Article The Maritime Edge: Issue 5 | Maritime Technology Insights | Insight UK

 

Issue 5

The Maritime Edge

 

 

By   / 30 Sep 2026

You Passed the Audit. The Attacker Still Logged In.

Compliance proves you wrote the access policy. It doesn’t prove you would catch it being used against you. In maritime cybersecurity, that gap is where fleets are breached.

By Simon Fotakis │ Maritime CISO, Insight │ Maritime Hub, Issue 5

By 2026, the maritime cybersecurity rulebook has put identity firmly in scope. IMO Resolution MSC.428(98) folds cyber risk into the ship's safety management system¹. BIMCO's Guidelines on Cyber Security Onboard Ships, Version 5, name access control and user privilege management as core controls². Your next ISM audit and your SIRE 2.0 assessment will both require that an access control policy is present. And yet, in the same year, more than 250 maritime, port and energy firms leaked credentials, 63% of them default admin accounts³. Every one of those firms could have probably passed a policy audit the week before. The rules had put identity in scope. The audits confirmed the paperwork existed. But the credential still leaked.

A certificate is a snapshot of your paperwork. It is not a control that catches a stolen login at 03:00.

That gap is not a technology problem but a fundamentally structural one. A clean audit proves the access policy exists and was evidenced on the day. It proves nothing about whether a departed superintendent's login still works, or that a shared bridge credential is not present in a crew WhatsApp group. At Insight, we view maritime identity risk through a three-layered lens that must line up: the Certificate you hold, the Credential the attacker uses, and the Catch that truly defends you. Get the first right but miss the third, and you can be compliant and compromised all at once.

The Certificate: What Compliance Actually Proves

Ask a maritime CISO what their last cyber audit proved, and the honest answer is: the policy existed on audit day. That is not negligible. But BIMCO v5 is explicit that a cyber risk assessment must be revisited whenever networks, connections, hardware and accounts change², which, on a live fleet, implies continuously.

A point-in-time certificate cannot satisfy a continuous requirement. It samples the estate, then moves on. Malicious actors do not.

This is where continuous identity management earns its keep. Insight builds a live identity store across ship and shore, capturing every user and machine identity, its owner, its privileges and usage. The result is an auditable evidence trail that an ISM auditor or SIRE 2.0 assessor can recognise. The outcome the client buys is not another static record; it is a defensible view of identity risk, accessible whenever they need it any time, any day.

The Credential: Where the Attacker Actually Gets In

2026 threat reporting is blunt: maritime incidents are increasingly identity-centric and persistence-driven, not purely technical⁴. The modern attacker rarely bothers with a clever exploit; a valid credential is often enough. In November 2025, the Black Sea logistics agency Stark Shipping had roughly 226 GB of manifests and financial files exfiltrated, through what looks like exposed remote access and admin-account phishing⁵. On another occasion, a widely deployed maritime VSAT terminal was found exposing its private satellite-network authentication key, through an unauthenticated management interface⁶.

The credential, not the exploit, is the way in.

Thus, the fix is not another certificate; it is true access control, that works in the operating environment. Shared and default accounts need to be eliminated. Multi-factor authentication and conditional access need to be enforced ashore and, as connectivity improves, extended shipside wherever practical. Privileged-access management should govern fleet platforms, while; OEMs, satellite providers and remote-support teams, should use time-bound (Just in Time), brokered access.

The supply chain reaches your fleet through logins, so it sits inside your identity perimeter whether your audit scope reaches it or not.

The Catch: The Detection That Actually Defends

IMO's six functions include “Detect” for a reason¹. Resilience is not proven by holding a certificate; it is proven by detecting a login being used against you in real time and shutting it down. That requires a 24/7 AI-powered maritime SOC watching identity signals and anomalous behaviour; impossible-travel logins, privilege escalation, dormant accounts reactivating, or a machinery account authenticating, from a continent away. And when an alert fires, an approved playbook kicks in; identification to isolation, containment and reporting, not a shrug and a password reset. The evidence trail should answer the questions a charterer or SIRE 2.0 assessor will ask; which account was affected, what was the operational and safety impact, what containment was applied, and how was the incident closed?

The fair objection? “We already run detection. Our compliance programme drives real monitoring.” If that is true, you are ahead of much of the market, and this article is not arguing against well-run detection programmes. But for many vessel operators, the gap remains. The frameworks ask for the Catch, yet certification too often rewards the Certificate and never tests for it.

