Journal is indexed in following databases:
- SCOPUS
- Web of Science Core Collection - Journal Citation Reports
- EBSCOhost
- Directory of Open Access Journals
- TRID Database - Transportation Research Board
- Index Copernicus Journals Master List
- BazTech
- Google Scholar
2025 Journal Impact Factor - 0.8
2025 CiteScore - 1.6
ISSN 2083-6473
ISSN 2083-6481 (electronic version)
Editor-in-Chief
Associate Editor
Prof. Tomasz Neumann
Published by
TransNav, Faculty of Navigation
Gdynia Maritime University
3, John Paul II Avenue
81-345 Gdynia, POLAND
e-mail transnav@umg.edu.pl
Cybersecurity Vulnerabilities in Maritime Transport Systems: A System-Oriented Review and Cyber-Physical Vulnerability Framework
1 Gdynia Maritime University, Gdynia, Poland
ABSTRACT: The digital transformation of maritime transport has created a highly interconnected cyber-physical environment in which navigation, communication, propulsion, cargo handling, port operations and shore-based services increasingly depend on software, network connectivity and continuous data exchange. This paper presents a structured review and system-oriented synthesis of cybersecurity vulnerabilities affecting contemporary maritime transport. Based on the reviewed literature, a five-class taxonomy is proposed comprising communication and positioning vulnerabilities, software and configuration vulnerabilities, network and architectural vulnerabilities, human and organisational vulnerabilities, and supply-chain and third-party vulnerabilities. The study further introduces a cyber-physical vulnerability chain linking a technical weakness with an attack vector, compromised maritime function, operational effect and potential safety or business consequence. The analysis indicates that system interdependency and propagation of untrusted information represent key characteristics of maritime cyber risk. Consequently, cybersecurity should move beyond protection of individual devices towards resilience of interconnected ship–shore–port ecosystems. The proposed taxonomy and propagation framework may support maritime cyber-risk assessment and the development of system-specific mitigation strategies.
KEYWORDS: Risk Assessment, Automatic Identification System (AIS), Global Navigation Satellite System (GNSS), Safety and Security in Sea Transportation, Cyber Security, Autonomous Ships, Maritime Cybersecurity, Maritime Information Systems
REFERENCES
Amro, A., Gkioulos, V.: Cyber risk management for autonomous passenger ships using threat-informed defense-in-depth. Int. J. Inf. Secur. 22, 1, 249–288 (2023). - doi:10.1007/s10207-022-00638-y
Androjna, A. et al.: AIS Data Vulnerability Indicated by a Spoofing Case-Study. Applied Sciences. 11, 11, 5015 (2021). - doi:10.3390/app11115015
Ashfaq Uz Zaman, S.M. et al.: A Review of Automatic Identification System Approaches for Maritime Cyber Security. Security and Communication Networks. 2026, 1, 5898106 (2026). - doi:10.1155/sec/5898106
Ben Farah, M.A. et al.: Cyber Security in the Maritime Industry: A Systematic Survey of Recent Advances and Future Trends. Information. 13, 1, 22 (2022). - doi:10.3390/info13010022
Bhatti, J., Humphreys, T.E.: Hostile Control of Ships via False GPS Signals: Demonstration and Detection. NAVIGATION. 64, 1, 51–66 (2017). - doi:10.1002/navi.183
BIMCO, ICS, IUMI, OCIMF, INTERTANKO, INTERCARGO et al.: The Guidelines on Cyber Security Onboard Ships. (2024).
