{"id":60,"date":"2018-04-30T09:24:00","date_gmt":"2018-04-30T08:24:00","guid":{"rendered":"https:\/\/portstrategy.nfdtesting.uk\/greenport\/2018\/04\/30\/cyber-legislation-makes-demands-of-ports\/"},"modified":"2026-08-27T13:41:56","modified_gmt":"2026-08-27T12:41:56","slug":"cyber-legislation-makes-demands-of-ports","status":"publish","type":"post","link":"https:\/\/www.portstrategy.com\/greenport\/news\/concessions-investments\/cyber-legislation-makes-demands-of-ports\/","title":{"rendered":"Cyber legislation makes demands of ports"},"content":{"rendered":"<p>The importance of cyber security to the maritime transport sector was brought into sharp focus in June 2017 when the \u2018NotPetya\u2019 malware attack struck organisations in more than 60 countries worldwide, including many prominent organisations within the maritime transport sector.<\/p>\n<p>Incidents such as this demonstrate the need to improve the security of network and information systems across the maritime transport sector. The Directive on Security of Network and Information Systems (EU 2016\/1148) (the Cyber Directive), which was transposed into UK law on May 9, 2018, brings cyber security onto a legislative footing. It applies to organisations termed as \u2018Operators of Essential Services\u2019 (OES) and requires such organisations to demonstrate that they have implemented \u2018appropriate and proportionate\u2019 cyber security measures to prevent, or at least alleviate, the potential harm of cyber security incidents.<\/p>\n<p>The latest UK Government publication on the application of the Cyber Directive indicates that OES within the maritime transport sector will apply to harbour authorities, ports or port operators that either have annual passenger numbers greater than 10m or that account for more than 15% of the UK\u2019s ro-ro traffic, 15% of the UK\u2019s lo-lo traffic, 10% of UK total liquid bulk; or 20% of UK total bio-mass fuel.<\/p>\n<p>The Cyber Directive will also impact sea freight carriers that handle more than 30% of freight at any UK port that falls within the parameters above, and 5m tonnes of total annual freight in UK ports as a whole.<\/p>\n<p>While those identified as OES pursuant to these thresholds will need to comply with the requirements of the Cyber Directive summarised below, it is important to note that businesses that supply or contract with OES are also likely to be affected due to the highly interconnected nature of the sector.<\/p>\n<p><strong>Compliance requirements<\/strong><\/p>\n<p>OES within the maritime transport sector will be required to comply with a set of fourteen security requirements based on the following four objectives as defined by the National Cyber Security Centre:<\/p>\n<p>Managing security risk \u2013 OES will need to ensure that appropriate organisational structures, policies, and processes are in place to understand, assess and systematically manage security risks to the network and information systems supporting essential services across their assets and supply chains.<\/p>\n<p>Protecting against cyber attack \u2013 This objective necessitates the implementation of proportionate security measures to protect essential services and systems from cyber attack. Examples include managing access to relevant systems, the protection of data and providing staff with appropriate training.<\/p>\n<p>Detecting cyber security events \u2013 OES must demonstrate they have the capability to ensure security defences remain effective and to detect cyber security events affecting, or with the potential to affect, essential services.<\/p>\n<p>Minimising the impact of cyber security incidents \u2013 This objective centres on an organisation&#8217;s ability to minimise the impact of a cyber security incident on the delivery of essential services. It calls for OES to have a robust incident response plan to cover all relevant potential incidents. In addition, any incident having a \u2018significant\u2019 impact on the continuity of essential services must be formally reported.<\/p>\n<p><strong>Oversight and enforcement<\/strong><\/p>\n<p>Once the Cyber Directive is effective, each \u2018Competent Authority\u2019 will have responsibility for the oversight of its sector. The Competent Authority for the maritime transport sector will be the Secretary of State for Transport, and by extension the Department for Transport. Responsibilities of the Competent Authority will include the designation of OES; monitoring the application of the Cyber Directive; the publication of guidance (including incident reporting thresholds); and enforcement and the imposition of penalties.<\/p>\n<p>The Competent Authority will have the right to impose financial penalties (up to a maximum of \u00a317m) on OES which contravene the Cyber Directive. However, the UK Government is keen to stress that the maximum penalty should be regarded as a last resort &#8211; indeed, the latest guidance dictates that the Competent Authority will take a reasonable and proportionate approach to enforcement.<\/p>\n<p><em>Matthew Gore is a partner at HFW, where he is a specialist lawyer covering the ports and terminals, shipping and logistics sectors. The author would like to thank Mark Devlin of HFW for his input on research and drafting for this article.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HFW\u2019s Matthew Gore examines the implications of new virtual security regulations<\/p>\n","protected":false},"author":8,"featured_media":61,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[],"sponsor":[],"class_list":["post-60","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-concessions-investments"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/posts\/60","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/comments?post=60"}],"version-history":[{"count":1,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/posts\/60\/revisions"}],"predecessor-version":[{"id":62,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/posts\/60\/revisions\/62"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/media\/61"}],"wp:attachment":[{"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/media?parent=60"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/categories?post=60"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/tags?post=60"},{"taxonomy":"sponsor","embeddable":true,"href":"https:\/\/www.portstrategy.com\/greenport\/wp-json\/wp\/v2\/sponsor?post=60"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}