THE UNSEEN STORM: A CRITICAL REVIEW OF CYBERSECURITY THREATS AND THEIR ECONOMIC IMPACT ON GLOBAL MARITIME TRADE
DOI:
https://doi.org/10.46754/jml.2026.08.005Keywords:
Maritime cybersecurity, Shipping 4.0, IMO cyber risk, economic impact of cyber-attack, supply chain disruptionAbstract
The maritime industry, the silent engine of global trade, is undergoing a profound digital transformation, often referred to as Shipping 4.0 (Mesa et al., 2024). This significant shift involves the widespread adoption of digital, interconnected operating environments known as Cyber-physical Systems. While this technological leap has brought about remarkable improvements in efficiency and competitiveness, it has also, ironically, exposed the sector to a new wave of complex cybersecurity threats. This critical review paper delves into the rapidly changing landscape of maritime cyber threats and, crucially, assesses their tangible economic impact on global maritime trade. Our investigation begins by mapping out the primary vulnerabilities found in both shipboard and port-side systems. We pay special attention to mission-critical technologies like the Electronic Chart Display and Information System (ECDIS), GNSS, and automated cargo-handling infrastructure. Key real-world incidents, such as the devastating NotPetya attack on A.P. Moller-Maersk, are analysed not only to illustrate the threat but also to provide an empirical basis for quantifying the full spectrum of costs. These costs include staggering direct financial losses, widespread trade disruption, significant reputational damage, and an inevitable rise in insurance premiums across the sector. Furthermore, the study critically reviews existing global policy and regulatory frameworks, specifically examining the effectiveness of instruments like the IMO Guidelines on Maritime Cyber Risk. This analysis highlights critical gaps in their practical implementation, particularly the persistent lack of economic incentives needed to encourage robust, industry-wide security investments. Ultimately, this paper concludes by offering strategic, economically sound recommendations designed to foster strong cyber-resilience, which is vital for protecting the integrity and efficiency of the critical maritime supply chain in this fast-evolving digital age.
References
Afenyo, M., & Caesar, L. D. (2023). Maritime cybersecurity threats: Gaps and directions for future research. Ocean and Coastal Management, 236, Article 106493. https://doi.org/10.1016/j.ocecoaman.2023.106493 DOI: https://doi.org/10.1016/j.ocecoaman.2023.106493
Akpan, F., Bendiab, G., Shiaeles, S., Karamperidis, S., & Michaloliakos, M. (2022). Cybersecurity challenges in the maritime sector. Network, 2(1), 123–138. https://doi.org/10.3390/network2010009 DOI: https://doi.org/10.3390/network2010009
Androjna, A., Brcko, T., Pavic, I., & Greidanus, H. (2020). Assessing cyber challenges of maritime navigation. Journal of Marine Science and Engineering, 8(10), Article 776. https://doi.org/10.3390/jmse8100776 DOI: https://doi.org/10.3390/jmse8100776
Ashraf, I., Park, Y., Hur, S., Kim, S. W., Alroobaea, R., Zikria, Y. B., & Nosheen, S. (2022). A survey on cyber security threats in IoT-enabled maritime industry. IEEE Transactions on Intelligent Transportation Systems, 24(2), 2677–2690. https://doi.org/10.1109/TITS.2022.3164678 DOI: https://doi.org/10.1109/TITS.2022.3164678
