Cyber Security in the Maritime Sector Threats, Trends and...

24
Cyber Security in the Maritime Sector Threats, Trends and Reality

Transcript of Cyber Security in the Maritime Sector Threats, Trends and...

Page 1: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Cyber Security in the Maritime SectorThreats, Trends and Reality

Page 2: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

*Fear, Uncertainty, Doubt

FUD

Page 3: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

1st ever Maritime Cyber Security Incident was documented thoroughly in 1997

Page 4: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

A computer hacker breaks into the computer system of the Seabourn Legend cruise liner and

sets it speeding on a collision course into a

gigantic oil tanker.Source: IMDB

Page 5: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

•ECDIS Tampering & GPS Spoofing

•Malware Infections (Mostly unintentional)

•Ransomware

•Phishing Attacks / email fraud for money transfers (Biggest case World Fuel Services @ US$15mil)

•Penalties from lack of compliance with legislation (Network Information Security Directive etc)

Threats

Page 6: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Maritime Cyber Threats Who is behind of the mask?

Disgruntled employeeHacktivist

CompetitionIncompetence

Nations

Page 7: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Maritime Cyber Threats Who is behind of the mask?

Willem Dafoe in Speed 2

Page 8: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

$3 trillioncost of a cyber attack to the world economy

43%of crew have sailed on a vessel that had been compromised

by a cyber incident

95%of breaches were caused by human error

90%of crew had never received any cyber security training or guidelines

World Economic Forum, Davos 2015 Crew Connectivity Survey, 2015

Crew Connectivity Survey, 2015 IBM’s 2015 Cyber Security Intelligence Index

Page 9: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Todd James Double AK's, 2015 Lazarides

“Contrary to popular belief, Somali pirates aren’t going to hijack your vessel using cyber

attacks anytime soon”

Page 10: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

• As vessels rely more on Automation systems, and as vessels become more connected, the number of attacks WILL increase.

• Most attacks are kept secret from victims in an effort to avoid reputation problems and potential loss of income.

• There is an increasing trend in uncovering incidents`

• “Maritime Cyber Security” is the new eldorado for PMSCs and Cyber security corporations. Big influx of cyber security firms in the shipping sector inexperienced in the realities of shipping.

Trends

Page 11: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

We are having a deja vu of the 2008 maritime Security Market. However this time all stakeholders are more proactive.

Reality..

Page 12: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

All major shipping associations and organizations, Classification societies, the flags, the insurance market are all proactive in assisting shipowners.

IMO Published draft guidelines in MSC 1/Circ 1526 BIMCO issued Cyber Security guidelines in January

Reality..

Page 13: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

BIMCO’s guidelines focus on seven critical aspects of maritime cyber security:

1. Identifying and understanding cyber security threats to the vessel 2. Assessing risk exposure and the likelihood of being exploited by external

threats 3. Developing protection and detection measures in order to minimize

impact 4. Establishing contingency plans to counter the threat’s impacts 5. Responding to cyber security incidents. 6. Identifying vulnerabilities within the ship’s cyber security measures 7. Creating a Cyber Security Culture through Training

Reality..

Page 14: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

vessel

Page 15: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system
Page 16: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

TIPS

Page 17: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

•Audit ISecGrade Methodology ISO 27001:2013•Vulnerability Assessment•Penetration Test White Box Black Box (Social Engineering – Phishing Attacks) Network / Web / Wireless Penetration Test Mobile Devices Penetration Test

RISK ASSESSMENT

Page 18: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

• Network Security Plan• Secure Server Configuration - Windows - Linux - MacOS• Deploying Policies (ISO 27001 compliant)• Security Plan Implementation

SECURITY PLAN

Page 19: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

• Containment• Eradication & Recovery• Forensics• Reputation Management

INCIDENT RESPONSE

Page 20: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

•Cyber Security Awareness•Hacker Detection for IT Administrators•Emergency Response for IT Administrators•Secure Coding

TRAINING

Page 21: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Security information and event management (SIEM) is an approach to security management that seeks to provide a holistic view of an

organization’s information technology (IT) security.

SIEM

Page 22: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Aspida is first to develop a Vessel Security Information and Event Management System. This service is addressed to shipowners and

management companies wishing to protect their vessels from cyber attacks

VSIEM

Page 23: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

CERTIFICATIONS

Page 24: Cyber Security in the Maritime Sector Threats, Trends and ...cyber.aspida.org/wp-content/uploads/2016/06/aspida_cyber_pres.pdf · A computer hacker breaks into the computer system

Thank you