Bolbot, V. et al.: A novel cyber-risk assessment method for ship systems. Safety Science. 131, 104908 (2020). - doi:10.1016/j.ssci.2020.104908
Bolbot, V. et al.: Developments and research directions in maritime cybersecurity: A systematic literature review and bibliometric analysis. International Journal of Critical Infrastructure Protection. 39, 100571 (2022). - doi:10.1016/j.ijcip.2022.100571
Caprolu, M. et al.: Vessels Cybersecurity: Issues, Challenges, and the Road Ahead. IEEE Communications Magazine. 58, 6, 90–96 (2020). - doi:10.1109/MCOM.001.1900632
Cichocki, R., Neumann, T.: Cybersecurity challenges and vulnerabilities of the automatic identification system in maritime transport. Archives of Transport. 77, 1, 27–43 (2026). - doi:10.61089/aot2026.1jaejy17
Dobryakova, L.A. et al.: GNSS Spoofing Detection Using Static or Rotating Single-Antenna of a Static or Moving Victim. IEEE Access. 6, 79074–79081 (2018). - doi:10.1109/ACCESS.2018.2879718
Enoch, S.Y. et al.: Novel security models, metrics and security assessment for maritime vessel networks. Computer Networks. 189, 107934 (2021). - doi:10.1016/j.comnet.2021.107934
Erbas, M. et al.: Systematic literature review of threat modeling and risk assessment in ship cybersecurity. Ocean Engineering. 306, 118059 (2024). - doi:10.1016/j.oceaneng.2024.118059
Glomsvoll, O., Bonenberg, L.K.: GNSS Jamming Resilience for Close to Shore Navigation in the Northern Sea. The Journal of Navigation. 70, 1, 33–48 (2017). - doi:10.1017/S0373463316000473
Goudosis, A., Katsikas, S.: Secure Automatic Identification System (SecAIS): Proof-of-Concept Implementation. Journal of Marine Science and Engineering. 10, 6, 805 (2022). - doi:10.3390/jmse10060805
Gyamfi, E. et al.: An Adaptive Network Security System for IoT-Enabled Maritime Transportation. IEEE Transactions on Intelligent Transportation Systems. 24, 2, 2538–2547 (2023). - doi:10.1109/TITS.2022.3159450
Harish, A.V. et al.: Literature review of maritime cyber security: The first decade. Maritime Technology and Research. 7, 2, 273805–273805 (2025). - doi:10.33175/mtr.2025.273805
International Maritime Organization: Guidelines on Maritime Cyber Risk Management. IMO, London (2017).
International Maritime Organization: International Code of Safety for Maritime Autonomous Surface Ships (MASS Code). IMO, London (2026).
International Maritime Organization: Maritime Cyber Risk Management in Safety Management Systems. IMO, London (2024).
Jafarnia-Jahromi, A. et al.: GPS Vulnerability to Spoofing Threats and a Review of Antispoofing Techniques. International Journal of Navigation and Observation. 2012, 1, 127072 (2012). - doi:10.1155/2012/127072
Jones, K. et al.: Threats and Impacts in Maritime Cyber Security. Engineering & Technology Reference. 2016, (2016). - doi:10.1049/etr.2015.0123
Khandker, S. et al.: Cybersecurity Attacks on Software Logic and Error Handling Within AIS Implementations: A Systematic Testing of Resilience. IEEE Access. 10, 29493–29505 (2022). - doi:10.1109/ACCESS.2022.3158943
Kurt, Y.B. et al.: A quantitative assessment of human factors in maritime cybersecurity: an investigation of seafarers’ knowledge and practices. J Cyber Secur. 12, 1, tyag015 (2026). - doi:10.1093/cybsec/tyag015
Kurt, Y.B. et al.: Analysis of human reliability in detecting GPS spoofing on ECDIS in congested waterways under evidential reasoning and HEART approach. Computers & Security. 151, 104316 (2025). - doi:10.1016/j.cose.2025.104316
Louart, M. et al.: An approach to detect identity spoofing in AIS messages. Expert Systems with Applications. 252, 124257 (2024). - doi:10.1016/j.eswa.2024.124257
Louart, M. et al.: Detection of AIS messages falsifications and spoofing by checking messages compliance with TDMA protocol. Digital Signal Processing. 136, 103983 (2023). - doi:10.1016/j.dsp.2023.103983
Marcos, E.P. et al.: Interference awareness and characterization for GNSS maritime applications. In: 2018 IEEE/ION Position, Location and Navigation Symposium (PLANS). pp. 908–919 (2018). - doi:10.1109/PLANS.2018.8373469
Martínez, F. et al.: Maritime cybersecurity: protecting digital seas. Int. J. Inf. Secur. 23, 2, 1429–1457 (2024). - doi:10.1007/s10207-023-00800-0
Moen, I. et al.: Survey-based analysis of cybersecurity awareness of Turkish seafarers. Int. J. Inf. Secur. 23, 5, 3153–3178 (2024). - doi:10.1007/s10207-024-00884-2
