Patched into cyber risks

Since the rushed introduction of the International Ship and Port Facility Code back in 2004, ports have had a dogged focus on security of their facilities. Miles of perimeter fencing has been erected, tens of thousands of security plans have been put in place and countless port security officers have been appointed.

Ports need to pay attention to cyber threats

But all these centre on the physical security of the port and pay little, if any, attention to another more menacing threat to security.

Cyber risks – perhaps via hacked systems or malware downloads – are relatively silent risks that have the potential to cause some very costly problems for unsuspecting and unprepared ports.

TT Club has released a timely report on the growing problem of cyber theft. They cite commercial identity theft, fraudulent use of internet clearing sites, instances where crime organisations have purchased legitimate but failing transport operators and continued to trade in their name, and spyware infiltrations as just a few of the cyber risks being utilised today.

The latter could be for the sole purpose of extracting release codes for containers from port and terminal facilities. However, more sophisticated spyware infiltrations can record movements, key strokes, and even download and print documents and screen shots to an external source.

It’s a serious, and costly, problem. In Europe alone, the value of cargo stolen in transit is pegged at E8.2bn by the European Commission.

“There is a marked trend in organised crime posing as legitimate operators or using internet cargo clearing sites to facilitate the theft of high value cargo. Perhaps most worrying is that this is global,” says TT Club.

And there is more than a financial cost attached to cyber threats; the cost, often unquantifiable, of brand damage is just as important.

Perhaps the most worrying statement made by the insurance specialist is that thieves will seek to “identify the weakest link in any given supply chain”. As the central hub of that supply chain, ports and terminals cannot afford to ignore the cyber threat.

Straightforward due diligence and vigilance will help, but beyond that ports should consider thorough risk assessments of the cyber attacks that they are unwittingly inviting and the ease of access for any trafficking or smuggling gang.

The impact of physical security is quantifiable and therefore easier to get Board buy-in; cyber threats are not, so port managers need to truly get to grips with the scale of this mounting problem and be ready to convince others of the need for cyber protection.