Request a Consultation
Specialized Industry Training — Sector-Specific Training

Cybersecurity Training for the Maritime Sector

Role-based, scenario-driven training built around the way ports, vessels, and cross-border trade actually operate — not a generic awareness course with a shipping logo bolted on.

+103%
Rise in reported maritime cyber incidents, 2025 vs. 2024
2021
Cyber risk management became mandatory in ships' Safety Management Systems
3
Major hub ports hit by ransomware in recent incidents: Rotterdam, Los Angeles, Busan
1
Foundation Module — completed by every participant before entering their role-specific track

General Cybersecurity & Risk Awareness for the Maritime Industry

Maritime operations run on an unusual mix of old and new: navigation and cargo systems designed decades ago, now bridged to satellite links, port networks, and cloud platforms. That IT/OT convergence, combined with a sprawling, multi-party supply chain — carriers, terminals, agents, customs, and financial institutions all exchanging data — makes the sector a distinctive and growing target. This module gives every participant the shared vocabulary, threat picture, and regulatory context that the role-specific modules build on.

+103%
Increase in reported maritime cyber incidents, 2025 vs. 2024 (CYTUR, 2026)
1,000+
Vessels facing daily GPS interference in the Red Sea corridor alone
3
Major hub ports recently hit by ransomware: Rotterdam, Los Angeles, Busan

Core Risk Areas Covered

GPS & AIS Spoofing / Jamming

Recognizing manipulated positioning and tracking data used to mislead vessels or mask illicit activity.

Ransomware & Malware

How ransomware has disrupted terminals and shipping lines, and how to reduce exposure.

Phishing & Business Email Compromise

Freight-fraud and payment-diversion schemes that specifically target shipping and logistics correspondence.

OT & Shipboard Systems Exposure

ECDIS, ballast, engine, and cargo-management systems — and what happens when they're networked.

Third-Party & Supply Chain Risk

Vendors, agents, and port systems as entry points into otherwise well-defended organizations.

Regulatory Non-Compliance

The operational and legal exposure of falling short of current maritime cyber risk requirements.

The Regulatory Landscape, Explained Plainly

IMO Resolution MSC.428(98)

Cyber risk management has been mandatory within ships' Safety Management Systems (ISM Code) since 1 January 2021.

IACS UR E26 & E27

Unified requirements for cyber resilience of ships and onboard systems, applying to new ships contracted from 1 July 2024.

EU NIS2 Directive

Brings ports and maritime transport into scope as essential/important entities, with national transposition from October 2024.

Regulatory emphasis is tailored to your flag state, operating region and jurisdiction — tell us your country in the form below and we'll scope the frameworks that matter most to you.

Role-Specific Tracks

Built Around Who Actually Touches the Risk

After the shared foundation, participants split into focused tracks. Ports and vessels face very different operational realities — so the training does too.

2

Ports & Port Officials

Port Authorities · Terminal Operators · Harbour Masters

Terminal Operating System (TOS) security and network segmentation
Port Community System data-exchange risk between carriers, agents, and customs
Physical-cyber convergence: access control, CCTV, and IoT sensor networks
Vendor and contractor access — managing third-party risk at the port
Coordinating incident response across port authority, terminal operators, and shipping lines
Working lessons from ransomware incidents at major hub ports
3

Mariners & Seafarers

Masters · Officers · Crew

Shipboard IT/OT systems: ECDIS, GPS/AIS, ballast and engine control
Recognizing and responding to GPS/AIS spoofing and jamming at sea
Phishing and social engineering over satellite and crew communications
Safe use of USB media and personal devices onboard
Cyber incident reporting under the ISM Code's cyber risk provisions
Maintaining safe navigation when electronic systems are compromised

"Why split the training this way? A port official needs to reason about terminal networks and vendor access; a seafarer needs to recognize spoofed navigation data mid-voyage. Teaching both groups the same generic content wastes time and leaves the sector's real gaps unaddressed — so each track is built from the systems and decisions that group actually owns."

Port & Port Official Scenarios

Simulated phishing targeting the terminal operations inbox
Tabletop exercise: ransomware isolates the TOS mid-shift
Reviewing a vendor remote-access request end to end

Mariner & Seafarer Scenarios

Identifying a spoofed AIS track versus a genuine one
A suspicious USB drive handed over in port — what next?
Escalating a navigation anomaly through the correct channel

Format for These Tracks

On-site at the port Onboard / pre-departure briefings Virtual instructor-led Self-paced e-learning
4
With extensive coverage of data governance — the discipline this role depends on most

Customs Officials

Customs Officers · Trade Compliance Teams · Border Agencies

Customs sits at a unique intersection: every shipment brings manifests, declarations, valuations, and personal data through officials' hands, often shared across agencies and borders. A lapse here isn't just a cybersecurity incident — it's a trade-data governance failure. This track goes deeper on data governance than any other module in the program.

Data Governance — Covered in Depth

Data classification and sensitivity labelling for manifests, declarations, and personal data
Role-based access control and least-privilege for customs and single-window systems
Safeguards for cross-border and inter-agency data sharing
Data retention, archival, and secure disposal schedules
Audit trails and accountability for every access to trade data
Insider risk and separation of duties in high-value clearance decisions
Protecting the integrity of fraud-detection and risk-targeting systems
Breach identification and notification readiness
Delivery Format
  • Instructor-led workshops
  • Self-paced e-learning modules
  • Scenario & tabletop exercises
  • Role-specific refreshers

All four modules can be delivered together as a full program, or the role-specific tracks can be licensed independently for organizations that only need one audience covered.

Why It Matters at This Scale

The stakes behind the training

One Record, Many Hands

A single shipment's data can pass through carriers, agents, and multiple government systems — every handoff is a governance decision.

Compliance Is Not Optional

Trade data governance failures carry legal exposure alongside the security risk — this module treats them as one problem.

People, Not Just Systems

Most data governance failures are procedural, not technical — the wrong person seeing the wrong record. Training targets exactly that.

Register Interest

Bring this training to your fleet, port, or agency

Schedule a consultation to scope the right modules for your teams. Tell us your country or flag state and we'll tailor the regulatory focus and delivery format to your region.

Modular by design

Run the full four-module program, or license just the tracks your organisation needs — port, vessel, customs, or all three built on the shared foundation module.

We reply within one business day. Prefer email? Write to info@thecyberdiplomat.com.

Looking for a different sector?

Explore our full range of accredited training categories.

View All Training