Cyberattacks against the global maritime industry more than doubled in 2025, rising 103% to 828 recorded incidents from 408 the year before, according to research published by maritime threat intelligence firm CYTUR. The shift in these attacks is as significant as their scale. Rather than targeting data alone, attackers are increasingly going after the operational technology (OT) that keeps ships moving, ports running and offshore assets producing.
For Christian Madsen Skytte, an automation specialist at NACOS Marine, the change reflects a simple reality: systems that were once isolated on board are now part of a connected network: “In the past, we saw the automation, navigation and DP platforms as independent platforms, on islands, on both the vessels. Today, they get more and more connected, especially to internet and to shore, and that of course brings in some additional risk.”
An expanding attack surface
Navigation, automation and dynamic positioning (DP) systems fall into the category of OT rather than information technology (IT) and have not traditionally been built with the same cybersecurity safeguards. According to Skytte, the greatest exposure on board a vessel today is rarely a targeted hack. It is far more likely to be an unintended error: a crew member plugging a network cable into the wrong port or introducing a virus by way of an infected USB stick, simply because they were not trained to recognise the risk.
Geopolitics has sharpened this picture. Fox Walker, senior defence analyst at GlobalData, points to recent operations in the Strait of Hormuz, where Iran’s Islamic Revolutionary Guard Corps has used domestically produced GNSS jamming and spoofing to prevent commercial and military vessels from navigating safely out of the waterway. Israel, he notes, has used cyberwarfare techniques during its conflict with Iran to compromise CCTV systems and other digital infrastructure to track movement. In the Black Sea, maritime operations tied to Russia’s war in Ukraine have increasingly relied on unmanned surface and underwater vehicles for intelligence gathering and electronic warfare, platforms that are themselves highly vulnerable to cyberattack given their dependence on remote command links rather than a crew on board.
That vulnerability is driving investment in more resilient uncrewed systems. The US Navy’s Extra Large Uncrewed Undersea Vehicle (XLUUV) programme, for example, recently selected Kongsberg and Oceaneering International to develop a platform capable of intelligence, surveillance and reconnaissance operations without reliance on GPS, an approach Walker cites as a benchmark for cyber-resilient design in unmanned maritime platforms.
The scale of the underlying threat is easier to see in commercial shipping data, where GPS and satellite navigation interference has become a daily occurrence rather than an isolated event. Industry monitoring in 2025 recorded roughly 1,000 GPS disruption incidents a day, affecting more than 40,000 vessels, with two high-profile cases underlining the physical consequences. In May 2025, the containership MSC Antonia ran aground near Jeddah after its navigation data was corrupted by GPS spoofing, and the following month two tankers collided in the Gulf, with spoofing suspected as a contributing factor. Incidents of this kind are precisely why regulators and naval customers alike are treating navigation system integrity as a safety issue rather than a purely digital one.
A standard, not a specification
The regulatory backdrop for all of this is a widening set of overlapping requirements. The International Maritime Organization’s baseline rules, together with the International Association of Classification Societies’ Unified Requirements E26 and E27, now set a minimum cybersecurity standard that all newly built vessels must meet. Naval programmes typically layer their own government-specific rules on top of this baseline, most of them modelled on information technology security frameworks rather than OT.
According to Skytte, that distinction matters. Cybersecurity practice in IT is comparatively mature. In OT, including the systems that manage water, power and propulsion on board a vessel, it remains close to a starting point.
Rather than negotiating each navy customer’s individual specification separately, NACOS Marine has pushed toward IEC 62443, an industrial automation security standard with four security levels, SL1 to SL4. SL4 is reserved for infrastructure whose failure could harm a nation, such as a nuclear facility. NACOS Marine is certifying its systems to SL III, one level below that, and Skytte was clear that this is what the company is targeting.
“Instead of trying to fulfil one specific clause in a specification from one navy customer, it is better that we say, of course we respect that you have all these requirements, but we are very close to this high standard, SL III,” Skytte said. In December 2025, the company’s NACOS Platinum integrated navigation system received DNV type approval for full compliance with IACS E27 under the 460 network cybersecurity notation, giving it a certified baseline to build on for higher classification levels.
Resilience built into the architecture
The push toward SL III certification sits alongside a broader shift in how navies are asking for systems to be built. Rather than requesting separate navigation, automation and DP platforms, naval customers increasingly want an integrated bridge and platform management system; in NACOS Marine’s terms, an IBPMS that allows a smaller crew to operate more functions from a single station.
For NACOS Marine, integration itself is not new. Skytte points to the market release of its Platinum navigation and automation control system back in 2010 as an early example of the same design principle, well before the current wave of naval interest.
What has changed is the demand behind it. Navies are moving toward leaner manning, largely because qualified sailors are harder to recruit, and integration is the only practical way to let fewer people manage increasingly complex systems. That trend cuts both ways from a security standpoint. A single operator managing multiple systems from one screen is more efficient, but it also means a single compromised station has a larger blast radius than in the days of isolated, single-purpose consoles.
Consolidating control onto fewer screens raises the stakes for cybersecurity, and NACOS Marine’s answer has been to design for isolation rather than assume it away. Individual components are built to keep functioning independently if the wider network is compromised. In the event of a network storm or attack, a vessel can disconnect its radar from the network ring and continue to use it as a radar, even if automated route transfer from the chart planning station is lost.
At the automation level, core logic runs on programmable logic controllers rather than the central computers, so even a full loss of onboard computing still leaves independent panels able to operate individual processes, with backup systems available to rebuild the automation and navigation environment if needed.
This redundancy is deliberate rather than incidental, and it applies as much to cruise vessels as to naval ones. For cruise operators, where the loss of a passenger, a collision or an attack-driven shutdown carries a direct reputational cost, resilient automation is less a compliance exercise than an operational safeguard, and Skytte describes cruise customers as leading the market on both fuel efficiency and cybersecurity for exactly that reason.
Certification does not end at delivery
Where the industry still has ground to cover, in Skytte’s assessment, is through-life maintenance. Historically, vessel owners-maintained automation systems reactively, addressing faults only once something went wrong.
To navigate this distinction, many operators are turning to naval cybersecurity as-a-service (CSaaS). CSaaS on naval vessels moves the burden of cybersecurity from the navigators to the cybersecurity suppliers. Vessels that choose CSaaS do not need to worry about hiring sailors with cybersecurity expertise, as the protection and maintenance is provided directly by the cybersecurity company.
Another benefit of CSaaS is that it reduces insurance costs—or at least reputation risk—as in case of an attack, the fault lies on the service operator rather than the sailors themselves.
Interest in ‘as-a-service’ protection has grown across subsectors. For example, there are many critical infrastructure sites that hire counter-drone technology providers as a service because this is easier for site managers than protecting against drone threats on their own.
Cybersecurity does not tolerate that approach, since firmware left unpatched for years becomes progressively easier to exploit. NACOS Marine has built a digital asset inventory into its systems that reports current equipment, firmware versions and installation dates, information the company uses to support owners with updates and a dedicated cyber maintenance contract for fleets already at sea.
That distinction, between a vessel that is cyber-secure at delivery and one that stays that way through a 30-year service life, is likely to define naval procurement conversations for the remainder of the decade. As Walker puts it, rising numbers of cyberwarfare incidents against naval vessels in contested waters will continue to increase demand for systems that protect freedom of navigation, reduce surveillance exposure and guard against mission disruption. Physical threats to maritime assets are not going away. What has changed, both analysts agree, is that no procurement decision can treat the digital threat as a secondary concern any longer.