The CISO's Recommended Roadmap: One Model, Three Moves

1. Baseline the Certificate. Honestly
List every account, human and machine, with its owner, privileges, last use and authentication method, then keep that view current across ship and shore. Most vessel operators cannot answer “who can log in to this vessel, and with what rights” in under a day. When kept live, that answer is more valuable than any certificate on the wall.

2. Close the Credential Gap
Eliminate shared and default accounts where found. Enforce MFA and conditional access wherever possible. Time-box and log OEM and remote-support access. Revoke a leaver’s access across ship and shore the same day. The process must work 24/7 with a vessel mid-ocean not just in a shore workshop the week before an inspection.

3. Build the Catch, and Measure It
Stand up 24/7 identity monitoring and tested ‘suspicious login’ playbooks. Measure identity exposure at board-level using; Key Risk Indicators, Key Performance Indicators, privileged and shared account counts, share protected by MFA, mean time to revoke a leaver, and the time to detect and contain a misused login. Those identity metrics indicate whether you would survive an actual attack. A certificate only proves you survived audit day.

A fleet does not become resilient the day it passes. It becomes resilient when it watches its own keys.

The sector is past debating whether identity is the front door. The real question is whether vessel operators can align the Certificate, the Credential and the Catch into one continuous operating model. Those who stop at the certification may prove compliance, but it does not prove resilience. Leaders go further, treating identity as a live operational discipline across fleet, shore, OEMs and security teams. Insight helps orchestrate that model end-to-end, from identity governance and privileged-access control through to a maritime SOC that catches trusted access, turned hostile.

You passed the audit. Would you catch the login?

 

Next in Issue 6: How Identity, Operational Technology segmentation and the incident playbook come together when a vessel is mid-voyage.

 
Simon Fotakis headshot

About the author

Simon Fotakis is a Maritime CISO at Insight, where he advises fleet operators on cyber risk across ship and shore. He has structured and led security programmes protecting assets across organisations generating up to $10 billion in revenue, with significant maritime experience gained at some of the world's largest ship managers. He is CISSP certified, and his focus spans maritime cyber architecture, ship-to-shore security, identity and access governance, and turning regulatory frameworks into working operational resilience

Insight sources:
¹ IMO, Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems: folds cyber risk into the ISM Code across govern, identify, protect, detect, respond, recover. imo.org.
² BIMCO, ICS et al., “The Guidelines on Cyber Security Onboard Ships, Version 5” (14 Nov 2024): names access control and user privilege management, and requires the risk assessment to stay current as accounts and connections change. maritimeglobalsecurity.org.
³ Industry threat reporting (FortiBleed disclosure) (Jul 2026): 250+ maritime, port and energy firms exposed; 63% default admin credentials; 87% internet-facing management interfaces.
⁴ Marlink Security Operations Centre, “Cyber Intelligence Report for Maritime 2026” (Apr 2026): incidents now identity-centric and persistence-driven rather than purely technical. marlink.com.
⁵ Public breach intelligence, Nova ransomware listing, Stark Shipping LLC (Nov 2025): ~226 GB exfiltrated via exposed remote access or admin-account phishing.
⁶ CISA / JPCERT, CVE-2026-38059, ST Engineering iDirect iQ-Series VSAT terminals (Jul 2026): unauthenticated management interface exposes the terminal private key. cisa.gov.
 

Further Reading:  From the Insight Maritime Hub and the Industry

Publication The Quick Take Theme Action
Marlink: Cyber Intelligence Report for Maritime 2026 The threat picture behind this piece: incidents are now identity-centric and persistence-driven. Threat Intel Read Report
BIMCO / ICS: Guidelines on Cyber Security Onboard Ships v5 The industry blueprint naming access control and user privilege management, and demanding a live risk assessment. Guidance Read Guidance
IMO: Resolution MSC.428(98) Folds cyber risk into the ISM Code's safety management system across six functions. Regulation Read Resolution
CISA / JPCERT: CVE-2026-38059 (VSAT terminals) When the ship-to-shore link itself hands over a trusted authentication key. Advisory Read Advisory
Insight: Maritime Cyber Readiness How Insight builds continuous identity governance, privileged-access control and a 24/7 maritime SOC. Insight Read More
Insight: Maritime Edge Issue 6 (preview) How Odfjell successfully drove onboard engagement by developing practical, user-friendly AI tools tailored for ship crews. Preview

Take the next step with Insight

From strategic workshops to scalable solutions, we're ready to help you accelerate transformation and realise the full value of your data and Al investments.