DIGITAL COMES WITH RISK

In the second part of a two-part review of a joint World Bank and IAPH report,* Felicity Landon discusses the report’s extensive warnings on preventing cyber security breaches and how this area demands more attention.

cyber security is a growing concern

“Digital technologies will enable the competitive business environments, increased accountability and better education and skills development systems that will create the maritime jobs of the future,” says Boutheina Guermazi, Digital Development Director at the World Bank, in her foreword to the new ‘Accelerating Digitalization’ report jointly produced by the World Bank and International Association of Ports and Harbours (IAPH).

All good, then? Well, not entirely. Many digital developments in the ports sector have been designed and deployed without even considering cybersecurity, warns the report. “Port leaders entering the smart port age face increasingly complex decisions regarding investments in new technologies, such as big data, the internet of things (IoT), artificial intelligence (AI), and digital currency exchanges to improve operational performance, enhance automated processes and increase competitiveness,” it says.

“These capabilities are key building blocks of smart port environments. However, smart ports have an Achilles’ heel: many of these platforms were designed and have been deployed without security in mind.”

CYBER SECURITY: A MAJOR CHALLENGE

As Guermazi says, growing digital integration is not without risk. “Cybersecurity is now one of the major challenges facing the maritime industry. Policymakers need to work with the private sector to ensure critical infrastructure is adequately protected, while continuing to help achieve the full benefits of new technologies in a sector where the digital transition has been uneven across countries.”

The report refers to the case 10 years ago, when Belgian authorities grew suspicious about containers found abandoned outside the Port of Antwerp. A Netherlands-based organised crime syndicate had recruited hackers to breach the port’s IT systems managing container movements. Their objective – to hide narcotics among legitimate cargoes, including timber and bananas shipped from South America.

“With the hackers’ assistance, the criminals accessed the release codes for targeted containers and gained advance knowledge of when and where to send a truck to intercept a container before the legitimate owner arrived.”

First, hackers launched a phishing attack, sending innocent-looking malware-infected emails to employees at various terminal operators. They then gained remote access to cargo management systems and container release codes.

When the breach was discovered and the malware removed, the criminals physically broke into the port to install key-logging devices on computer systems. Via wi-fi, they were able to collect data such as usernames and passwords, using this information to regain access to key systems and continue their smuggling activities.

“Lesson learned: Traditional investments in supporting ISPS Code compliance did not deliver effective integrated security to port stakeholders,” says the report.

‘HYPER INTER-CONNECTEDNESS’ – NEW VULNERABILITIES

The IoT’s ‘hyper interconnectedness’ impacts every port authority, commercial maritime organisation, government agency and individual relying on digital networks, networked systems and applications, cloud-based technologies and mobile devices, it warns.

“Connected port communities – often serving as the critical foundations supporting entire national economies – are increasingly vulnerable to attack tactics exploiting the vulnerabilities that arise from the integration of digital cyberphysical systems.” In short, “while IoT-enabled technologies offer significant potential operational efficiencies to port stakeholders, they also introduce new vulnerabilities that open the door to cyberthreats.”

So, what are the lessons? The report emphasises the convergence of cyber and physical threats, the collaboration of organised crime and hackers, the limitations of local law enforcement versus transnational crime, and the need for communication and coordination between local, regional, national and transnational law enforcement agencies.

Port stakeholders must understand how cyber threats can impact their organisations, analyse and re-evaluate decisionmaking responsibilities and authorities, employ new training strategies, plan for and prepare to respond to possibly debilitating incidents, and understand how to effectively communicate within their organisations and externally among their port community partners, customers, and key stakeholders, the report urges.

It notes that while the trend towards digitalisation and automation of maritime trade, logistics, transport and cargo handling has been under way for many decades, the trend has accelerated in the past few years and has ramped up substantially during the COVID-19 pandemic.

