Ensuring OT cybersecurity requires a coordinated, layered approach

Importer
Peter Krahenbuhl, WinGD, HR

In a recent white paper, KVH highlights that the number of attacks in maritime increased by 33% in 2021, following a 900% increase in 2020.

Rather than the data focus of IT, OT includes any hardware or software used to control and monitor industrial control systems (DCS, PLCs, Scada, etc) such as onboard automation, propulsion, and remote-control systems. It includes the hardware and software used to control and monitor the systems and the infrastructure that connects the different devices/nodes together.

Matti Suominen, Director, Maritime Cybersecurity at Wärtsilä, says the convergence of OT with IT is resulting in an escalation of cybersecurity threats with hacktivists increasingly targeting OT systems in recent years. With this shift, awareness is growing – all the way from classification societies right through to the more traditional maritime players. This is helped by the fact that maritime is a very heavily regulated industry which means the relevant bodies, organisations and agencies have the authority and ability to put in place requirements which encourage safe and secure shipping.

“Bad actors are on the rise,” says Suominen. “In general, we see two types of scenarios. First, the importance of the maritime industry to the world means that it is a lucrative target for cyber criminals. They choose their targets based on specific motives, be those, for example, financial or political. Second, increasing connectivity with vessels makes them a target for automated attacks that are common in traditional IT environments. In such cases, the bad actor may not even be aware that the system they have hacked is on a vessel.”

A unique challenge in maritime cybersecurity is the number of players involved before a vessel sets sail, he says. “No single party in this process can make a vessel secure without working with others. Even the most secure piece of equipment is at risk when everything around it is designed without security in mind. This is why collaboration between yards, owners, operators, and OEMs is crucial.

“Wärtsilä works to collaborate with all the stakeholders in the value chain. With other OEMs that we rely on, we try to help them on their cyber journey. With yards and integrators, we work to ensure that the security design of our products is considered in the security architecture of the vessel. With owners and operators, it’s all about providing them the right tools while also ensuring that they understand the operational and lifecycle needs of the vessel.

“While this all sounds simple, the reality of it is a lot of work behind the scenes. Thankfully, we have great partners who, like us, take cybersecurity seriously and are willing to join us on this journey to secure the maritime ecosystem.

“The core of our cybersecurity strategy is in enabling value creation for our customers. As cybersecurity is increasingly a global concern, the link between the work we do and the value for customers has never been clearer.”

Peter Krähenbühl, Head of Digital Transformation & Technology at WinGD, says that the more connected systems become, the more likely – and potentially more severe – cyber threats will be. Newer systems which offer greater potential for diagnostics, optimisation and integration with other systems have a greater risk. Permissions needed to access systems for these functions can also potentially be used for other means without adequate security.

The basis for cybersecurity in operating systems since 2021 lies in the International Electrotechnical Commission (IEC) standards, which are themselves based on wider information technology standards developed by the International Organization for Standardization (ISO). IEC 62443 standards were designed for control systems in automated industry and have since been applied to maritime for similar applications through classification societies and the International Association of Classification Societies (IACS).

All newbuilds contracted for after 1 January 2024 will need to meet new IACS unified requirements for cyber resilience on ships (UR E26) and of on-board systems and equipment (UR E27)). “For WinGD, UR E27 will apply to our computer-based systems, including the WiCE engine control system and its sub-systems and auxiliary systems, as well as to our WiDE remote diagnostics platform. It also applies to our X-EL Hybrid Manager, which governs the energy system on vessels that have hybrid propulsion configurations and uses elements of both WiCE and WiDE,” says Krähenbühl.

Svend Krogsgaard

Source: MAN Energy Solutions

Svend Krogsgaard, Cybersecurity & Safety Manager – Automation at MAN Energy Solutions

“WinGD is working with DNV to secure cybersecurity type approvals which assure that we are technically ready to meet these standards,” he says. WiCE has already been granted the SP1 ‘Cyber Secure Essential’ notation and WiDE has reached SP0 ‘Cyber Secure Basic’, with the aim of reaching SP1 early next year. A similar timeframe is in place for X-EL Hybrid Manager.

The approvals will give confidence to owners and operators that WinGD OT meets regulatory requirements for cybersecurity. However, Krähenbühl says cybersecurity is not to be achieved with a one-time solution, it needs to evolve. This is acknowledged in the rules, which require that different systems reach higher cybersecurity levels based on the criticality of the systems. Approvals also need to be updated when systems are revised.

“We are upgrading WiCE to version 3.5 and that will require re-certification later this year. These evolving targets are an integral part of what it means for systems to remain cybersecure and that is factored into our technology development.

“WinGD is beginning to use artificial intelligence tools to help detect and combat cyber threats. At the same time, it is clear that malicious actors will also find ways to automate and improve cyber-attacks using the same technologies. This is part of the constantly evolving landscape of cybersecurity: creativity has no limits, whether you are attacking or protecting a system.”

Svend Krogsgaard, Cybersecurity & Safety Manager – Automation at MAN Energy Solutions, says one of the key challenges at present is to ensure that individual roles and responsibilities of the many stakeholders is clear.

Additionally, he says, cybersecurity is not something you just put around a product afterwards. “It is something that should be in the mindset of the developer who’s writing the code or designing the hardware components. It should be in their mind and in the specifications from the very beginning, from the first line of code.”

Cybersecurity by design involves preventing errors from an early stage in the development phase, keeping the attack surface of the system as small as possible, providing consistent separation of the systems for better isolation in case of attacks (defence-in-depth) and continuously testing security.

