YOUR CYBER SECURITY PARTNER
SHIPS
are increasingly using systems that rely on digitisation, integration, and automation, which call for cyber risk management onboard. As technology continues to develop, information technology (IT) and operational technology (OT) onboard ships are being networked together – and more frequently connected to the internet. Cybersecurity Experts say that the ship’s navigational system is easy to intercept giving hackers an incredible opportunity to change the course of a vessel. And the news comes just a few months after researchers have proved that the GPS system of a vessel can be altered to get them into collision with other ships. Cybersecurity is today a priority in the international maritime sector. MITEK looks closely at new requirements which all of us in this industry must now meet. Also, we provide guidance on how to implement cybersecurity in maritime operations. The increasing automation systems will cause decreasing of crew on board and Cyber security will more become a premise for marine operations.
THE NEW MANDATORY CYBERSECURITY REQUIREMENTS FOR ALL SHIP OWNERS
In the face of emerging cybersecurity threats to the industry and with the RESOLUTION MSC.428(98) in mind, IMO has taken the decision to incorporate mandatory cybersecurity requirements into the International Safety Management Code, ISM. As of January 1, 2021, cybersecurity must be addressed by all players in the shipping industry and incorporated into their Safety Management Systems, SMS. One organisation which was quick to respond to these new circumstances was the Oil Companies International Marine Forum, OCIMF. Beginning in January 2018 the OCIMF updated Tanker Management and Self Assessment, TMSA, version 3, with a 13th Performance Element. This new element deals specifically with cybersecurity. What do developments like these mean for the worldwide maritime sector? More specifically, what does the ISM Code, a SOLAS requirement, and TMSA version 3, best industry practice, require when it comes to preventing cyber crime at sea?
Risk Assessment
IMO / OCIMF / Rightship
Risk Control
Security Plan Contigency Plan
Manual / Policy Procedure / Procesdd Instruction / Record
HOW CAN YOU COMPLY WITH THE NEW CYBERSECURITY REQUIREMENTS?
Any business operating under the jurisdiction of the new ISM Code should start planning to update their SMS accordingly. The deadline is no later than the first annual verification of the company’s Document of Compliance following January 1st 2021. For all organizations concerned the message is clear. In order to be prepared and to develop the required business cybersecurity posture, including provisions relating to third party ecosystems, start planning now for the implementation of best-practice. In support of this action IMO has updated it´s guidelines on cybersecurity.
HOW MITeK CAN SUPPORT YOUR COMPANY
MITEK Cyber Security team helps you to analyse the cyber security status of your operational IT and O T system both on board and ashore and to moitigate identified risks. Our comprehensive cyber security solutions include in more detail the followings.
c
j
CYBER INTELLIGENCE
INCIDENT RESPONCE
C
a
FULL SECURITY AUDIT
PENETRATION TESTING
n
6
MONITORING
IMO COMPLIACE
b
f
CYBER SECURITY TRAININGS
SOCIAL ENGINGEERING
NETWORK SEGMENTATION AND PROTECTION
Installation of perimeter firewall between the onboard network and the internet Installation of network switches between each network segment Installation of internal firewalls between each network segment Virtual Local Area Networks (VLAN) to host separate segments. Appropriate network access controls and software firewalls and malware detection. IDEAL NETWORK SOLUTION
Genoa Sicily
Bukarest Naples Malta
27001
MITeK LTD
MALTA MARITIME HUB, Xatt il-Mollijiet, Marsa MRS Malta +39 3930532394 info@mitekltd.com www.mitekcyber .com