Maritime OT Faces A Varied and Interconnected Threat
What do you see as the cybersecurity challenges facing the maritime industry?
Virtually 90% of global trade is conducted by shipping, making the maritime industry a prime target for adversaries.
One of the biggest challenges facing the maritime community is visibility into underway vessels and security monitoring of satellite and ship to shore communication systems. As the threat landscape evolves, adversaries may develop more effective ways of utilising these systems to gain access or to utilise land-based connections to bridge their operations into otherwise remote ship networks.
While equipment may have a limited threat surface, the interconnected nature of maritime systems broadens the threat landscape. Gaps in one sector can provide an “adversary opportunity,” even if there is no specific “adversary intent” to target maritime operations.
Automated attacks generally focus on “adversary opportunity,” seeking to exploit any vulnerabilities they find across a broad array of targets. These attacks often utilise malware, ransomware, or phishing campaigns and are not usually targeted at a specific entity.
On the other hand, targeted attacks, which are less frequent but could potentially be more damaging, usually signify a specific “adversary intent” to compromise a particular maritime operation or asset.
What are the specific treats to OT systems?
The threat surface in maritime OT is not uniform; it varies significantly between land-based and ship-based assets. While the operational complexity of maritime vessels may pose initial barriers to less capable adversaries, the reliance on land-based systems creates vulnerabilities that could lead to significant operational impact.
Given the various systems involved in modern shipping operations, the attack surface requires an adversary to perform extensive research or have access to sources that possess such knowledge about the most effective way to enact a desired effect. The complexity and diversity of vendor implementations of systems and processes also present a challenge for an adversary to identify, understand, and plan offensive operations that target maritime on a larger scale.
As increasing digitalisation in maritime occurs, especially if the maritime industry takes AI and automated piloting seriously as a course of operations, the distance between an adversary achieving the ability to perform complex, real time, interactive operations on a remote vessel shrinks.
How important are penetration tests?
Penetration testing is a crucial but singular component of a comprehensive cybersecurity strategy. It should neither be the initial nor the final measure in evaluating an organisation’s cybersecurity posture. Rather than viewing penetration testing as a competitive exercise to either succeed in breaching defences or thwarting the test, it should be conducted collaboratively with defensive or “blue” teams.
The aim is to jointly identify the failure points of security controls and understand the reasons behind those failures.
A well-designed penetration test should have clearly defined objectives and be executed from multiple attack vectors. This could include scenarios such as an insider threat, exploitation of remotely accessible vulnerable assets, or leveraging compromised credentials.
These scenarios should mirror the common initial entry points that adversaries typically target and how an adversary would operate in an environment, thereby providing more actionable insights. The complexity of penetration tests should be incremental, starting with simpler tests and gradually moving towards more advanced techniques. Initially, one can make use of freely available offensive security tools found on platforms like GitHub, before progressing to customised methods specifically designed to challenge existing security measures. The overarching goal is to iteratively enhance the security program while continually validating and verifying the effectiveness of current security controls.
Conducting only overly complex penetration tests is counterproductive if basic security measures are not robust enough to thwart publicly available threats like web shells, Mimikatz, or commonly used malware. Moreover, if your security architecture fails to detect or counter basic attack techniques such as ‘Pass-the-Hash’ or other anomalous activities, the value derived from a complex penetration test would be limited. This does not mean organisations should only do extremely basic tests either with automated penetration testing tools like a Nessus scanner. The focus should be on incrementally strengthening the security posture while ensuring that foundational controls are both effective and resilient.
The primary objective of penetration testing is not to assign blame or find faults in the existing security setup, but to improve overall security measures. Security controls can fail, and human errors are inevitable; the focus should be on developing mitigating strategies to reduce the associated risks and impacts of such occurrences.