Krogsgaard highlights what he calls the “crown jewels” – the most important thing for onboard power systems – which is maintaining availability. “Even if there is a breach of some systems, the first priority is to ensure that it is still possible to manoeuvre the vessel,” he says. This involves creating onion-like layers of protection on a ship. If one layer is breached, there are more layers protecting the core functional systems.

He says that cybersecurity must be understood from the top down but mitigated from the bottom up. When a yard or owner asks if a particular product is cybersecure, he says, it’s important that they understand the answer: “You cannot just build a ship with each component having its own cyber acceptance or type approval and think you have built a good system. It might be open like a Swiss cheese. Cybersecurity is all about the overall system architecture. From an engine perspective, this involves ensuring that the interfaces are installed in the proper manner and conducting a risk assessment of the complete ship.”

Embedding cybersecurity by design into automation and control platforms is something MAN has been doing for a long time. In many cases, MAN’s solutions exceed those required by IACS as it works to increasingly high levels of compliance within the IEC 62443 standards. This is driven by MAN’s own ambitions, but Krogsgaard says it is also increasingly being pushed by customers who are requesting, and expecting, documented compliance to standards. Some contracts are now setting requirements for the highest security and maturity levels defined in the standards.

In ABB’s view, cybersecurity needs to be maintained and taken care of throughout all stages of the product lifecycle, starting from product development, product integration in project execution phase, operation phase and during decommissioning/retrofit when the product reaches the end of its lifecycle and is replaced with a new one.

“Shipowners are aware of cyber risks and their potential impact on vessel operations, however investing to upgrade obsolete systems remains an issue as it requires investment and careful planning during dry docks. Obsolete systems are challenging to maintain and protect, which means OT systems are left vulnerable to cyber threats,” says Ahmed Hassan, Global Cybersecurity Manager, ABB Marine & Ports.

“Poor network segregation and segmentation, especially for old operational vessels, can lead to spreading of a potential cyberattack between critical systems: if one of the systems is affected, the risk can increase significantly if accompanied by poor disaster recovery planning and procedures.”

ABB offers vendor-agnostic cybersecurity solutions and services by partnering with key cybersecurity software, hardware and service providers. That way, ABB can provide cybersecurity solutions that can be utilized by all OT vendors onboard the vessel. While ABB provides the overall architecture, the shipyard, acting as the system integrator, carries the overall responsibility to integrate other OT systems to the common solution. ABB will offer support to the shipyard and other vendors to integrate into the common solution. When the ship is in operation, ABB will continue to provide support to shipowner to maintain system security.

Korean Register (KR) has proactively conducted joint development projects with Korean shipyards (HD HHI, K Shipbuilding, SHI) to implement the IACS UR E26 and issue Approval in Principle certificates. KR has also established its own cybersecurity certification system by integrating digital ship survey technology with traditional ship survey techniques. As a technical advisor, KR also give cybersecurity technical services such as cybersecurity awareness training, ship cyber risk assessment, vulnerability analysis and penetration testing, a test where the latest hacking techniques are used to directly penetrate networks and systems to expose vulnerabilities and determine whether actual exploitation is possible.

Currently, a ship typically controls external access from the various vendors with a firewall, but this is not an absolute defence, says Lim Jeoungkyu, Senior Cyber Security Surveyor (Cyber Certification Team). For example, if a vendor that is allowed remote access is hacked and this route is used, the entire ship system may be vulnerable. Therefore, ships need a comprehensive cybersecurity control/monitoring system, combination of SIEM (Security information and event management), NMS (Network Monitoring System) and IDS (Intrusion Detection System).

Osku Kälkäjä

Source: ABB Marine & Ports

Osku Kälkäjä, Head of Digital Business, ABB Marine & Ports

Cybersecurity specialist CyberOwl says shipowners should be aware that whilst OT is distinct from IT, in practice it is very difficult to truly separate OT from IT interaction and connections on board a vessel. Even if successful at design and initial implementation, is it even harder to maintain that separation through the vessel’s lifetime, says CEO Daniel Ng.

The only practical way is to invest in mitigations – gaining visibility of onboard systems to ensure some separation remains and undertaking regular cyber incident exercises. Cyber exercises help organisations understand how it differs from a physical safety incident and what practical steps they can take to improve readiness to respond. This includes understanding and containing a cyber incident, which may extend to multiple assets both on and offshore. Operators are advised to:

1. Harmonize their cybersecurity approach. Set up a single unit within fleet operations that covers both IT and OT. This ensures one coordinated unit can deal with incidents.

2. Practice. Develop cyber incident training and drills.

3. Engage more deeply with suppliers. New regulations coming into force will provide some level of assurance for OT equipment installed on new vessels, but supplier controls need to be well implemented and maintained. Involving suppliers in the cyber incident training and drills is also critical.

Osku Kälkäjä, Head of Digital Business, ABB Marine & Ports, says cybersecurity regulations are continuously being developed to better meet the best cybersecurity practices and to reduce cyber risks. Shipowners are also becoming increasingly aware of cybersecurity risks and paying attention to make sure they collaborate with and rely only on recognised cybersecurity experts.

As he says, cybersecurity is not only a product but a process, and one of the important parts in that process is to be able to assess the risks, detect vulnerabilities and define how to mitigate these. “Cybersecurity is always a joint collaborative effort. We need to fight this together. Collaboration is the key.”