629
1 INTRODUCTION
Maritime transport is undergoing a transition from
relatively isolated electromechanical and electronic
systems towards interconnected digital ecosystems.
Modern vessels and ports increasingly rely on
integrated navigation, satellite communication,
automated machinery, operational technology, cloud
services and continuous ship–shore data exchange.
Although these developments improve efficiency,
situational awareness and automation, they
simultaneously expand the maritime cyberattack
surface [4, 7, 8, 15, 24, 31, 36, 48].
Unlike conventional enterprise information
technology, maritime infrastructures are cyber-
physical systems in which compromised information
may affect physical processes such as navigation,
propulsion, collision avoidance and cargo operations.
Cybersecurity must therefore consider not only
confidentiality, integrity and availability, but also
safety, operational continuity and resilience [7, 12, 15,
40, 48, 49, 55]. Increasing integration further means that
manipulation of one trusted information source may
influence several interconnected systems
simultaneously.
The maritime cybersecurity literature has expanded
considerably during the past decade. Early studies
demonstrated potential attack scenarios against
navigation, propulsion and cargo systems [24].
Subsequent research introduced maritime-specific
Cybersecurity Vulnerabilities in Maritime Transport
Systems: A System-Oriented Review and Cyber-Physical
Vulnerability Framework
T. Neumann
Gdynia Maritime University, Gdynia, Poland
ABSTRACT: The digital transformation of maritime transport has created a highly interconnected cyber-physical
environment in which navigation, communication, propulsion, cargo handling, port operations and shore-based
services increasingly depend on software, network connectivity and continuous data exchange. This paper
presents a structured review and system-oriented synthesis of cybersecurity vulnerabilities affecting
contemporary maritime transport. Based on the reviewed literature, a five-class taxonomy is proposed
comprising communication and positioning vulnerabilities, software and configuration vulnerabilities, network
and architectural vulnerabilities, human and organisational vulnerabilities, and supply-chain and third-party
vulnerabilities. The study further introduces a cyber-physical vulnerability chain linking a technical weakness
with an attack vector, compromised maritime function, operational effect and potential safety or business
consequence. The analysis indicates that system interdependency and propagation of untrusted information
represent key characteristics of maritime cyber risk. Consequently, cybersecurity should move beyond protection
of individual devices towards resilience of interconnected ship–shore–port ecosystems. The proposed taxonomy
and propagation framework may support maritime cyber-risk assessment and the development of system-
specific mitigation strategies.
http://www.transnav.eu
the International Journal
on Marine Navigation
and Safety of Sea Transportation
Volume 20
Number 3
September 2026
DOI: 10.12716/1001.20.03.11
630
risk-assessment frameworks such as MaCRA and
CYRA-MS [7, 48], comprehensive reviews of maritime
cyber threats [4, 8, 15, 19, 31, 46], Bayesian and FMEA-
based approaches [40], survey-driven risk-assessment
methodologies [49], and approaches for autonomous
vessels [55]. Recent research has also placed greater
emphasis on human factors, cyber situational
awareness, smart ports, threat-informed defence and
the propagation of cybersecurity risks between
interconnected systems [26, 27, 33, 37, 50, 56, 57].
Despite this progress, the literature remains
heterogeneous. Some studies focus on individual
technologies such as AIS, GNSS, ECDIS or radar,
whereas others analyse organisational risk,
autonomous ships or port environments. This makes it
difficult to relate a technical vulnerability identified in
one subsystem to its wider operational and safety
consequences. Moreover, a device-centric approach
may underestimate risks created by dependencies
between navigation, communication, automation and
shore-based services.
The regulatory environment is evolving in parallel.
IMO Resolution MSC.428(98) incorporated cyber-risk
management into Safety Management Systems, while
the revised Guidelines on Maritime Cyber Risk
Management provide updated recommendations
covering governance, identification, protection,
detection, response and recovery [20, 22]. Recent IMO
and industry initiatives further indicate a transition
towards more systematic maritime cybersecurity
governance [6, 21].
Accordingly, the study investigates which
vulnerabilities are most relevant to contemporary
maritime systems, how they can be systematically
classified, how compromise can propagate into
operational and safety consequences, and which
defence-in-depth mechanisms can reduce these risks.
The principal contribution of the paper is therefore
not another catalogue of known attacks. Instead, it
proposes a five-class vulnerability taxonomy and
integrates it with a cyber-physical propagation
framework expressed as: Vulnerability, Attack Vector,
Compromised Function, Operational Effect, Safety or
Business Consequence.
This approach shifts attention from individual
devices towards functional dependencies and the
operational consequences of compromised
information or control.
2 MATERIALS AND METHODS
2.1 Research design
The study applies a structured narrative review
combined with a system-oriented qualitative synthesis.
This approach was selected because maritime
cybersecurity research comprises heterogeneous
evidence, including experimental studies, case
analyses, risk-assessment models, surveys and
regulatory guidance. The objective was therefore to
identify recurring vulnerability mechanisms and their
relationships with maritime operational functions
rather than to aggregate quantitative effect sizes.
The literature search, completed in September 2026,
combined maritime-domain terms with cybersecurity
concepts covering ship cybersecurity, navigation-
system vulnerabilities, operational technology,
autonomous vessels, ports and human factors. Peer-
reviewed journal and conference papers were
identified through scholarly publisher platforms and
bibliographic search services, supplemented by
backward and forward citation chaining. Regulatory
and normative sources were obtained from IMO, NIST
and maritime-industry guidance.
