DGMA warns of cyber threats as ports automate operations
With ports increasingly adopting digital technologies and automation, cyber threats have emerged as a potential risk to maritime security and the continuity of port operations
With ports increasingly adopting digital technologies and automation, cyber threats have emerged as a potential risk to maritime security and the continuity of port operations, the Directorate General of Maritime Administration (DGMA) has cautioned in a fresh advisory. Referring to the International Ship and Port Facility Security Code, DGMA said the growing dependence of modern ports on interconnected information technology and operational technology systems had created new vulnerabilities that could adversely affect the safety, security and functioning of port facilities.
The advisory said terminal operating systems, cargo handling infrastructure, vessel traffic management systems, access control mechanisms, surveillance networks and communication systems among others were vulnerable to cyber risks. Incidents of cyber attacks could result from unauthorised access, malware, ransomware attacks, insecure remote access arrangements, third-party access and compromise of interconnected systems, it said. Need for cyber resilience To strengthen cyber resilience, DGMA advised ports to incorporate cyber security risk assessments into their Port Facility Security Assessment.
The assessment could identify vulnerabilities, threat possibilities and the impact of cyberattacks on port security and operational continuity. The mitigation measures identified through the exercise should be integrated into the Port Facility Security Plan. Port authorities were advised to periodically test their backup and recovery arrangements to improve resilience against cyberattacks. Emphasising the importance of preparedness, the advisory said Port Facility Security Officers and other personnel responsible for security should possess adequate awareness of cyberattacks.
Officers designated for cyber security risk management should hold regular awareness programmes, drills, simulations and exercises to assess preparedness and improve response capabilities, it said. DGMA urged the ports to establish clear procedures for cyber incident reporting, response, containment and recovery, while periodically reviewing and updating cyber security measures in line with evolving threats, technological advancements and operational requirements.