For generations, seafarers have been trained to think about safety. Before starting a job, we identify hazards, assess the risks, and put safeguards in place. We conduct toolbox meetings, drills, and safety inspections because we know that one small mistake can sometimes lead to a much bigger incident.
Today, the same thinking needs to extend to our digital environment.
Modern ships depend heavily on technology. ECDIS, satellite communications, cargo systems, machinery monitoring, electronic documentation, remote technical support and ship-shore applications are now part of our everyday operations.
With this increased connectivity comes another operational risk: cybersecurity.
For a seafarer, cybersecurity does not need to begin with complicated IT terminology. It starts with situations we may experience during an ordinary working day.
Imagine receiving an email that appears to come from the office, asking you to urgently open an attachment or follow a link. Would you immediately click it, or would you first verify the sender?
A USB drive may be brought onboard containing documents, charts, or software updates. Do we know where it came from and whether it is safe to connect?
Passwords are another simple example. Sharing passwords, writing them beside a workstation or using the same password across different systems may be convenient, but it can weaken the security of the entire system.
Remote access also deserves attention. Ships regularly require support from equipment makers, service engineers, and shore teams. But before allowing somebody to remotely access a shipboard computer, we should know who is connecting, why access is required, whether it is authorized and when the connection should be closed.
These are not purely IT problems. They are shipboard operational risks.
There is a strong similarity between traditional shipboard safety and cybersecurity.
We would not allow an unknown person to enter a restricted space without checking their identity. So why should we allow unknown access to a computer or network?
We would not use equipment without considering whether it is safe. The same thinking should apply before connecting an unknown USB device.
When an alarm appears on the bridge or in the engine room, we investigate it rather than simply ignoring it. Unusual computer behaviour should create the same curiosity.
This is where cyber hygiene becomes part of normal seamanship.
Reporting is particularly important. Suppose someone accidentally clicks a suspicious link. If it is reported immediately, the vessel and shore team have an opportunity to investigate and take action. If the person stays silent because of fear of blame, a manageable situation could develop into something much more serious.
A strong cyber culture, just like a strong safety culture, should therefore encourage early reporting, learning, and continuous improvement.
Cybersecurity does not require every seafarer to become an IT specialist. What we need is awareness.
While co-authoring Hacked Hull – Cybersecurity & Cyber Risk Management, this practical gap was something we wanted to address. The book was developed as a resource to help Masters, officers and crew relate cybersecurity principles to the realities of working onboard.
Ultimately, the objective is bigger than any book. It is about making cyber awareness part of our everyday maritime culture.
We protect our people. We protect our ship. We protect our cargo and the environment.
Today, we must also protect our systems and data.
And perhaps the most important firewall onboard is not a piece of software.
It is an aware and well-informed seafarer.
The co-author of Hacked Hull: Cybersecurity and the former IT/Cybersecurity Manager for the Shoei fleet. He is an alumnus of the National University of Singapore, where he completed the programme Cybersecurity: Building Cyber Resilience. He also holds an MBA in Finance from SP Jain School of Global Management. With extensive seagoing and shore-based experience, his professional interests include maritime cybersecurity, fleet digitalisation, marine safety and operational risk management. He advocates treating cyber hygiene as an essential part of everyday onboard safety culture and empowering seafarers to remain the strongest line of defence against cyber threats.