The review focused primarily on publications from
2016–2026, while earlier studies were retained where
they provided relevant background, particularly for
GNSS security. Studies were included when they
addressed maritime systems, shipboard IT/OT,
navigation, ports or directly applicable maritime
cybersecurity methods. The final evidence base
comprised 56 references.
2.2 Analytical coding
Each study was analysed according to five attributes:
the affected maritime asset, vulnerability, attack or
exploitation mechanism, compromised maritime
function and potential consequence. Comparison of the
coded vulnerabilities revealed recurring mechanisms
that were consolidated into five classes designated V1–
V5. The classes are not mutually exclusive: a single
system may contain vulnerabilities belonging to
several categories. The taxonomy therefore classifies
the origin of vulnerability rather than assigning entire
systems to individual classes.
2.3 Cyber-physical consequence analysis
A second analytical stage examined how compromise
propagates through interconnected maritime systems.
Because a compromised digital component may
support a safety-critical physical function, the analysis
extends beyond identification of the affected device
and uses the following five-stage chain: Vulnerability,
Attack Vector, Compromised Function, Operational
Effect, Safety or Business Consequence. This structure
distinguishes the technical exploitation mechanism
from its operational and physical consequences.
2.4 Evaluation perspective
The analysis considers confidentiality, integrity,
availability and operational safety. Particular attention
is given to integrity because plausible but incorrect
information may remain unnoticed while directly
influencing human or automated decisions. The
assessment is qualitative rather than probabilistic and
is intended to identify propagation mechanisms that
may subsequently support quantitative or semi-
quantitative approaches such as MaCRA, CYRA-MS,
CRASH, FMEA/BN, CRAMMTS or STPA-Cyber [4, 7,
38, 40, 49, 56].
631
3 MARITIME TRANSPORT AS AN
INTERCONNECTED CYBER-PHYSICAL
ECOSYSTEM
The cybersecurity boundary of a modern vessel
extends beyond the physical ship. Navigation and
control systems interact with satellite infrastructure,
coastal services, company networks, equipment
vendors, ports and cloud providers. Ports are similarly
connected to customs, shipping companies and inland
logistics operators. Maritime cybersecurity is therefore
best considered within an interconnected ship–shore–
port–cloud ecosystem, as illustrated in Figure 1.
Figure 1. Maritime cyberattack surface as an interconnected
ship–shore–port ecosystem.
This interconnection increases the importance of
interfaces and trust relationships. A compromise of a
comparatively non-critical service may enable lateral
movement towards operational systems, while an
uncompromised application may nevertheless
produce unsafe output when it accepts corrupted
information from a trusted source. Consequently,
system dependencies are as important as
vulnerabilities within individual devices.
4 PROPOSED TAXONOMY OF MARITIME
CYBERSECURITY VULNERABILITIES
4.1 V1 – Communication and positioning vulnerabilities
V1 – Communication and positioning vulnerabilities
concern weaknesses in the acquisition or transmission
of maritime information. Representative examples
include unauthenticated AIS communication, GNSS
spoofing and jamming, and insecure wireless or ship–
shore data exchange. Their defining characteristic is
that an attacker may manipulate or deny information
without directly compromising the application that
ultimately processes it [2, 3, 5, 11, 13, 16, 17, 23, 25, 28–
30, 52, 58].
4.2 V2 – Software and configuration vulnerabilities
V2 – Software and configuration vulnerabilities
include obsolete or unsupported software, weak
credentials, insecure default configurations,
unnecessary services, unprotected removable media
and insecure update mechanisms. Long maritime
equipment lifecycles can increase exposure because
updates may require vendor intervention, testing or
operational downtime [43–45, 53].
4.3 V3 – Network and architectural vulnerabilities
V3 – Network and architectural vulnerabilities include
flat networks, insufficient IT/OT separation, insecure
remote access, excessive trust between network zones
and single points of failure. Such weaknesses are
particularly important because they determine
whether compromise remains local or propagates
towards safety-critical systems [9, 14, 18, 41].
4.4 V4 – Human and organisational vulnerabilities
V4 – Human and organisational vulnerabilities include
phishing susceptibility, weak credential practices,
uncontrolled removable media, configuration errors,
insufficient cybersecurity awareness and unclear
responsibilities. Human factors are especially
important in maritime operations because crew
members are both users of digital systems and
potential detectors of corrupted or inconsistent
information [26, 27, 33, 37].
4.5 V5 – Supply-chain and third-party vulnerabilities
V5 – Supply-chain and third-party vulnerabilities arise
from dependence on software suppliers, equipment
manufacturers, cloud providers, remote-maintenance
services and external contractors. Representative
weaknesses include compromised updates, stolen
vendor credentials, insecure remote access and
vulnerable third-party components. These
dependencies extend the effective maritime attack
surface beyond the vessel or port itself [1, 54–56].
5 SYSTEM-SPECIFIC CYBERSECURITY
VULNERABILITIES
5.1 Automatic Identification System
AIS exchanges vessel identity, position, course, speed
and voyage-related information but lacks native source
authentication. This allows potential message injection,
identity spoofing and manipulation of vessel
information, as demonstrated in experimental and case
studies [2, 3, 11, 17, 25, 28, 29, 52, 58].
