THREAT-WATCH logoTHREAT-WATCH

SHIPPING & MARITIME

Cybersecurity for Shipping

Shore offices, fleet systems and the ship-shore link each carry different risks, and NIS2 now treats maritime transport as a high-criticality sector.

Why this sector is different

Greek owners control the largest merchant fleet in the world by deadweight tonnage, and Piraeus and Limassol are among Europe's biggest ship-management hubs. That makes Greek and Cypriot shipping companies a concentrated, high-value target. The attack surface is unusual: a shore office running chartering, crewing and payments, vessels connected by satellite links that keep getting faster, and brokers, agents and bunker suppliers exchanging payment instructions by email every day. Regulation has caught up too. The IMO already expects cyber risk to be managed within each company's Safety Management System, and NIS2 now brings maritime transport companies under national cybersecurity supervision.

Where NIS2 actually lands in shipping

Maritime transport sits in NIS2 Annex I, the high-criticality sectors. Three kinds of organisation are named: sea and coastal passenger and freight water transport companies, managing bodies of ports, and operators of vessel traffic services. Note the wording: the obligations fall on the company, not on each vessel it operates. A large company in scope is an essential entity and a medium one an important entity, on the usual thresholds (50+ staff, or over €10M turnover). In Greece that means registration and supervision under Law 5160/2024, the Article 21 risk-management measures, and a 24-hour early warning when a significant incident hits. Companies below the thresholds are still pulled in through charterers and customers, who increasingly ask for security evidence in contracts. In Cyprus, NIS2 applies through the Security of Networks and Information Systems (Amendment) Law of 2025 (Law 60(I)/2025), which amends Law 89(I)/2020, with the Digital Security Authority (DSA) as the competent authority for Cyprus-based companies.

What coverage looks like across shore and fleet

The shore office is where most real incidents start and where coverage is most complete: endpoint protection, email security and 24/7 monitoring across chartering, crewing, finance and fleet-management systems. Vessels are different. Satellite bandwidth is limited and expensive, onboard systems such as ECDIS and engine control come from makers who restrict what can be installed, and a ship can be days from a technician. So the priority is the ship-shore boundary: who and what can reach a vessel remotely, how that access is controlled, and detection tuned to the traffic crossing it. New ships contracted from July 2024 must also meet IACS unified requirements E26 and E27 on cyber resilience, which gives a baseline to build on. Onboard OT monitoring is scoped vessel by vessel, because fleets rarely share one configuration.

Payment fraud by email

Business email compromise is one of the most common losses in shipping. Attackers sit quietly in a broker's, agent's or supplier's mailbox, then send altered bank details for a hire, freight or bunker payment at exactly the right moment.

Ransomware on shore systems

When chartering, crewing or port-call systems go down, ships keep sailing but the business behind them stops. NotPetya's impact on Maersk in 2017 showed how fast one infection can halt a global operator.

Remote access into vessels

Satellite connectivity has made ships reachable like any branch office. Vendor and support connections into onboard systems are a common, often poorly controlled way in.

GPS and AIS interference

Spoofing and jamming of navigation signals are now routine in several sea areas, including the Eastern Mediterranean and the Black Sea. Crews need procedures for it, and shore teams need to see it in the data.

Talk to us about fleet and shore security

Tell us how your shore office and fleet are set up, and we'll show you where your exposure actually sits.