Ben Farah, M. A., Ukwandu, E., Hindy, H., Brosset, D., Bures, M., Andonovic, I., & Bellekens, X. (2022). Cyber security in the maritime industry: A systematic survey of recent advances and future trends. Information, 13(1), Article 22. https://doi.org/10.3390/info13010022 DOI: https://doi.org/10.3390/info13010022
Bocayuva, M. (2021). Cybersecurity in the European Union port sector in light of the digital transformation and the COVID-19 pandemic. WMU Journal of Maritime Affairs, 20, 173–192. https://doi.org/10.1007/s13437-021-00240-4 DOI: https://doi.org/10.1007/s13437-021-00240-4
Bolbot, V., Kulkarni, K., Brunou, P., Valdez Banda, O., & Musharraf, M. (2022). Developments and research directions in maritime cybersecurity: A systematic literature review and bibliometric analysis. International Journal of Critical Infrastructure Protection, 39, Article 100571. https://doi.org/10.1016/j.ijcip.2022.100571 DOI: https://doi.org/10.1016/j.ijcip.2022.100571
Clavijo Mesa, M. V., Patino-Rodriguez, C. E., & Guevara Carazas, F. J. (2024). Cybersecurity at sea: A literature review of cyber-attack impacts and defenses in maritime supply chains. Information, 15(11), Article 710. https://doi.org/10.3390/info15110710 DOI: https://doi.org/10.3390/info15110710
de la Peña Zarzuelo, I. (2021). Cybersecurity in ports and maritime industry: Reasons for raising awareness on this issue. Transport Policy, 100, 1–4. https://doi.org/10.1016/j.tranpol.2020.10.001 DOI: https://doi.org/10.1016/j.tranpol.2020.10.001
Dimakopoulou, A., & Rantos, K. (2024). Comprehensive analysis of maritime cybersecurity landscape based on the NIST CSF v2.0. Journal of Marine Science and Engineering, 12(6), Article 919. https://doi.org/10.3390/jmse12060919 DOI: https://doi.org/10.3390/jmse12060919
Dominguez-Péry, C., Arab, K., Perea, C., & Tassabehji, R. (2023). Ship’s cyber security: Antecedents to improve resilience capabilities and their impact on decision-making and collaborative performance. MCIS 2023 Proceedings, Article 34. https://aisel.aisnet.org/mcis2023/34
Hemminghaus, C., Bauer, J., & Padilla, E. (2021). BRAT: A BRidge Attack Tool for cyber security assessments of maritime systems. TransNav: The International Journal on Marine Navigation and Safety of Sea Transportation, 15(1), 35–44. https://doi.org/10.12716/1001.15.01.02 DOI: https://doi.org/10.12716/1001.15.01.02
Jo, Y., Choi, O., You, J., Cha, Y., & Lee, D. H. (2022). Cyberattack models for ship equipment based on the MITRE ATT&CK framework. Sensors, 22(5), Article 1860. https://doi.org/10.3390/s22051860 DOI: https://doi.org/10.3390/s22051860
Johnsen, S. O., & Kilskar, S. S. (2020). A review of resilience in autonomous transport to improve safety and security. In Baraldi, P., Di Maio, F., & Zio, E. (Eds.), Proceedings of the 30th European Safety and Reliability Conference and the 15th Probabilistic Safety Assessment and Management Conference. Research Publishing. https://www.sintef.no/globalassets/project/hfc/sarepta/johnsen-kilskar-2020-a-review-of-resilience-in-autonomous-transport-to-improve-safety-and-security.pdf DOI: https://doi.org/10.3850/978-981-14-8593-0_3493-cd
Kavallieratos, G., & Katsikas, S. (2020). Managing cyber security risks of the cyber-enabled ship. Journal of Marine Science and Engineering, 8(10), Article 768. https://doi.org/10.3390/jmse8100768 DOI: https://doi.org/10.3390/jmse8100768
Kechagias, E. P., Chatzistelios, G., Papadopoulos, G. A., & Apostolou, P. (2022). Digital transformation of the maritime industry: A cybersecurity systemic approach. International Journal of Critical Infrastructure Protection, 37, Article 100526. https://doi.org/10.1016/j.ijcip.2022.100526 DOI: https://doi.org/10.1016/j.ijcip.2022.100526