Proposed countermeasures include cryptographic
authentication, analysis of TDMA behaviour, physical
transceiver characteristics and trajectory anomalies [17,
28, 29, 52, 58]. Since no single mechanism provides
complete protection, practical resilience should
combine AIS-specific detection with independent
observations such as radar and visual information.
5.2 GNSS
GNSS is particularly important because positioning
data are reused by numerous shipboard systems.
Maritime receivers may be affected by interference,
jamming and spoofing, with spoofing posing a
particularly significant integrity problem because false
632
positions can appear plausible to the operator [5, 13, 16,
23, 30].
Resilience therefore requires both attack detection
and independent positioning information. Multiple
displays using the same GNSS source do not provide
genuine information redundancy; radar, inertial
information, visual observations and other
independent measurements are required for effective
cross-validation.
5.3 ECDIS and integrated navigation
ECDIS combines chart information with inputs from
GNSS, AIS and other sensors. Its cybersecurity
therefore depends both on the security of the ECDIS
platform and on the integrity of upstream data.
Software vulnerabilities, removable media and
insecure configurations may compromise the platform
[44], while falsified GNSS or AIS data may create an
incorrect navigational picture even when ECDIS itself
remains uncompromised.
5.4 Radar and ARPA
Modern marine radar is a networked digital system
and may itself be affected by software and network
vulnerabilities [45, 53]. At the same time, radar
provides an independent physical sensing principle
and therefore plays an important defensive role in
validating GNSS and AIS information. Loss of radar
integrity may consequently both compromise
situational awareness and remove an important cross-
checking mechanism.
5.5 Voyage Data Recorder
VDR cybersecurity is relevant both to operational data
and to post-incident investigation. Network or
software compromise may alter or remove recorded
information, demonstrating that integrity protection is
also necessary for systems supporting accountability
and forensic analysis [43].
5.6 Shipboard networks and operational technology
Shipboard OT supports propulsion, electrical power,
steering, ballast and cargo operations and often
contains long-lived systems with legacy software or
protocols. Because immediate patching may conflict
with operational availability and certification
requirements, network segmentation, monitoring and
controlled maintenance are particularly important for
limiting the propagation of compromise.
5.7 Satellite communications and external connectivity
Satellite communication systems provide external
connectivity for operational data, remote services and
crew communications, but exposed interfaces, weak
credentials or inadequate segmentation may create an
entry point to internal networks. The main risk
therefore depends not only on compromise of the
communication terminal itself, but on whether the
architecture permits subsequent lateral movement.
5.8 Autonomous and remotely operated vessels
Autonomous and remotely operated vessels increase
dependence on sensors, communication links, software
and shore-based control. Cyber-risk studies
consequently identify navigation, propulsion,
communications and remote-control functions as
important attack paths [1, 7, 54–56]. Reduced onboard
human intervention further increases the importance
of integrating cybersecurity with functional safety.
5.9 Ports and terminal infrastructure
Ports combine enterprise IT, industrial control,
automated equipment and extensive external data
exchange. Disruption of TOS, PCS, gate systems or
other central platforms may stop physical cargo flows
without directly damaging handling equipment [42,
47, 51, 57]. Port cyber resilience must therefore
encompass both restoration of information systems
and continuity or safe degradation of logistics
operations.
6 CYBER-PHYSICAL PROPAGATION OF
MARITIME CYBER INCIDENTS
The proposed framework extends vulnerability
analysis beyond the compromised device by
examining the operational functions that depend on it.
As illustrated in Figure 2, the analysis follows the
sequence Vulnerability, Attack Vector, Compromised
Function, Operational Effect, Safety or Business
Consequence.
Figure 2. Proposed maritime cyber-physical vulnerability
chain.
GNSS spoofing illustrates this propagation
particularly clearly. Acceptance of counterfeit signals
may compromise positioning, leading to an incorrect
vessel position that is subsequently used by ECDIS,
track-control functions or bridge personnel, potentially
contributing to navigational deviation, grounding or
collision. Equivalent propagation chains may be
constructed for AIS manipulation, machinery-network
intrusion or ransomware affecting port information
systems.
The key implication is that cyber-risk severity
depends on functional dependency rather than solely
on the technical sophistication of an attack. In
navigation, plausible but corrupted information may
be particularly hazardous because it can continue to
influence human or automated decisions while the
system appears operational.
