Protecting ports from cyber threats

Cyber threat specialist EclecticIQ has joined forces with the Nato Cooperative Cyber Defence Centre of Excellence to address the growing risk of cyberattacks on critical maritime infrastructure.

Man looking at five computer screens

The partnership has culminated in the release of a major Nato-affiliated report, Addressing State-Linked Cyber Threats to Critical Maritime Port Infrastructure, which investigates cybersecurity vulnerabilities in port facilities across Nato member and partner countries.

“We are proud to have supported this important research, which aligns closely with our mission to help protect critical infrastructure through actionable intelligence,” said Cody Barrow, chief executive at EclecticIQ.

The report reveals a disturbing rise in state-sponsored activity, with Russian-linked APT44 and Iran-linked Yellow Lideric among the groups executing cyber campaigns against European and Middle Eastern ports.

Exploiting weaknesses in legacy systems, foreign-manufactured components and insufficient network segmentation, these actors threaten both civilian trade and military logistics.

One of the report’s key findings is the increasing convergence of IT and OT environments in modern ports, which has created complex, interconnected attack surfaces. It also identifies serious gaps in cyber threat intelligence sharing among port authorities, national security agencies and private operators.

EclecticIQ contributed deep CTI expertise to the report using its proprietary tools to map threat actor tactics, techniques and procedures, and assess critical vulnerabilities.

“This Nato collaboration showcases how actionable threat intelligence can bridge the gap between identifying threats and preventing attacks on the critical infrastructure that keeps the global economy moving,” said Barrow.