Cybersecurity
Port and Maritime Cybersecurity: Terminals, Intermodal Logistics and Onboard Systems
Ports and ships are complex, under-protected OT ecosystems: automated cranes, onboard systems, terminals and intermodal logistics. A map of risks and obligations for a critical sector that is often overlooked.
A critical infrastructure that moves
Ports are the nodes through which almost all international trade in goods passes. Yet, from the perspective of OT cybersecurity, they are among the least protected of all critical infrastructures. The reason is their hybrid nature: a port is at once an industrial plant, a logistics hub and a customs border, and each of these identities brings its own systems and its own vendors.
To this we must add the mobile component. Ships are floating OT platforms, with propulsion, navigation and cargo management systems that are increasingly digital and connected via satellite. The attack surface does not stop at the quayside.
Mapping the systems at risk
It is worth separating the shore domain from the onboard domain.
On shore, in the terminals:
- Terminal Operating System (TOS): the logistical brain of the port, it orchestrates berth allocation, crane planning and the position of every container. Bringing it down means halting all handling.
- Cranes and automated equipment: ship-to-shore cranes, AGVs (automated guided vehicles), straddle carriers. Industrial control systems to all intents and purposes, with direct physical impacts.
- Access and gate systems: automated gates, license plate and container reading, access control. The junction between physical and cyber security.
- Support networks: refrigeration of reefer containers, lighting, quayside power supply.
Onboard, on the ships:
- Navigation systems (ECDIS, GPS, AIS): manipulation of position data is a documented vector.
- Propulsion and machinery management systems: industrial control with consequences for the safety of navigation.
- Satellite connectivity: often the entry point, historically with poor segmentation from operational systems.
Why the sector is behind
Several factors explain why maritime lags behind other OT verticals. The systems are extremely heterogeneous, the product of decades of layering and of different vendors for each function. Supply chains are international and long. Crews and terminal operators are in constant turnover, which makes it hard to build a stable security culture. And onboard connectivity, for years expensive and limited, has been treated as an accessory service rather than as a surface to protect.
The result is a sector where the asset inventory is often incomplete and segmentation between IT, OT and entertainment networks is weak or absent.
The regulatory framework
Regulation is closing the gap on two fronts.
At sea, the International Maritime Organization (IMO) has long required cyber risk management to be integrated into ships' safety management systems. No longer an option, but part of operational compliance.
On land, NIS2 includes transport among the essential sectors. Port authorities and significant logistics operators must put in place risk management, incident notification and supply chain controls. The pressure is set to grow, also in the wake of high-profile incidents that have shut down major terminals for days.
Where to start
For a port authority or a terminal operator, the sequence does not differ from general OT principles, but priority should go to the points of greatest operational impact:
- OT asset inventory of the terminals, with attention to crane systems and automated equipment that are often off the IT radar.
- Segmentation between the TOS, the equipment control networks and the administrative network, to prevent an administrative intrusion from reaching the handling layer.
- Vendor access governance: maintenance of cranes and systems is almost always outsourced. Just-in-time access, logged and revocable.
- Passive monitoring at traffic aggregation points, to detect anomalies without interfering with sensitive systems.
- Continuity plans that account for the scenario of an unavailable TOS and define how the port keeps operating in degraded mode.
Maritime is a sector catching up fast. Those who build the foundations of visibility and segmentation now will be ahead when regulatory pressure turns into verification.
The MON5 angle
Ship-to-shore cranes, AGVs, TOS and reefer networks coexist in a terminal with different vendors and protocols for each function: the incomplete inventory mentioned above is the norm, not the exception. MON5 reconstructs it with passive discovery at traffic aggregation points, cataloguing even the control systems of cranes and automated equipment that are often off the IT radar, without interfering with handling.
The multi-site architecture adapts to groups managing multiple terminals or ports: telemetry collected locally, a centralized view, continuous monitoring with anomaly detection in the sessions of external maintainers. For a port authority or a terminal operator, the foundations are laid with an OT assessment.
Related articles

Cybersecurity
Railway Cybersecurity: Specific Challenges and a Regulatory Approach
Railway networks are becoming more connected and more exposed. An analysis of systems at risk, the regulatory framework and defence strategies for an often overlooked critical infrastructure.

Cybersecurity
Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure
Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

Cybersecurity
OT Cybersecurity in Healthcare: Connected Medical Devices, Hospitals and NIS2
Hospitals are OT environments in their own right: thousands of connected medical devices, often unmanageable with traditional IT tools. How to secure the IoMT fleet under NIS2.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.
Learn more about the regulation: NIS2