636
10 CONCLUSIONS
This study demonstrates that maritime cybersecurity
should be analysed at the level of interconnected cyber-
physical systems rather than individual devices. Five
recurring vulnerability classes were identified:
communication and positioning, software and
configuration, network and architectural, human and
organisational, and supply-chain and third-party
vulnerabilities.
The proposed cyber-physical framework links these
vulnerabilities with attack vectors, compromised
functions, operational effects and final safety or
business consequences. Its central implication is that
the significance of a technical weakness depends on
functional dependencies and on the extent to which
other maritime systems trust or reuse compromised
information.
Effective maritime cybersecurity therefore requires
a transition from device protection towards system-of-
systems resilience. Defence-in-depth should combine
technical controls with information cross-validation,
human capability, safe operational fallback and
lifecycle governance. These requirements will become
increasingly important as vessels, ports and shore
services become more integrated and autonomous.
ACKNOWLEDGEMENT
The herein study was supported by Gdynia Maritime
University internal grant WN/2026/PZ/07.
REFERENCES
[1] Amro, A., Gkioulos, V.: Cyber risk management for
autonomous passenger ships using threat-informed
defense-in-depth. Int. J. Inf. Secur. 22, 1, 249–288 (2023).
https://doi.org/10.1007/s10207-022-00638-y.
[2] Androjna, A. et al.: AIS Data Vulnerability Indicated by a
Spoofing Case-Study. Applied Sciences. 11, 11, 5015
(2021). https://doi.org/10.3390/app11115015.
[3] Ashfaq Uz Zaman, S.M. et al.: A Review of Automatic
Identification System Approaches for Maritime Cyber
Security. Security and Communication Networks. 2026, 1,
5898106 (2026). https://doi.org/10.1155/sec/5898106.
[4] Ben Farah, M.A. et al.: Cyber Security in the Maritime
Industry: A Systematic Survey of Recent Advances and
Future Trends. Information. 13, 1, 22 (2022).
https://doi.org/10.3390/info13010022.
[5] Bhatti, J., Humphreys, T.E.: Hostile Control of Ships via
False GPS Signals: Demonstration and Detection.
NAVIGATION. 64, 1, 51–66 (2017).
https://doi.org/10.1002/navi.183.
[6] BIMCO, ICS, IUMI, OCIMF, INTERTANKO,
INTERCARGO et al.: The Guidelines on Cyber Security
Onboard Ships. (2024).
[7] Bolbot, V. et al.: A novel cyber-risk assessment method for
ship systems. Safety Science. 131, 104908 (2020).
https://doi.org/10.1016/j.ssci.2020.104908.
[8] Bolbot, V. et al.: Developments and research directions in
maritime cybersecurity: A systematic literature review
and bibliometric analysis. International Journal of Critical
Infrastructure Protection. 39, 100571 (2022).
https://doi.org/10.1016/j.ijcip.2022.100571.
[9] Caprolu, M. et al.: Vessels Cybersecurity: Issues,
Challenges, and the Road Ahead. IEEE Communications
Magazine. 58, 6, 90–96 (2020).
https://doi.org/10.1109/MCOM.001.1900632.
[10] Cichocki, R.: Artificial Intelligence in Maritime
Cybersecurity: Dual-Use Applications for Defense and
Offense in the Age of Digital Seas. TransNav Int. J. Mar.
Navig. Saf. Sea Transp. 19, 2, 617–623 (2025).
https://doi.org/10.12716/1001.19.02.34.
[11] Cichocki, R., Neumann, T.: Cybersecurity challenges and
vulnerabilities of the automatic identification system in
maritime transport. Archives of Transport. 77, 1, 27–43
(2026). https://doi.org/10.61089/aot2026.1jaejy17.
[12] Cichocki, R., Wójcik, P.: Cybersecurity in Maritime
Transport Systems: Threats, Trends, and
Countermeasures in the Last Decade. TransNav Int. J.
Mar. Navig. Saf. Sea Transp. 19, 3, 715–722 (2025).
https://doi.org/10.12716/1001.19.03.03.
[13] Dobryakova, L.A. et al.: GNSS Spoofing Detection Using
Static or Rotating Single-Antenna of a Static or Moving
Victim. IEEE Access. 6, 79074–79081 (2018).
https://doi.org/10.1109/ACCESS.2018.2879718.
[14] Enoch, S.Y. et al.: Novel security models, metrics and
security assessment for maritime vessel networks.
Computer Networks. 189, 107934 (2021).
https://doi.org/10.1016/j.comnet.2021.107934.
[15] Erbas, M. et al.: Systematic literature review of threat
modeling and risk assessment in ship cybersecurity.
Ocean Engineering. 306, 118059 (2024).
https://doi.org/10.1016/j.oceaneng.2024.118059.
[16] Glomsvoll, O., Bonenberg, L.K.: GNSS Jamming
Resilience for Close to Shore Navigation in the Northern
Sea. The Journal of Navigation. 70, 1, 33–48 (2017).
https://doi.org/10.1017/S0373463316000473.
[17] Goudosis, A., Katsikas, S.: Secure Automatic
Identification System (SecAIS): Proof-of-Concept
Implementation. Journal of Marine Science and
Engineering. 10, 6, 805 (2022).
https://doi.org/10.3390/jmse10060805.
[18] Gyamfi, E. et al.: An Adaptive Network Security System
for IoT-Enabled Maritime Transportation. IEEE
Transactions on Intelligent Transportation Systems. 24, 2,
2538–2547 (2023).
https://doi.org/10.1109/TITS.2022.3159450.
[19] Harish, A.V. et al.: Literature review of maritime cyber
security: The first decade. Maritime Technology and
Research. 7, 2, 273805–273805 (2025).
https://doi.org/10.33175/mtr.2025.273805.
[20] International Maritime Organization: Guidelines on
Maritime Cyber Risk Management. IMO, London (2017).
[21] International Maritime Organization: International Code
of Safety for Maritime Autonomous Surface Ships (MASS
Code). IMO, London (2026).
[22] International Maritime Organization: Maritime Cyber
Risk Management in Safety Management Systems. IMO,
London (2024).
[23] Jafarnia-Jahromi, A. et al.: GPS Vulnerability to Spoofing
Threats and a Review of Antispoofing Techniques.
International Journal of Navigation and Observation.
2012, 1, 127072 (2012).
https://doi.org/10.1155/2012/127072.
[24] Jones, K. et al.: Threats and Impacts in Maritime Cyber
Security. Engineering & Technology Reference. 2016,
(2016). https://doi.org/10.1049/etr.2015.0123.
[25] Khandker, S. et al.: Cybersecurity Attacks on Software
Logic and Error Handling Within AIS Implementations:
A Systematic Testing of Resilience. IEEE Access. 10,
29493–29505 (2022).
https://doi.org/10.1109/ACCESS.2022.3158943.
[26] Kurt, Y.B. et al.: A quantitative assessment of human
factors in maritime cybersecurity: an investigation of
seafarers’ knowledge and practices. J Cyber Secur. 12, 1,
tyag015 (2026). https://doi.org/10.1093/cybsec/tyag015.
[27] Kurt, Y.B. et al.: Analysis of human reliability in
detecting GPS spoofing on ECDIS in congested
waterways under evidential reasoning and HEART