“This has consequently increased the cyberattack surface and enticed threat actors,” it underlines. The Port of Los Angeles, for example, has reported a 50 per cent increase in unauthorised intrusion attempts since the start of the pandemic, and other ports around the globe are also reporting increased cyberthreat activity. “The risk of a cyberattack has become the top risk for port authorities and the wider port community of stakeholders, necessitating improved cybersecurity at the port community ecosystem level,” says the report.

It points readers to the IMO Guidelines on Maritime Cyber Risk Management, released in parallel with the IMO’s new cybersecurity regulations which entered into force in January 2021. Resolution MSC.428(98) on Maritime Cyber Risk Management encourages administrations to ensure that cyber risks are appropriately addressed in existing safety management systems, as defined in the International Safety Management (ISM) Code.

INFORMATION SHARING: TICK THAT BOX

In terms of recommendations, the IAPH/World Bank report says that sharing cyber threat information through mechanisms such as security alerts, suspicious activity reports and breach of security notifications can help port community members to identify, assess, monitor and respond to a range of threats. Information sharing partnerships should be encouraged, including parties such as the port, local law enforcement, customs, various first responders and logistics partners.

“If no facility or mechanism exists for information sharing within a port community, the port community should establish a local body to organise and sustain information sharing activities covering cyberphysical security.” Members of the port community ecosystem can reduce their own cyber risks by implementing essential cybersecurity building blocks such as a cybersecurity framework, says the report.

It suggests the five-step cybersecurity framework developed by the US National Institute of Standards and Technology, based on: identify, protect, detect (research by IBM showed that on average a breach is detected after 197 days), respond and recover (including the need for back-up and restore facilities). Emphasis is placed on the port authority’s ‘natural and neutral orchestration role’. Several port communities have implemented various degrees of cybersecurity discussion forums and roundtables; manual orchestration is a good start, it says.

It highlights the Port of Los Angeles as a good example involving a port community cyber defence scheme. In 2014, it became the first port in the world to implement a state-ofthe-art Cyber Security Operations Center (CSOC) and the following year it was the first port in the world to attain the ISO 27001 cybersecurity certification. In 2019, the port completed its second-generation CSOC.

*Digitalising the Maritime Sector Set to Boost the Competitiveness and Resilience of Global Trade


Task list to achieve cyber resilience

The IAPH/World Bank report says digitalisation is not solely a technological issue, but also a human capital and institution issue. “The move toward digitalisation will also require improvements in human capital to commission, absorb, and implement the associated demands on stakeholders.”

In the same way, cybersecurity is incredibly people dependent. Ongoing investment in staff training across all forms of IT and support must keep pace with the fast-changing challenges of cybersecurity, it says. Another aspect of the ‘protect’ function is creating awareness.

“When professionals discuss cyber resilience, they often refer to people as the weakest link. And indeed, this could be true in breaches that involve phishing, social engineering or another form of human contact. However, when ‘working cyber secure’ becomes part of an organisation’s safety and security culture, people may in fact be your strongest link.

“When employees are taught to detect and report suspicious behaviour, emails and changes in IT, they become a robust line of defence. It is therefore vital to invest in ongoing efforts to raise cybersecurity awareness. Also, in the protect phase, risk control processes and measures should be implemented, and contingency planning to protect against a cyber event should ensure continuity of port operations, including awareness at board level.”

The report, which offers a proposed point-by-point task list for implementation of cyber resilience, concludes that there are reasons for optimism. Some port communities have taken key first steps to drive cybersecurity capability development in their environments by engaging with investors and experts.

Cybersecurity efforts are rapidly strengthening at key port trade hubs as a direct result of a new wave of investment accelerators, technical centres of excellence and academic programmes focused on innovative technologies, including start-ups in ports and maritime trade logistics.

In 2019 alone, venture capital firms invested US$7.86 billion in 646 cybersecurity start-ups, with some of the companies around the world leading the cybersecurity efforts including PortXL in Rotterdam, Dock Innovation Hub in Israel and Pier71 in Singapore.