633
Table 1. System-oriented mapping of maritime cybersecurity vulnerabilities
Maritime asset or
function
Vulnerability
class
Representative
attack vector
Primary security
property affected
Possible operational
effect
Potential wider
consequence
AIS
V1
Message injection,
identity spoofing,
replay
Integrity
False traffic
information
Incorrect
navigational
assessment
GNSS receiver
V1
Jamming, spoofing
Availability /
integrity
Loss or falsification of
position
Route deviation,
grounding or
collision risk
ECDIS
V1/V2
Malware,
compromised
update, falsified
input
Integrity /
availability
Incorrect navigational
picture
Navigational error
Radar/ARPA
V2/V3
Network attack,
malware, DoS
Integrity /
availability
Degraded target
information
Reduced collision-
avoidance capability
INS/IBS
V1/V3
Sensor
manipulation,
lateral movement
Integrity
Multi-system
propagation
Systemic loss of
bridge situational
awareness
VDR
V2/V3
Malware,
unauthorised access
Integrity /
availability
Loss or alteration of
recorded data
Reduced forensic
capability
Autopilot / track
control
V1/V3
False input, control
manipulation
Integrity
Incorrect course
control
Route deviation or
collision risk
Dynamic
positioning
V1/V3
GNSS spoofing,
sensor
manipulation
Integrity /
availability
Loss of position
keeping
Collision or offshore
operational incident
SATCOM/VSAT
V2/V3
Credential attacks,
exposed services
Confidentiality /
availability
Communication
compromise
Entry point to
internal network
Shipboard Wi-Fi
V3
Credential
compromise,
unauthorised access
Confidentiality /
availability
Network penetration
Lateral movement
Machinery
automation
V2/V3
Malware,
unauthorised
commands
Availability /
integrity
Machinery
malfunction
Loss of propulsion or
power
Steering control
V2/V3
Network intrusion,
logic manipulation
Integrity /
availability
Steering disruption
Loss of
manoeuvrability
Cargo control
V2/V3
Malware,
ransomware
Availability /
integrity
Cargo-operation
disruption
Safety and
commercial losses
Ballast systems
V2/V3
Unauthorised
control
Integrity
Incorrect ballast
condition
Stability or
operational problems
Remote
maintenance
V3/V5
Stolen vendor
credentials
Integrity /
confidentiality
External access to
technical systems
Lateral movement
into critical zones
Software updates
V2/V5
Compromised
update
Integrity
Deployment of
malicious software
Fleet-wide
compromise
potential
TOS
V2/V3
Ransomware,
credential
compromise
Availability
Terminal slowdown
or shutdown
Supply-chain
disruption
PCS
V3/V5
Web attacks,
credential theft
Integrity /
availability
Documentation or
coordination failure
Delayed cargo flows
VTS
V1/V3
Data manipulation,
DoS
Integrity /
availability
Degraded traffic
monitoring
Reduced waterway
safety
Port IoT
V2/V5
Device takeover,
credential attacks
Integrity /
availability
False measurements
Operational
disruption
Cloud fleet
platform
V2/V5
Account takeover,
API abuse
Confidentiality /
integrity
Data modification or
leakage
Multi-vessel
organisational
impact
Remote-control
centre
V3/V5
Network intrusion,
DoS
Integrity /
availability
Loss of remote
supervision/control
Autonomous-vessel
safety impact
7 DEFENCE-IN-DEPTH AND MARITIME CYBER
RESILIENCE
Maritime cyber risk occurs across technical,
organisational and operational layers and therefore
requires a defence-in-depth approach, as summarised
in Figure 3 and Table 2. Governance establishes
responsibility, asset visibility and supplier oversight,
while preventive controls such as segmentation, secure
configuration and access management reduce
opportunities for compromise and lateral movement.
Maritime environments additionally require
mechanisms for validating operational information.
Cross-checking between GNSS, radar, inertial data,
AIS and other independent sources can help identify
manipulated navigation data even when the initial
attack cannot be prevented [34, 50]. Monitoring should
therefore combine conventional IT/OT security
indicators with physical and navigational anomalies.
Response and recovery must also account for
operational safety. Disconnecting a compromised
system may itself introduce hazards, making safe
634
degradation, manual fallback, tested backups and
coordinated ship–shore response essential elements of
maritime cyber resilience.
Figure 3. Defence-in-depth model for maritime cyber
resilience.
Table 2. Defence-in-depth controls mapped to maritime
vulnerability classes and operational objectives
Control
domain
Principal maritime
implementation
V1
V2
V3
V4
V5
Main
operational
objective
Cyber
governance
Cyber risk integrated
with SMS and
organisational risk
management
✓
✓
✓
✓
✓
Consistent risk
ownership
Asset inventory
Identification of IT,
OT, sensors,
software and
external
dependencies
✓
✓
✓
Visibility of
attack surface
Network
segmentation
Separation of bridge,
machinery,
administrative, crew
and passenger
networks
✓
Limitation of
lateral
movement
Access control
Unique accounts,
least privilege and
account lifecycle
management
✓
✓
✓
✓
Prevention of
unauthorised
access
Multi-factor
authentication
Protection of shore,
cloud and remote-
maintenance access
✓
✓
✓
✓
Reduction of
credential risk
Secure
configuration
Removal of default
credentials and
unnecessary services
✓
✓
Reduction of
exploitable
exposure
Patch
management
Controlled and
tested update
processes
✓
✓
Reduction of
known
vulnerabilities
Software-
update
validation
Cryptographic and
procedural
verification of
updates
✓
✓
Supply-chain
integrity
Remote-access
control
Time-limited vendor
access, monitoring
and approval
✓
✓
✓
Control of third-
party
connectivity
GNSS
resilience
Multi-source PNT,
interference
detection and
fallback navigation
✓
✓
Maintenance of
trustworthy
position
AIS verification
Radar correlation,
trajectory
plausibility and
source-
✓
✓
Integrity of
maritime traffic
picture
authentication
mechanisms
Cross-sensor
validation
Comparison of
GNSS, INS, radar,
speed, depth and
other measurements
✓
✓
✓
Detection of
manipulated
navigation data
IT/OT
monitoring
Network IDS, logs
and protocol-aware
monitoring
✓
✓
Early attack
detection
Cyber
situational
awareness
Presentation of
actionable cyber
information to ship
and shore personnel
✓
✓
✓
✓
Improved
decision-making
Removable-
media
management
Scanning and
controlled use of
USB and
maintenance media
✓
✓
✓
Prevention of
malware
introduction
Crew training
Scenario-based
phishing, navigation
and cyber-incident
exercises
✓
✓
✓
✓
Human
detection and
response
capability
Cyber range
exercises
Simulation of cyber-
physical maritime
scenarios
✓
✓
✓
✓
Preparation
without
operational risk
Backup and
restoration
Offline or protected
backups and tested
recovery
✓
✓
✓
✓
Reduction of
downtime
Manual
fallback
Ability to navigate
or operate safely
during digital-
system degradation
✓
✓
✓
Operational
resilience
Supplier
security
Cybersecurity
requirements,
disclosure and
maintenance
obligations
✓
✓
✓
Lifecycle and
supply-chain
resilience
Incident
reporting
Structured ship–
shore escalation and
information sharing
✓
✓
✓
✓
✓
Faster
containment and
organisational
learning
8 DISCUSSION
8.1 From device cybersecurity to system-of-systems
resilience
Existing maritime cybersecurity research frequently
analyses vulnerabilities within individual component
boundaries, whereas operational systems depend on
shared information and interconnected functions.