National Institute of Standards and Technology: The NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology, Gaithersburg, MD (2024). - doi:10.6028/NIST.CSWP.29
Nganga, A. et al.: Enabling cyber resilient shipping through maritime security operation center adoption: A human factors perspective. Applied Ergonomics. 119, 104312 (2024). - doi:10.1016/j.apergo.2024.104312
Park, C. et al.: A BN driven FMEA approach to assess maritime cybersecurity risks. Ocean & Coastal Management. 235, 106480 (2023). - doi:10.1016/j.ocecoaman.2023.106480
Sahay, R. et al.: CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships. Future Generation Computer Systems. 100, 736–750 (2019). - doi:10.1016/j.future.2019.05.049
Senarak, C.: Port cybersecurity and threat: A structural model for prevention and policy development. The Asian Journal of Shipping and Logistics. 37, 1, 20–36 (2021). - doi:10.1016/j.ajsl.2020.05.001
Söner, Ö. et al.: Cybersecurity risk assessment of VDR. The Journal of Navigation. 76, 1, 20–37 (2023). - doi:10.1017/S0373463322000595
Svilicic, B. et al.: Assessing ship cyber risks: a framework and case study of ECDIS security. WMU J Marit Affairs. 18, 3, 509–520 (2019). - doi:10.1007/s13437-019-00183-x
Svilicic, B. et al.: Towards a Cyber Secure Shipboard Radar. The Journal of Navigation. 73, 3, 547–558 (2020). - doi:10.1017/S0373463319000808
Symes, S. et al.: Cyberattacks on the Maritime Sector: A Literature Review. J. Marine. Sci. Appl. 23, 4, 689–706 (2024). - doi:10.1007/s11804-024-00443-0
Tam, K. et al.: Quantifying the econometric loss of a cyber-physical attack on a seaport. Front. Comput. Sci. 4, (2023). - doi:10.3389/fcomp.2022.1057507
Tam, K., Jones, K.: MaCRA: a model-based framework for maritime cyber-risk assessment. WMU Journal of Maritime Affairs. 18, 1, 129–163 (2019). - doi:10.1007/s13437-019-00162-2
Tatar, U. et al.: Charting new waters with CRAMMTS: A survey-driven cybersecurity risk analysis method for maritime stakeholders. Computers & Security. 145, 104015 (2024). - doi:10.1016/j.cose.2024.104015
Vasan, D. et al.: Cyber-attacks: Securing ship navigation systems using multi-layer cross-validation defense. Computers & Security. 160, 104706 (2026). - doi:10.1016/j.cose.2025.104706
Weaver, G.A. et al.: Estimating economic losses from cyber-attacks on shipping ports: An optimization-based approach. Transportation Research Part C: Emerging Technologies. 137, 103423 (2022). - doi:10.1016/j.trc.2021.103423
Wimpenny, G. et al.: Securing the Automatic Identification System (AIS): Using public key cryptography to prevent spoofing whilst retaining backwards compatibility. The Journal of Navigation. 75, 2, 333–345 (2022). - doi:10.1017/S0373463321000837
Wolsing, K. et al.: Network Attacks Against Marine Radar Systems: A Taxonomy, Simulation Environment, and Dataset. In: 2022 IEEE 47th Conference on Local Computer Networks (LCN). pp. 114–122 (2022). - doi:10.1109/LCN53696.2022.9843801
Yoo, J., Jo, Y.: Formulating Cybersecurity Requirements for Autonomous Ships Using the SQUARE Methodology. Sensors. 23, 11, 5033 (2023). - doi:10.3390/s23115033
Yousaf, A. et al.: Cyber risk assessment of cyber-enabled autonomous cargo vessel. International Journal of Critical Infrastructure Protection. 46, 100695 (2024). - doi:10.1016/j.ijcip.2024.100695
Yousaf, A. et al.: STPA-Cyber: A semi-automated cyber risk assessment framework for maritime cybersecurity. Computers & Security. 157, 104559 (2025). - doi:10.1016/j.cose.2025.104559
Zhao, Y. et al.: Cybersecurity in smart port systems: A systematic review and data-driven research agenda. Transport Policy. 187, 104268 (2026). - doi:10.1016/j.tranpol.2026.104268
Zheng, H. et al.: Identification of Spoofing Ships from Automatic Identification System Data via Trajectory Segmentation and Isolation Forest. Journal of Marine Science and Engineering. 11, 8, 1516 (2023). - doi:10.3390/jmse11081516
Citation note:
Neumann T.: Cybersecurity Vulnerabilities in Maritime Transport Systems: A System-Oriented Review and Cyber-Physical Vulnerability Framework. TransNav, the International Journal on Marine Navigation and Safety of Sea Transportation, Vol. 20, No. 3, doi:10.12716/1001.20.03.11, pp. 629-637, 2026
Authors in other databases:


56825238000
OSCcDNYAAAAJ