pi_circular Operational riskCompliance & regulation American P&I Club
MEMBER ALERT Shipowners Claims Bureau, Inc., Manager One Battery Park Plaza 31 st Fl., New York, NY 10004 USA Tel: +1 212 847 4500 Fa x: +1 212 847 4599 https://www.american-club.com American Club Member Alert – July 10, 2019 1 JULY 10, 2019 USCG MARINE SAFETY ALERT: CYBERSECURITY The US Coast Guard (USCG) has issued a Marine Safety Alert 06-19, Cyber Incident Exposes Potential Vulnerabilities Onboard Commercial Vessels, prompted by a recent cyber malware incident onboard a deep-draft vessel whi ch significantly impacted its shipboard network. In drawing conclusions from its investigation, the USC G noted that this was not just an IT issue, and pointed to cybersecurity as being a fundamental operational imperative in the 21 st century maritime environment. The USC G strongly encourages all vessel and facility owners and operators to conduct cybersecurity assessments to better understand the extent of their cyber vulnerabilities. The USCG Alert, as attached, recommends basic measures shipowners should consider to improve their cybersecurity. Your Managers recommend that Members take note of this information, and be guided accordingly. 1 July 8, 2019 Safety Alert 06-19 Washington, D.C. Cyber Incident Exposes Potential Vulnerabilities Onboard Commercial Vessels In February 2019, a deep draft vessel on an international voyage bound for the Port of New York and New Jersey reported that they were experiencing a significant cyber incident impacting their shipboard network. An interagency team of cyber experts, led by the Coast Guard, responded and conducted an analysis of the vessel’s network and essential control systems. The team concluded that although the malware significantly degraded the functionality of the onboard computer system, essential vessel control systems had not been impacted. Nevertheless, the interagency response found that the vessel was operating without effective cybersecurity measures in place, exposing critical vessel control systems to significant vulnerabilities. Prior to the incident, the security risk presented by the shipboard network was well known among the crew. Although most crewmembers didn’t use onboard computers to check personal email, make online purchases or check their bank accounts, the same shipboard network was used for official business – to update electronic charts, manage cargo data and communicate with shore-side facilities, pilots, agents, and the Coast Guard. It is unknown whether this vessel is representative of the current state of cybersecurity aboard deep draft vessels. However, with engines that are controlled by mouse clicks, and growing reliance on electronic charting and navigation systems, protecting these systems with proper cybersecurity measures is as essential as controlling physical access to the ship or performing routine maintenance on traditional machinery. It is imperative that the maritime community adapt to changing technologies and the changing threat landscape by recognizing the need for and implementing basic cyber hygiene measures. In order to improve the resilience of vessels and facilities, and to protect the safety of the waterways in which they operate, the U.S. Coast Guard strongly recommends that vessel and facility owners, operators and other responsible parties take the following basic measures to improve their cybersecurity: • Segment Networks. “Flat” networks allow an adversary to easily maneuver to any system connected to that network. Segment your networks int
07-10-19 - USCG Marine Safety Alert: Cybersecurity
American P&I Club
Read full article at American P&I Club →
Opens American P&I Club in a new tab