GNSS, AIS, ECDIS, radar and control systems
participate in a common decision environment,
meaning that compromise of a trusted information
source may be sufficient to affect several downstream
functions.
The proposed framework makes this propagation
explicit and complements rather than replaces existing
risk-assessment methods. MaCRA provides a model-
based maritime risk framework [48], CYRA-MS links
vulnerabilities and attack scenarios to ship systems [7],
Bayesian/FMEA approaches address uncertainty [40],
CRAMMTS incorporates stakeholder assessment [49],
and STPA-Cyber supports system-level risk modelling
[56]. The present approach provides a preliminary
functional layer linking vulnerability origin with
operational and safety consequences.
635
8.2 Information integrity, redundancy and diversity
Maritime navigation depends particularly strongly on
data integrity. Loss of information is often immediately
observable, whereas plausible but manipulated GNSS
or AIS data may continue to influence decisions
without generating an obvious failure condition.
Cybersecurity should therefore consider not only data
availability but also provenance, confidence and cross-
source consistency.
This distinction also affects the concept of
redundancy. Two systems receiving information from
the same compromised source provide equipment
redundancy but not information resilience. Cyber-
resilient navigation consequently requires diversity of
measurement principles, combining satellite, radar,
inertial, visual and other independent information.
This becomes increasingly important as autonomous
systems rely more heavily on automated sensor fusion.
8.3 Human element as an adaptive defence layer
Human operators represent both a potential source of
vulnerability and an adaptive layer of cyber resilience
[26, 27, 32, 33, 37, 56]. Seafarers may introduce risk
through phishing, weak credentials or removable
media, but experienced navigators may also recognise
inconsistencies between digital information and the
physical environment.
Research on GPS spoofing detection indicates that
such recognition is not guaranteed and depends on
workload and human reliability [27]. Maritime
cybersecurity training should therefore extend beyond
generic awareness towards simulator-based scenarios
involving misleading but apparently functional
systems, cross-checking of independent information
and safe fallback procedures.
8.4 IT/OT lifecycle and supply-chain security
Maritime OT illustrates the limitations of directly
transferring enterprise-IT security practices to safety-
critical systems. Rapid patching or isolation may not
always be possible where availability, certification and
operational continuity are critical. Cybersecurity
controls should therefore be lifecycle-oriented,
combining segmentation, monitoring and controlled
maintenance with secure update mechanisms.
The same lifecycle perspective must include
suppliers. Remote maintenance, cloud services and
vendor software make third parties part of the effective
vessel architecture. Cybersecurity requirements
concerning authentication, remote access, vulnerability
disclosure, update integrity and end-of-life support
should therefore be incorporated into procurement
and supplier governance [6, 35].
8.5 Smart ports and systemic consequences
Port cybersecurity demonstrates that cyber incidents
may generate physical and economic consequences
without directly damaging operational equipment.
Loss of information required to identify containers,
allocate resources or coordinate movements may
interrupt cargo flows even when cranes and vehicles
remain functional [47, 51]. Cyber-physical
consequences may also propagate beyond the port to
shipping, road and rail networks, illustrating the
systemic nature of maritime cyber risk.
8.6 Autonomous shipping, regulations and research
implications
Autonomous shipping intensifies the dependencies
identified throughout this study because perception,
decision-making and control increasingly rely on
sensors, software, communication links and remote
operators. Cybersecurity consequently becomes
closely linked to functional safety: future assurance
should consider not only normal system performance
but also behaviour under manipulated data,
communication loss and compromised external
services [1, 39, 50, 56].
The regulatory framework is evolving in the same
direction. IMO cyber-risk guidance and the integration
of cybersecurity into Safety Management Systems
indicate a transition from treating cyber threats as an
IT problem towards broader operational-risk
governance [20, 22]. The MASS Code further increases
the relevance of cybersecurity assurance for
autonomous and remotely operated vessels [21].
Future research should place greater emphasis on
cross-system attack propagation and quantitative
assessment of information trust. Maritime digital twins
may provide safe environments for testing cyber-
physical attack scenarios, while sensor-consistency
models could support dynamic estimation of
confidence in navigation information.
