Hidden in full view
Cyber security needs to be taken more seriously by vulnerable seaports, says Martin Rushmere
A dollar short and a day late
US ports are seen as lagging behind other infrastructure sectors in the country and need to chart a clearer course on cyber protection.
A June 2014 report by the US Government Accountability Office said that the government has still to carry out a “thorough cyber risk assessment” of ports and that there is no way of knowing just how weak the system is. The biggest danger is seen as an advanced persistent threat (APT).
A startling illustration of how little has been done, and how little attention the ports are paying, is shown by the amounts spent on cyber security. The government set up a Port Security Grant Program, with more than $2bn available. Less than $6m went on cyber security. What’s more, since 2007 Long Beach has been the only major port to carry out a vulnerability assessment.
Mark Gazit of ThetaRay has a bleak assessment. “At this time there is no standard or authority that supervises this aspect for the maritime industries. Government-funded research into cyber security in ports exposed a glum picture where even basic cyber security hygiene measures are not being practiced in ports.”
Thomas Heverin of PGFM Solutions adds: “Although other critical infrastructure sectors have guidelines that focus on specific problems, the seaport sector lacks similar guidelines. The Defense Security Information Exchange (DSIE) is an information sharing initiative for critical infrastructure organisations including defense agencies and private companies. Seaports should aim to become part of DSIE or create a similar effort.”
Lanier Watkins at Johns Hopkins Information Security Institute says: “APT may become the primary perpetrator exploiting vulnerabilities in mobile devices to gain entry into the IT systems, then targeting operator’s networks to track and route containers, or targeting industrial control systems (ICS) to sabotage or manipulate port operations.”
Sue Englebert of Tulane University adds that US Vessel Traffic Systems are less vulnerable because they are run off of US Coast Guard equipment.
But Mr Watkins points out another problem: “The increased use of personal mobile devices in US maritime port IT systems could significantly increase the cyber vulnerability of US port maritime systems to APT.”
Ms Englebert sums up the situation: “Where there is a will; there is now a computer hacker…”