for a cyber-attack, warned Naval Dome CEO Itai Sela today. 

Speaking at the Singapore Maritime Technology Conference (SMTC) 2019, organised by the Maritime and Port Authority of Singapore, Sela said: “Somebody, somewhere is targeting the maritime sector. The shipping industry should be on Red Alert.”

To continue reading, please click here.

Source: seanews.co.uk

Congress Seen As Failing To Prioritize Maritime Cyber Risks

The United States Coast Guard (USCG) routinely responds to cybersecurity breaches on ships at the same time lawmakers are failing to devote the attention and resources needed to help lessen the threat, according to government officials.

“The problems are very severe,” said John Garamendi, a Democratic congressman from California, speaking on a panel on “Securing Maritime Commerce” at the Brookings Institution in Washington, D.C. this week.

To continue reading, please click here.

Source: benzinga.com

Norsk Hydro cyber attack highlights hacking threat to maritime companies warns Nor-Shipping

This week’s ransomware cyber attack on Norsk Hydro, one of the world’s largest aluminium producers, is a clear demonstration of the growing threat facing firms within the maritime and ocean industries, says Per Martin Tanggaard, Director of Nor-Shipping.

Norsk Hydro computer systems were initially hit by the comparatively new LockerGoga virus on Monday. It then spread through the firm’s network encrypting files. As a result the company, which employs some 36,000 people in 40 countries, was forced to halt production in several plants, switching to increased manual operations to bypass problems connecting to its production systems. LockerGoga works by demanding payment for the decryption of infected files.

To continue reading, please click here.

Source: hellenicshippingnews.com

ABS Launches New Maritime Cybersecurity Risk Assessment Platform

ABS Advanced Solutions (ABS) announced its partnership with SecurityGate, affording the most in-depth cyber risk analysis solution in the maritime market.

The effort integrates the ABS proprietary FCI Cyber Risk™ Methodology into the award-winning SecurityGate SaaS platform, further solidifying the ABS maritime cyber security leadership. The resulting dashboard provides an instant shared view, illustrating the degree of cyber risk across assets, operations and critical suppliers.  

To continue reading, please click here.

Source: maritime-executive.com