Li, M., Zhou, J., Chattopadhyay, S., & Goh, M. (2024). Maritime cybersecurity: A comprehensive review [Preprint]. arXiv. https://arxiv.org/abs/2409.11417v3
Longo, G., Orlich, A., Musante, S., Merlo, A., & Russo, E. (2023). MaCySTe: A virtual testbed for maritime cybersecurity (SSRN Scholarly Paper No. 4374685). Social Science Research Network. https://doi.org/10.2139/ssrn.4374685 DOI: https://doi.org/10.1016/j.softx.2023.101426
Meland, P. H., Bernsmed, K., Wille, E., Rødseth, Ø. J., & Nesheim, D. A. (2021). A retrospective analysis of maritime cyber security incidents. TransNav: The International Journal on Marine Navigation and Safety of Sea Transportation, 15(3), 519–530. https://doi.org/10.12716/1001.15.03.04 DOI: https://doi.org/10.12716/1001.15.03.04
Mraković, I., & Vojinović, R. (2019). Maritime cyber security analysis: How to reduce threats? Transactions on Maritime Science, 8(1), 132–139. https://doi.org/10.7225/toms.v08.n01.013 DOI: https://doi.org/10.7225/toms.v08.n01.013
Park, C., Kontovas, C., Yang, Z., & Chang, C.-H. (2023). A BN driven FMEA approach to assess maritime cybersecurity risks. Ocean and Coastal Management, 235, Article 106480. https://doi.org/10.1016/j.ocecoaman.2023.106480 DOI: https://doi.org/10.1016/j.ocecoaman.2023.106480
Progoulakis, I., Rohmeyer, P., & Nikitakos, N. (2021). Cyber physical systems security for maritime assets. Journal of Marine Science and Engineering, 9(12), Article 1384. https://doi.org/10.3390/jmse9121384 DOI: https://doi.org/10.3390/jmse9121384
Sesay, M. A. K. (2019). Awareness of cybersecurity threats in the Port of Freetown, Sierra Leone [Master’s dissertation, World Maritime University]. WMU The Maritime Commons. https://commons.wmu.se/cgi/viewcontent.cgi?article=2457&context=all_dissertations
Silverajan, B., Ocak, M., & Nagel, B. (2018). Cybersecurity attacks and defences for unmanned smart ships. In 2018 IEEE Conferences on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData) (pp. 15–20). IEEE. https://doi.org/10.1109/Cybermatics_2018.2018.00037 DOI: https://doi.org/10.1109/Cybermatics_2018.2018.00037
Svilicic, B., Brčić, D., Žuškin, S., & Kalebić, D. (2019). Raising awareness on cyber security of ECDIS. TransNav: The International Journal on Marine Navigation and Safety of Sea Transportation, 13(1), 231–236. https://doi.org/10.12716/1001.13.01.24 DOI: https://doi.org/10.12716/1001.13.01.24
Symes, S., Blanco-Davis, E., Graham, T., Wang, J., & Shaw, E. (2025). The survivability of autonomous vessels from cyber-attacks. Journal of Marine Engineering & Technology, 24(3), 194–216. https://doi.org/10.1080/20464177.2024.2428022 DOI: https://doi.org/10.1080/20464177.2024.2428022
Tam, K., Moara-Nkwe, K., & Jones, K. D. (2021). The use of cyber ranges in the maritime context: Assessing maritime-cyber risks, raising awareness, and providing training. Maritime Technology and Research, 3(1), 16–30. https://doi.org/10.33175/mtr.2021.241410 DOI: https://doi.org/10.33175/mtr.2021.241410
Yoo, Y., & Park, H.-S. (2021). Qualitative risk assessment of cybersecurity and development of vulnerability enhancement plans in consideration of digitalized ship. Journal of Marine Science and Engineering, 9(6), Article 565. https://doi.org/10.3390/jmse9060565 DOI: https://doi.org/10.3390/jmse9060565
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Journal of Maritime Logistics

This work is licensed under a Creative Commons Attribution 4.0 International License.







