BIMCO Publishes Improved Cyber Security Guidelines

“The industry will soon be under the obligation to incorporate measures to deal with cyber risks in the ship’s safety management system. This had not been tackled in the previous versions,” says Dirk Fry, chair of BIMCO’s cyber security working group and Director of Columbia Ship Management Ltd.

“The third edition provides additional information which should help shipping companies carry out proper risk assessments and include measures in their safety management systems to protect ships from cyber-incidents. A new dedicated annex provides measures that all companies should consider implementing to address cyber risk management in an approved SMS,” Fry says.

“This is much easier said than done”, he adds and notes that the criminals trying to exploit companies or breach their security are getting more inventive by the minute.

Cyber Security
Image Credits: Fidra Group – Youtube

The new guidelines are the third edition in as many years, which reflects the constantly evolving nature of the risks and challenges.

OT risks differ
A second key expansion in the guidelines is around operational technology. Ships have more and more Operational technology (OT) which is integrated with Information technology (IT) and which can be connected to the internet, but the risks associated with OT are different from IT systems.

For example, malfunctioning IT may cause a significant delay of a ship’s unloading or clearance, but with malfunctioning or inoperative OT there can be a real risk of harm to people, the ship or the marine environment.

“On a ship, the job may be less focused on protecting data while protecting operational systems working in the real world has direct safety implications. If the ECDIS system or software controlling an engine are hit with malware, or if it breaks down due to lack of compatibility after an update of software, it can lead to dangerous situations,” Fry says.

Another new element in the guidelines is a number of examples of actual incidents to demonstrate some of the real-world situations shipowners and operators face. The examples have been anonymized.

According to the Cyber Security Survey by BIMCO, Fairplay and ABS Advanced Solutions, the joint Industry Guidelines on Cyber Security Onboard Ships, are widely used across the industry. The survey also showed industry is more aware of the issue and has increased cyber risk management training, but there remains room for improvement.

Supply chain risks
A third new focus area is the risk of malware infecting the ship’s systems via the many parties associated with the operation of a ship and its systems.

“The ships are not just sitting there in the middle of the ocean. More and more ships are also closely connected to security systems in the companies’ offices and shippers’ offices and agents’ offices,” says Fry.

Advice includes evaluating the security of service providers, defining a minimum set of requirements to manage supply chain or third-party risks and making sure that agreements on cyber risks are formal and written.

The guidelines also underline the need for ships to be able to disconnect quickly and effectively from shore-based networks, where required.

The following organisations produced the third edition: BIMCO, InterManager, International Association of Dry Cargo Shipowners (INTERCARGO), International Association of Independent Tanker Owners (INTERTANKO), International Chamber of Shipping (ICS), International Union of Marine Insurance (IUMI), Oil Companies International Marine Forum (OCIMF) and World Shipping Council (WSC).

The work was supported by
Anglo Eastern, Colombia Ship Management, Maersk Line, Moran Shipping Agencies as well as the cyber security experts NCC, SOFTimpact, Templar Executives and Cyber Keel.

Reference: bimco.org

Disclaimer :
The information contained in this website is for general information purposes only. While we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk.

In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this website.

Disclaimer :
The information contained in this website is for general information purposes only. While we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk.

Do you have info to share with us ? Suggest a correction

About Author

Marine Insight News Network is a premier source for up-to-date, comprehensive, and insightful coverage of the maritime industry. Dedicated to offering the latest news, trends, and analyses in shipping, marine technology, regulations, and global maritime affairs, Marine Insight News Network prides itself on delivering accurate, engaging, and relevant information.

About Author

Marine Insight News Network is a premier source for up-to-date, comprehensive, and insightful coverage of the maritime industry. Dedicated to offering the latest news, trends, and analyses in shipping, marine technology, regulations, and global maritime affairs, Marine Insight News Network prides itself on delivering accurate, engaging, and relevant information.

Article Footer Banner
Article Footer Banner

Subscribe To Our Newsletters

By subscribing, you agree to our Privacy Policy and may receive occasional deal communications; you can unsubscribe anytime.

Web Stories

Leave a Reply

Your email address will not be published. Required fields are marked *