Artificial intelligence may improve anomaly
detection but also introduces new attack surfaces
involving adversarial inputs, compromised models
and corrupted training data [10]. Cybersecurity
assurance for future maritime systems will therefore
need to address both conventional software
vulnerabilities and the integrity of increasingly
autonomous decision processes.
9 LIMITATIONS
This study has several limitations. First, it is a
structured narrative review and qualitative synthesis
rather than a quantitative meta-analysis. The proposed
V1–V5 taxonomy intentionally simplifies a complex
environment, and individual incidents may involve
vulnerabilities belonging to several classes
simultaneously. Likewise, the cyber-physical
propagation chains describe credible causal paths
rather than probabilities or quantified risk levels.
The evidence base is also constrained by limited
public disclosure of vulnerabilities in operational
maritime systems, while rapidly changing technology,
regulations and attack techniques may affect the
continued applicability of individual findings. The
proposed framework should therefore be treated as an
extensible analytical structure rather than a static
catalogue.
636
10 CONCLUSIONS
This study demonstrates that maritime cybersecurity
should be analysed at the level of interconnected cyber-
physical systems rather than individual devices. Five
recurring vulnerability classes were identified:
communication and positioning, software and
configuration, network and architectural, human and
organisational, and supply-chain and third-party
vulnerabilities.
The proposed cyber-physical framework links these
vulnerabilities with attack vectors, compromised
functions, operational effects and final safety or
business consequences. Its central implication is that
the significance of a technical weakness depends on
functional dependencies and on the extent to which
other maritime systems trust or reuse compromised
information.
Effective maritime cybersecurity therefore requires
a transition from device protection towards system-of-
systems resilience. Defence-in-depth should combine
technical controls with information cross-validation,
human capability, safe operational fallback and
lifecycle governance. These requirements will become
increasingly important as vessels, ports and shore
services become more integrated and autonomous.
ACKNOWLEDGEMENT
The herein study was supported by Gdynia Maritime
University internal grant WN/2026/PZ/07.
REFERENCES
[1] Amro, A., Gkioulos, V.: Cyber risk management for
autonomous passenger ships using threat-informed
defense-in-depth. Int. J. Inf. Secur. 22, 1, 249–288 (2023).
https://doi.org/10.1007/s10207-022-00638-y.
[2] Androjna, A. et al.: AIS Data Vulnerability Indicated by a
Spoofing Case-Study. Applied Sciences. 11, 11, 5015
(2021). https://doi.org/10.3390/app11115015.
[3] Ashfaq Uz Zaman, S.M. et al.: A Review of Automatic
Identification System Approaches for Maritime Cyber
Security. Security and Communication Networks. 2026, 1,
5898106 (2026). https://doi.org/10.1155/sec/5898106.
[4] Ben Farah, M.A. et al.: Cyber Security in the Maritime
Industry: A Systematic Survey of Recent Advances and
Future Trends. Information. 13, 1, 22 (2022).
https://doi.org/10.3390/info13010022.
[5] Bhatti, J., Humphreys, T.E.: Hostile Control of Ships via
False GPS Signals: Demonstration and Detection.
NAVIGATION. 64, 1, 51–66 (2017).
https://doi.org/10.1002/navi.183.
[6] BIMCO, ICS, IUMI, OCIMF, INTERTANKO,
INTERCARGO et al.: The Guidelines on Cyber Security
Onboard Ships. (2024).
[7] Bolbot, V. et al.: A novel cyber-risk assessment method for
ship systems. Safety Science. 131, 104908 (2020).
https://doi.org/10.1016/j.ssci.2020.104908.
[8] Bolbot, V. et al.: Developments and research directions in
maritime cybersecurity: A systematic literature review
and bibliometric analysis. International Journal of Critical
Infrastructure Protection. 39, 100571 (2022).
https://doi.org/10.1016/j.ijcip.2022.100571.
[9] Caprolu, M. et al.: Vessels Cybersecurity: Issues,
Challenges, and the Road Ahead. IEEE Communications
Magazine. 58, 6, 90–96 (2020).
https://doi.org/10.1109/MCOM.001.1900632.
[10] Cichocki, R.: Artificial Intelligence in Maritime
Cybersecurity: Dual-Use Applications for Defense and
Offense in the Age of Digital Seas. TransNav Int. J. Mar.
Navig. Saf. Sea Transp. 19, 2, 617–623 (2025).
https://doi.org/10.12716/1001.19.02.34.
[11] Cichocki, R., Neumann, T.: Cybersecurity challenges and
vulnerabilities of the automatic identification system in
maritime transport. Archives of Transport. 77, 1, 27–43
(2026). https://doi.org/10.61089/aot2026.1jaejy17.
[12] Cichocki, R., Wójcik, P.: Cybersecurity in Maritime
Transport Systems: Threats, Trends, and
Countermeasures in the Last Decade. TransNav Int. J.
Mar. Navig. Saf. Sea Transp. 19, 3, 715–722 (2025).
https://doi.org/10.12716/1001.19.03.03.
[13] Dobryakova, L.A. et al.: GNSS Spoofing Detection Using
Static or Rotating Single-Antenna of a Static or Moving
Victim. IEEE Access. 6, 79074–79081 (2018).
https://doi.org/10.1109/ACCESS.2018.2879718.
[14] Enoch, S.Y. et al.: Novel security models, metrics and
security assessment for maritime vessel networks.
Computer Networks. 189, 107934 (2021).
https://doi.org/10.1016/j.comnet.2021.107934.
