DGMA warns of rising cyberthreats as ports adopt digital technologies, Pg12
DGMA issues advisory warning of escalating cyberthreats to maritime security and port operations due to increasing digital technology adoption and automation.
The Directorate General of Maritime Administration (DGMA) has issued an advisory warning of increasing cyberthreats to ports.
This rise in threats is linked to the growing adoption of digital technologies and automation in port operations.
Cyberthreats pose a significant risk to maritime security and the continuity of port services.
The advisory references the International Ship and Port Facility Security Code regarding new vulnerabilities created by interconnected systems.
Key port systems, including terminal operating systems and vessel traffic management, are identified as vulnerable.
Detailed Insights:
Modern ports' increasing reliance on interconnected Information Technology (IT) and Operational Technology (OT) systems creates new security vulnerabilities.
Cyberattacks can manifest through unauthorized access, malware, ransomware, insecure remote access, and third-party compromises.
The DGMA recommends incorporating cybersecurity risk assessments into the existing Port Facility Security Assessment.
Mitigation measures identified through these assessments should be integrated into the Port Facility Security Plan.
Port authorities are advised to regularly test their backup and recovery arrangements to enhance resilience against cyberattacks.
Port Facility Security Officers (PFSOs) and other security personnel must be aware of cyberattack risks and participate in regular training.
Ports are urged to establish clear procedures for cyber incident reporting, response, containment, and recovery.
Key Concepts Involved:
International Ship and Port Facility Security (ISPS) Code: An international maritime security framework for ships and port facilities.
Information Technology (IT) and Operational Technology (OT): Systems used for data processing and controlling physical processes, respectively, in port operations.
Ransomware: A type of malicious software designed to block access to a computer system or data until a sum of money is paid.
Port Facility Security Officer (PFSO): The person designated responsible for the development, implementation, revision, and maintenance of the port facility security plan.