DNV’s cybersecurity readiness heightened with Cyberowl
In 2007 DNV established cybersecurity services which included advisory, recommended practices, academy training, as well as cyber class notation and type approval. In 2021 it acquired Netherlands-based Applied Risk, a provider of industrial cybersecurity solutions and last year bought Finland’s Nixu, a cybersecurity services company. This year’s Cyberowl deal was indeed the culmination of years of bolstering DNV’s cybersecurity offering to the effect that it now has over 550 professionals working in the field across 11 countries and is soon to launch DNV Cyber, a dedicated subsidiary reflecting its strength in the area.
Teutonic shifts rocking foundations
The CEO of DNV Maritime, Knut Ørbeck-Nilssen (pictured), kicked off proceedings at DNV’s cybersecurity briefing with a rather ominous analogy that the sector is reminiscent of Creedence Clearwater Revival’s classic “Have you ever seen the rain”. He then explained how while cyber attacks had eased off some time ago, they were now increasing, both in volume and severity. The context of this uptick includes: political shocks and unpredictable markets, decarbonisation informing regulatory measures and technology being the bedrock of a maritime renaissance.
Ørbeck-Nilssen used a phrase throughout his presentation, “attack vectors” which in the parlance of cybersecurity refers to the method which cybercriminals use to gain access to an unauthorised system. But Ørbeck-Nilssen said that there’s now a “blurring of cyber risks with usual risks” with the suggestion being that cybersecurity should now be paramount for maritime companies along with more traditional risk management. A rise in cyber incidents has occurred with an increase in connectivity between vessels and the shore using technology like Starlink or more generally satellite communication. This is one driver of increased investment in the sector with well-documented cases of malware attacks on Norwegian, Dutch and Greek vessels to gain remote access to onboard systems causing consternation.
Another driver of maritime investment in cybersecurity is regulation, with the IMO highlighting how cyber risk is defined as a general safety risk in January 2021. The International Association of Classification Societies (IACS) has since taken the helm this year publishing mandatory cybersecurity requirements, detailing the minimum needed for cyber resilience among connected ships. He summed up by stating that closer collaboration and training for both seafarers and those onshore was needed to make the maritime industry safe from cyberattacks. Tellingly, Ørbeck-Nilssen showed that the maritime sector had a greater cyber risk appetite compared to all other industries, by more than 10 percentage points. Despite this, 76% of respondents to a DNV survey said that training was not adequate to protect against a sophisticated cyberattack.
Cyber priority
Liv Hovem, CEO of Accelerator at DNV detailed the findings of a cyber priority report produced by DNV which looks at maritime and the energy sector (another focus of DNV). The report found that 71% of respondents felt that assets were vulnerable to cyberattacks, which Hovem said is an all time high. An even higher number, 73% of respondents said they would increase spending on cybersecurity. Hovem said this a dramatic change in feeling from when she first entered the space, a time when maritime professionals would say cybersecurity is not relevant as ships aren’t connected and so on. But these fears seem well based, with Hovem stating that the average shipping company faces up to 80 attacks a year.
The report also details where in the cybersecurity ecosystem respondents are investing, from preventative measures like identifying cyber risks to responsive measures like system or asset recovery. Here the results were surprising with a whopping 45% investing in responsive measures suggesting the cybersecurity threat in shipping is very real. Despite this threat, respondents appeared confident in their respective cybersecurity measures with 83% stating they had good cybersecurity measures in place 71% sure their businesses would return to normal quickly after a cyber-attack. Digging deeper into the report suggests that this confidence is not as resolute as first appears, with just 53% agreeing with the statement it can “demonstrate full visibility of its supply chain and vulnerabilities”. Furthermore, 43% agreed with “My organisation lacks the skills and talent required to comply with cybersecurity regulations”.
The reports findings were cited as the context in which DNV has been investing in its own cybersecurity business.
Cyberowl
DNV’s most recent investment in its cybersecurity offering Cyberowl is a security monitoring and automation company focused on remote assets such as ships, and offshore platforms. Its CEO Dan Ng describes the business as a “CCTV camera” focused on a ship during its life cycle. It’s this lifetime of a vessel focus which makes the deal with DNV a “perfect marriage” in Ng’s words as the class society has strengths in the design and construction phase of a ship, or to continue the analogy, a vessel’s birth.
Ng points to the boom in newbuilds coupled with regulations governing how ships are secure straight out of the shipyard which makes this lifetime of a vessel focus crucial. Ng says it’s vital, “to ensure that ships are secure by design as they leave the yard, also then operate and maintain in a secure way” and his company’s cyber analysts will go and visit a vessel that has signed up to Cyberowl’s services within the first 12 months. They are maritime specialists and with that Ng has inside knowledge of the type of cyberattacks ships face. He says that only 1% are actually targeted specifically at ships which due to their design can often isolate the issue by simply shutting down. This is to say that someone may unsuspectingly infect a system with malware by using an infected USB stick. The result is, according to Ng, that ship owners don’t actually know they have been affected by a cyber-attack and just think it’s equipment failure.
With geopolitical tensions running high at the moment targeted cyberattacks against shipping is not that far fetched though, and with DNV’s investment in the sector it looks to have prepared for any eventuality.