[15] Erbas, M. et al.: Systematic literature review of threat
modeling and risk assessment in ship cybersecurity.
Ocean Engineering. 306, 118059 (2024).
https://doi.org/10.1016/j.oceaneng.2024.118059.
[16] Glomsvoll, O., Bonenberg, L.K.: GNSS Jamming
Resilience for Close to Shore Navigation in the Northern
Sea. The Journal of Navigation. 70, 1, 33–48 (2017).
https://doi.org/10.1017/S0373463316000473.
[17] Goudosis, A., Katsikas, S.: Secure Automatic
Identification System (SecAIS): Proof-of-Concept
Implementation. Journal of Marine Science and
Engineering. 10, 6, 805 (2022).
https://doi.org/10.3390/jmse10060805.
[18] Gyamfi, E. et al.: An Adaptive Network Security System
for IoT-Enabled Maritime Transportation. IEEE
Transactions on Intelligent Transportation Systems. 24, 2,
2538–2547 (2023).
https://doi.org/10.1109/TITS.2022.3159450.
[19] Harish, A.V. et al.: Literature review of maritime cyber
security: The first decade. Maritime Technology and
Research. 7, 2, 273805–273805 (2025).
https://doi.org/10.33175/mtr.2025.273805.
[20] International Maritime Organization: Guidelines on
Maritime Cyber Risk Management. IMO, London (2017).
[21] International Maritime Organization: International Code
of Safety for Maritime Autonomous Surface Ships (MASS
Code). IMO, London (2026).
[22] International Maritime Organization: Maritime Cyber
Risk Management in Safety Management Systems. IMO,
London (2024).
[23] Jafarnia-Jahromi, A. et al.: GPS Vulnerability to Spoofing
Threats and a Review of Antispoofing Techniques.
International Journal of Navigation and Observation.
2012, 1, 127072 (2012).
https://doi.org/10.1155/2012/127072.
[24] Jones, K. et al.: Threats and Impacts in Maritime Cyber
Security. Engineering & Technology Reference. 2016,
(2016). https://doi.org/10.1049/etr.2015.0123.
[25] Khandker, S. et al.: Cybersecurity Attacks on Software
Logic and Error Handling Within AIS Implementations:
A Systematic Testing of Resilience. IEEE Access. 10,
29493–29505 (2022).
https://doi.org/10.1109/ACCESS.2022.3158943.
[26] Kurt, Y.B. et al.: A quantitative assessment of human
factors in maritime cybersecurity: an investigation of
seafarers’ knowledge and practices. J Cyber Secur. 12, 1,
tyag015 (2026). https://doi.org/10.1093/cybsec/tyag015.
[27] Kurt, Y.B. et al.: Analysis of human reliability in
detecting GPS spoofing on ECDIS in congested
waterways under evidential reasoning and HEART
637
approach. Computers & Security. 151, 104316 (2025).
https://doi.org/10.1016/j.cose.2025.104316.
[28] Louart, M. et al.: An approach to detect identity spoofing
in AIS messages. Expert Systems with Applications. 252,
124257 (2024). https://doi.org/10.1016/j.eswa.2024.124257.
[29] Louart, M. et al.: Detection of AIS messages falsifications
and spoofing by checking messages compliance with
TDMA protocol. Digital Signal Processing. 136, 103983
(2023). https://doi.org/10.1016/j.dsp.2023.103983.
[30] Marcos, E.P. et al.: Interference awareness and
characterization for GNSS maritime applications. In: 2018
IEEE/ION Position, Location and Navigation Symposium
(PLANS). pp. 908–919 (2018).
https://doi.org/10.1109/PLANS.2018.8373469.
[31] Martínez, F. et al.: Maritime cybersecurity: protecting
digital seas. Int. J. Inf. Secur. 23, 2, 1429–1457 (2024).
https://doi.org/10.1007/s10207-023-00800-0.
[32] de Melo Rodríguez, G. et al.: Development of Maritime
Cybersecurity Protocols – Enhancing Awareness on
Cyberthreats in Maritime Transport. TransNav Int. J.
Mar. Navig. Saf. Sea Transp. 19, 3, 701–706 (2025).
https://doi.org/10.12716/1001.19.03.01.
[33] Moen, I. et al.: Survey-based analysis of cybersecurity
awareness of Turkish seafarers. Int. J. Inf. Secur. 23, 5,
3153–3178 (2024). https://doi.org/10.1007/s10207-024-
00884-2.
[34] Mrozowska, A.: Metasystem for Maritime Cybersecurity
Management During Digital Transformation at Sea.
TransNav Int. J. Mar. Navig. Saf. Sea Transp. 19, 3, 707–
713 (2025). https://doi.org/10.12716/1001.19.03.02.
[35] National Institute of Standards and Technology: The
NIST Cybersecurity Framework (CSF) 2.0. National
Institute of Standards and Technology, Gaithersburg, MD
(2024). https://doi.org/10.6028/NIST.CSWP.29.
[36] Neumann, T.: Cybersecurity in Maritime Industry.
TransNav Int. J. Mar. Navig. Saf. Sea Transp. 18, 4, 765–
774 (2024). https://doi.org/10.12716/1001.18.04.02.
[37] Nganga, A. et al.: Enabling cyber resilient shipping
through maritime security operation center adoption: A
human factors perspective. Applied Ergonomics. 119,
104312 (2024).
https://doi.org/10.1016/j.apergo.2024.104312.
