Navigating the cyber seas

Navigating the cyber seas

Navigating the Cyber Seas – Arcanum’s Insights from LISW 2025

London International Shipping Week 2025 (LISW) brought together maritime leaders, regulators, and cyber security experts to address the evolving digital threats facing the global shipping industry. Neil Hulme, Arcanum’s Senior OT Sales Lead and Jonny Keiller our Senior OT Consultant and Team lead were at the forefront of these discussions, sharing critical findings and recommendations that highlight the urgent need for cyber resilience across maritime operations.

One of the key themes was the implementation of the IMO’s Unified Requirements E26 and E27, which came into force for new vessels contracted from July 2024. These regulations mark a significant shift in maritime cyber governance, focusing on Operational Technology (OT) systems essential to vessel safety. E26 addresses the cyber resilience of the vessel, while E27 targets individual onboard systems. Arcanum emphasised that compliance alone is not enough true resilience requires proactive detection, response, and recovery capabilities built into vessel design and operations.

A major concern raised during LISW was the vulnerability of satellite communications. As vessels increasingly rely on satellite links for navigation, cargo tracking and crew welfare, the threat surface expands. Arcanum highlighted risks such as signal jamming, spoofing and command interference, which could allow attackers to hijack satellite systems or disrupt critical data flows. The maritime sector must adopt layered encryption, real-time monitoring, and international collaboration to safeguard these vital systems.

Ports are also facing increasing demands. The NIS2 Directive, implemented in 2024, broadens cyber security requirements to encompass mid-sized operators and technology providers. Arcanum explained that numerous port authorities remain inadequately prepared to meet the rigorous requirements, which encompass 24-hour incident reporting, disaster recovery planning and comprehensive supply chain risk management. With fines set at up to the greater of €10 million or 2% of global annual revenue, compliance is not optional, it’s essential for operational continuity and national security.

As an ISA/IEC 62443 Expert, Jonny has identified that the maritime sector should adopt IEC 62443 as a cyber security framework to systematically address the growing threats to Operational Technology and industrial control systems onboard vessels and within port infrastructure. By implementing its layered defence-in-depth approach, maritime organisations can enhance risk management, ensure compliance with international standards and protect critical assets from cyberattacks. IEC 62443’s modular structure allows for scalable application across diverse maritime environments, supporting secure integration of legacy systems and modern technologies alike.

Cyber Resilience in a Digitally Transformed Maritime World

Arcanum’s findings also touched on the UK’s Principles-Based Assurance (PBA) framework, developed by the National Cyber Security Centre (NCSC). PBA promotes a risk-based approach, rather than compliance driven approach to cyber assurance. It encourages vendors and operators to demonstrate resilience through structured claims, arguments and evidence, tailored to the maritime threat landscape. This flexible model is especially relevant for technologies like battery systems and hybrid propulsion, which are reshaping vessel architecture.

The move to electrification is accelerating, with over 1,000 battery-powered vessels now in operation globally. While this supports decarbonisation goals, it introduces new cyber risks. Arcanum stressed the importance of securing Energy Storage Systems (ESS) and Onshore Power Supply (OPS) infrastructure, which are vulnerable to software manipulation and remote interference. Without robust cyber controls, electrification could become a double-edged sword.

Digital transformation is another frontier. From smart ships to automated ports, the maritime industry is embracing connectivity but often without adequate cyber safeguards. Arcanum cited research showing that only 17% of shipyards have in-house cyber expertise, and many vessels still operate with outdated software. The lack of secure-by-design principles leaves operators exposed to ransomware, data breaches and navigation failures.

Finally, the EU Data Act, fully applicable from September 2025, adds another layer of complexity. It mandates fair access to data generated by connected devices, including ships and port systems. While this promotes innovation and transparency, it also raises concerns about data sovereignty, cloud security and third-party access. Arcanum urged maritime stakeholders to review their data governance strategies and ensure compliance with the Act’s interoperability and portability requirements.

The importance of Maritime cyber security 

Arcanum’s participation in LISW 2025 conveyed a definitive message: cyber security has evolved from a niche concern to a fundamental strategic priority. As the maritime sector sails into a digitally connected, electrified future, resilience must be built into every layer of operations. From IMO regulations to EU data laws, the tide of compliance is rising. But with the right tools, frameworks, and partnerships, the industry can navigate these waters safely.

Get in touch to find out how we can help secure your organisation.