Cybersecurity Training for the Maritime Sector
Role-based, scenario-driven training built around the way ports, vessels, and cross-border trade actually operate — not a generic awareness course with a shipping logo bolted on.
Four modules, built around who touches the risk
General Cybersecurity & Risk Awareness for the Maritime Industry
The shared foundation — how and why the sector is targeted, and the regulatory landscape everyone must understand.
Ports & Port Officials
Terminal systems, port community platforms, and physical-cyber convergence at the port.
Mariners & Seafarers
Shipboard IT/OT systems, navigation integrity, and safe practice at sea.
Customs Officials — with Extensive Data Governance
Trade data classification, access control, and cross-border data handling, covered in depth.
General Cybersecurity & Risk Awareness for the Maritime Industry
Maritime operations run on an unusual mix of old and new: navigation and cargo systems designed decades ago, now bridged to satellite links, port networks, and cloud platforms. That IT/OT convergence, combined with a sprawling, multi-party supply chain — carriers, terminals, agents, customs, and financial institutions all exchanging data — makes the sector a distinctive and growing target. This module gives every participant the shared vocabulary, threat picture, and regulatory context that the role-specific modules build on.
Core Risk Areas Covered
GPS & AIS Spoofing / Jamming
Recognizing manipulated positioning and tracking data used to mislead vessels or mask illicit activity.
Ransomware & Malware
How ransomware has disrupted terminals and shipping lines, and how to reduce exposure.
Phishing & Business Email Compromise
Freight-fraud and payment-diversion schemes that specifically target shipping and logistics correspondence.
OT & Shipboard Systems Exposure
ECDIS, ballast, engine, and cargo-management systems — and what happens when they're networked.
Third-Party & Supply Chain Risk
Vendors, agents, and port systems as entry points into otherwise well-defended organizations.
Regulatory Non-Compliance
The operational and legal exposure of falling short of current maritime cyber risk requirements.
The Regulatory Landscape, Explained Plainly
IMO Resolution MSC.428(98)
Cyber risk management has been mandatory within ships' Safety Management Systems (ISM Code) since 1 January 2021.
IACS UR E26 & E27
Unified requirements for cyber resilience of ships and onboard systems, applying to new ships contracted from 1 July 2024.
EU NIS2 Directive
Brings ports and maritime transport into scope as essential/important entities, with national transposition from October 2024.
Regulatory emphasis is tailored to your flag state, operating region and jurisdiction — tell us your country in the form below and we'll scope the frameworks that matter most to you.
Built Around Who Actually Touches the Risk
After the shared foundation, participants split into focused tracks. Ports and vessels face very different operational realities — so the training does too.
Ports & Port Officials
Port Authorities · Terminal Operators · Harbour Masters
Mariners & Seafarers
Masters · Officers · Crew
"Why split the training this way? A port official needs to reason about terminal networks and vendor access; a seafarer needs to recognize spoofed navigation data mid-voyage. Teaching both groups the same generic content wastes time and leaves the sector's real gaps unaddressed — so each track is built from the systems and decisions that group actually owns."
Port & Port Official Scenarios
Mariner & Seafarer Scenarios
Format for These Tracks
Customs Officials
Customs Officers · Trade Compliance Teams · Border Agencies
Customs sits at a unique intersection: every shipment brings manifests, declarations, valuations, and personal data through officials' hands, often shared across agencies and borders. A lapse here isn't just a cybersecurity incident — it's a trade-data governance failure. This track goes deeper on data governance than any other module in the program.
Data Governance — Covered in Depth
- Instructor-led workshops
- Self-paced e-learning modules
- Scenario & tabletop exercises
- Role-specific refreshers
All four modules can be delivered together as a full program, or the role-specific tracks can be licensed independently for organizations that only need one audience covered.
The stakes behind the training
One Record, Many Hands
A single shipment's data can pass through carriers, agents, and multiple government systems — every handoff is a governance decision.
Compliance Is Not Optional
Trade data governance failures carry legal exposure alongside the security risk — this module treats them as one problem.
People, Not Just Systems
Most data governance failures are procedural, not technical — the wrong person seeing the wrong record. Training targets exactly that.
Bring this training to your fleet, port, or agency
Schedule a consultation to scope the right modules for your teams. Tell us your country or flag state and we'll tailor the regulatory focus and delivery format to your region.
Modular by design
Run the full four-module program, or license just the tracks your organisation needs — port, vessel, customs, or all three built on the shared foundation module.
Looking for a different sector?
Explore our full range of accredited training categories.