[38] Oruc, A. et al.: Evaluation of Maritime Cyber Security
(MarCy) Training Programme. TransNav Int. J. Mar.
Navig. Saf. Sea Transp. 18, 4, 743–763 (2024).
https://doi.org/10.12716/1001.18.04.01.
[39] Palbar Misas, J.D. et al.: Developing Human-Autonomy
Teaming Strategies for Maritime Cyber Security
Resilience in Uncrewed Autonomous and Remote
Surface Vessel Operations. TransNav Int. J. Mar. Navig.
Saf. Sea Transp. 19, 2, 625–643 (2025).
https://doi.org/10.12716/1001.19.02.35.
[40] Park, C. et al.: A BN driven FMEA approach to assess
maritime cybersecurity risks. Ocean & Coastal
Management. 235, 106480 (2023).
https://doi.org/10.1016/j.ocecoaman.2023.106480.
[41] Sahay, R. et al.: CyberShip-IoT: A dynamic and adaptive
SDN-based security policy enforcement framework for
ships. Future Generation Computer Systems. 100, 736–
750 (2019). https://doi.org/10.1016/j.future.2019.05.049.
[42] Senarak, C.: Port cybersecurity and threat: A structural
model for prevention and policy development. The Asian
Journal of Shipping and Logistics. 37, 1, 20–36 (2021).
https://doi.org/10.1016/j.ajsl.2020.05.001.
[43] Söner, Ö. et al.: Cybersecurity risk assessment of VDR.
The Journal of Navigation. 76, 1, 20–37 (2023).
https://doi.org/10.1017/S0373463322000595.
[44] Svilicic, B. et al.: Assessing ship cyber risks: a framework
and case study of ECDIS security. WMU J Marit Affairs.
18, 3, 509–520 (2019). https://doi.org/10.1007/s13437-019-
00183-x.
[45] Svilicic, B. et al.: Towards a Cyber Secure Shipboard
Radar. The Journal of Navigation. 73, 3, 547–558 (2020).
https://doi.org/10.1017/S0373463319000808.
[46] Symes, S. et al.: Cyberattacks on the Maritime Sector: A
Literature Review. J. Marine. Sci. Appl. 23, 4, 689–706
(2024). https://doi.org/10.1007/s11804-024-00443-0.
[47] Tam, K. et al.: Quantifying the econometric loss of a
cyber-physical attack on a seaport. Front. Comput. Sci. 4,
(2023). https://doi.org/10.3389/fcomp.2022.1057507.
[48] Tam, K., Jones, K.: MaCRA: a model-based framework
for maritime cyber-risk assessment. WMU Journal of
Maritime Affairs. 18, 1, 129–163 (2019).
https://doi.org/10.1007/s13437-019-00162-2.
[49] Tatar, U. et al.: Charting new waters with CRAMMTS: A
survey-driven cybersecurity risk analysis method for
maritime stakeholders. Computers & Security. 145,
104015 (2024). https://doi.org/10.1016/j.cose.2024.104015.
[50] Vasan, D. et al.: Cyber-attacks: Securing ship navigation
systems using multi-layer cross-validation defense.
Computers & Security. 160, 104706 (2026).
https://doi.org/10.1016/j.cose.2025.104706.
[51] Weaver, G.A. et al.: Estimating economic losses from
cyber-attacks on shipping ports: An optimization-based
approach. Transportation Research Part C: Emerging
Technologies. 137, 103423 (2022).
https://doi.org/10.1016/j.trc.2021.103423.
[52] Wimpenny, G. et al.: Securing the Automatic
Identification System (AIS): Using public key
cryptography to prevent spoofing whilst retaining
backwards compatibility. The Journal of Navigation. 75,
2, 333–345 (2022).
https://doi.org/10.1017/S0373463321000837.
[53] Wolsing, K. et al.: Network Attacks Against Marine
Radar Systems: A Taxonomy, Simulation Environment,
and Dataset. In: 2022 IEEE 47th Conference on Local
Computer Networks (LCN). pp. 114–122 (2022).
https://doi.org/10.1109/LCN53696.2022.9843801.
[54] Yoo, J., Jo, Y.: Formulating Cybersecurity Requirements
for Autonomous Ships Using the SQUARE Methodology.
Sensors. 23, 11, 5033 (2023).
https://doi.org/10.3390/s23115033.
[55] Yousaf, A. et al.: Cyber risk assessment of cyber-enabled
autonomous cargo vessel. International Journal of Critical
Infrastructure Protection. 46, 100695 (2024).
https://doi.org/10.1016/j.ijcip.2024.100695.
[56] Yousaf, A. et al.: STPA-Cyber: A semi-automated cyber
risk assessment framework for maritime cybersecurity.
Computers & Security. 157, 104559 (2025).
https://doi.org/10.1016/j.cose.2025.104559.
[57] Zhao, Y. et al.: Cybersecurity in smart port systems: A
systematic review and data-driven research agenda.
Transport Policy. 187, 104268 (2026).
https://doi.org/10.1016/j.tranpol.2026.104268.
[58] Zheng, H. et al.: Identification of Spoofing Ships from
Automatic Identification System Data via Trajectory
Segmentation and Isolation Forest. Journal of Marine
Science and Engineering. 11, 8, 1516 (2023).
https://doi.org/10.3390/jmse11081516.