Cyberattacks against the global maritime industry more than doubled in 2025, rising 103% to 828 recorded incidents from 408 the year before, according to research published by maritime threat intelligence firm CYTUR.

The shift in these attacks is as significant as their scale. Rather than targeting data alone, attackers are increasingly going after the operational technology (OT) that keeps ships moving, ports running and offshore assets producing.

For Christian Madsen Skytte, an automation specialist at NACOS Marine, the change reflects a simple reality: systems that were once isolated on board are now part of a connected network. “Historically, automation, navigation and dynamic positioning (DP) systems operated as largely independent platforms, with each serving a distinct function onboard vessel. Today, they get more and more connected, especially to internet and to shore, and that of course brings in some additional risk.”

An expanding attack surface

Navigation, automation and DP systems fall into the category of OT rather than information technology (IT) and have not traditionally been built with the same cybersecurity safeguards. According to Skytte, the greatest exposure on board a vessel today is rarely a targeted hack.

It is far more likely to be an unintended error: a crew member plugging a network cable into the wrong port or introducing a virus by way of an infected USB stick, simply because they were not trained to recognise the risk.

Geopolitics has sharpened this picture. Fox Walker, senior defence analyst at GlobalData, points to recent operations in the Strait of Hormuz, where GNSS jamming and spoofing techniques have been used to disrupt commercial and military vessels attempting to navigate safely through a contested waterway. Known attacks have also used cyberwarfare techniques during periods of regional conflict to compromise CCTV systems and other digital infrastructure to track vessel movement. Elsewhere, maritime operations tied to an ongoing regional conflict have increasingly relied on unmanned surface and underwater vehicles for intelligence gathering and electronic warfare, platforms that are themselves highly vulnerable to cyberattack given their dependence on remote command links rather than a crew on board.

That vulnerability is driving investment in more resilient uncrewed systems. The US Navy’s Extra Large Uncrewed Undersea Vehicle (XLUUV) programme, for example, recently selected Kongsberg and Oceaneering International to develop a platform capable of intelligence, surveillance and reconnaissance operations without reliance on GPS, an approach Walker cites as a benchmark for cyber-resilient design in unmanned maritime platforms.

The scale of the underlying threat is easier to see in commercial shipping data, where GPS and satellite navigation interference has become a daily occurrence rather than an isolated event. Industry monitoring in 2025 recorded roughly 1,000 GPS disruption incidents a day, affecting more than 40,000 vessels, with two high-profile cases underlining the physical consequences.

In May 2025, the containership MSC Antonia ran aground near Jeddah after its navigation data was corrupted by GPS spoofing, and the following month two tankers collided in the Gulf, with spoofing suspected as a contributing factor. Incidents of this kind are precisely why regulators and naval customers alike are treating navigation system integrity as a safety issue rather than a purely digital one.

A standard, not a specification

With the rapid digitisation of maritime operations exposing vessel networks to sophisticated cyberthreats, industry bodies are proactively working on updating regulations that would potentially strengthen cyber resilience.

For example, updates were made to regulations from the International Association of Classification Societies (IACS) to better tackle cybersecurity concerns on ships. IACS E26, for instance has set our cybersecurity requirements for vessels and ship building processes. Conversely, IACS E27 regulations address cyber resilience of individual systems and equipment installed on the ship, with an emphasis on the security of third-party equipment and systems.

Additionally, naval programmes typically layer their own government-specific rules on top of this baseline, most of them modelled on information technology security frameworks rather than OT.

For Skytte, that distinction matters. Cybersecurity in IT is relatively mature, while OT security remains at an earlier stage. This is particularly important for vessels, where OT systems control critical functions including water, power and propulsion.

“We are met with many individual specific requirements outlined in our navy customers specifications. Rather than addressing all these single clauses in isolation, NACOS Marine aims to deliver an overall design targeted at SL3. We believe that it is in the best interest of our customers and us as suppliers to follow a common standard that ensures continuously delivery of secure solutions,” Skytte said.

In December 2025, the company’s NACOS Platinum Integrated Navigation System (INS) received DNV Type Approval for Security Profile 1 under IEC 61162-460 Edition 3, a standard accepted by IACS as an alternative to UR E26/E27.

Resilience built into the architecture

The move towards SL 3 certification reflects a wider change in naval requirements. Instead of procuring separate navigation, automation and DP systems, navies are increasingly looking for integrated bridge and platform management systems (IBPMS). The approach enables smaller crews to manage a wider range of functions from a single station.

But integration itself is not new. Skytte points to the market release of the Platinum navigation and automation control system in 2010 as an early example of the same design principle, well before the current wave of interest from naval customers.

What has changed is the demand behind it. Navies are moving toward leaner manning, largely because qualified sailors are harder to recruit, and integration would be a practical way to let fewer people manage increasingly complex systems. That trend cuts both ways from a security standpoint. A single operator managing multiple systems from one screen is more efficient, but it also means a single compromised station has a larger blast radius than in the days of isolated, single-purpose consoles.

Consolidating control onto fewer screens raises the stakes for cybersecurity, and NACOS Marine’s approach has been to build in isolation rather than assume the network will remain secure. Cybersecurity is incorporated throughout the system, from product development through to lifecycle management. In the event of a network storm or attack, a vessel can disconnect its radar from the network ring and continue to use it independently, even if automated route transfer from the chart planning station is lost.

At the automation level, core functions run on programmable logic controllers rather than the central computers. This means that even a full loss of onboard computing leaves independent panels able to operate individual processes, with backup systems available to rebuild the automation and navigation environment if needed.

This redundancy is deliberate rather than incidental, and it applies as much to cruise vessels as to naval ones. For cruise operators, where the loss of a passenger, a collision or an attack-driven shutdown carries a direct reputational cost, resilient automation is less a compliance exercise than an operational safeguard, and Skytte describes cruise customers as leading the market on both fuel efficiency and cybersecurity for exactly that reason.

Certification does not end at delivery

Where the industry still has ground to cover, in Skytte’s assessment, is through-life maintenance.

Historically, vessel owners-maintained automation systems reactively, addressing faults only once something went wrong.

To navigate this distinction, many operators are turning to naval cybersecurity as-a-service (CSaaS). On naval vessels, the model shifts responsibility for monitoring and managing cybersecurity from the crew to specialist providers, giving operators access to expertise that may be difficult to maintain in-house.

The model is gaining traction across other critical infrastructure subsectors. Many sites, for example, use counter-drone technology providers on a service basis, allowing site managers to access specialist protection without developing the capability themselves.

For naval cybersecurity, however, the value of such support extends beyond responding to individual threats. Vessels need ongoing monitoring and maintenance as systems, software and threats evolve. Firmware that remains unpatched for years, for example, can become increasingly vulnerable to exploitation. This makes cybersecurity a continuing requirement rather than a capability that can be installed and left unchanged.

According to Skytte, the company has built a digital asset inventory that produces a report of current equipment, firmware versions and installation dates. NACOS Marine uses that information to supply owners with the latest firmware and updates, and it underpins a cyber maintenance contract available to fleets already at sea.

That distinction, between a vessel that is cyber-secure at delivery and one that stays that way through a 30-year service life, is likely to define naval procurement conversations for the remainder of the decade.

Walker believes the rising numbers of cyberwarfare incidents against naval vessels in contested waters will continue to increase demand for systems that protect freedom of navigation, reduce surveillance exposure and guard against mission disruption.

Physical threats to maritime assets are not going away. What has changed, both analysts agree, is that no procurement decision can treat the digital threat as a secondary concern any longer.