05
Mon, Oct

CYTUR finds 94% of marine equipment assessments warrant cyber risk treatment

CYTUR finds 94% of marine equipment assessments warrant cyber risk treatment

Maritime cyber security
CYTUR finds 94% of marine equipment assessments warrant cyber risk treatment

A new analysis of more than a dozen marine equipment cyber risk assessments has found that 94% of the systems examined were rated at a level where cyber risk treatment should be considered or is required, with about 60% classified as requiring treatment.

The findings, published by cybersecurity company CYTUR in its September 2026 Threat Brief, highlight the limitations of relying on Common Vulnerabilities and Exposures (CVEs) alone to assess the cyber risk of shipboard equipment. CYTUR said the assessments showed that actual risk was shaped by a combination of vulnerabilities, network exposure, connectivity and the potential operational impact of a compromise.

The company stressed that the 94% figure does not mean that 94% of marine equipment is vulnerable, as the systems assessed were commissioned by CYTUR clients and were not a random or representative sample of the wider maritime equipment market.

CVE numbers do not tell the full story

The assessments were reclassified using the risk treatment criteria of IACS Recommendation 171. Under the framework, a Risk Level (RL) below 4 is considered “Optional”, a level of 4 to 12 is “Appropriate”, while a level above 12 means that risk treatment is “Required”.

CYTUR found that about 34% of the assessed systems were in the Appropriate category and about 60% were in the Required category, while only 6% fell into the Optional range.

The company noted, however, that the risk level is not determined simply by the number of CVEs present. IACS Rec. 171 considers the system’s category, the potential impact of an incident and the likelihood of an attack.

One comparison illustrated the difference. An Integrated Automation System (IAS) with more than 200 identified CVEs received a Risk Level of 20, while another IAS with about 20 CVEs received a Risk Level of 16. Both were therefore classified as requiring risk treatment.

According to CYTUR, the finding demonstrates that a lower CVE count does not necessarily translate into proportionally lower cyber risk. The relevance of vulnerabilities depends on whether they can actually be reached, whether they provide a pathway to other systems and what a compromise could mean for vessel operations.

Implications for shipowners, shipyards and equipment manufacturers

CYTUR said the findings have different implications across the vessel lifecycle.

For shipowners and ship managers, the company recommends obtaining an asset inventory covering hardware, software, firmware and active ports before equipment is delivered, prioritising risks based on exposure, connectivity and impact rather than CVE counts, and establishing periodic reassessments during vessel operation.

For shipyards, CYTUR recommends including the disabling of unused ports and services and firmware currency in equipment delivery conditions. It also calls for measured scans during system integration and sea trials to identify differences between the intended and actual network configuration, with corrective measures verified through re-measurement.

For equipment manufacturers, the company recommends maintaining a software bill of materials covering both in-house products and bundled components, checking unused ports, services and management interfaces in default configurations before shipment, and providing post-remediation verification results to shipyards and shipowners.

Four factors shape actual cyber risk

Based on the assessment results, CYTUR identified four factors that need to be considered together when evaluating ship equipment cyber risk:

  • Vulnerability: Whether known vulnerabilities such as CVEs exist.
  • Exposure: Which ports and services are actually active and whether authentication and encryption are used.
  • Connectivity: Which networks the equipment is connected to and whether it has pathways to other onboard systems.
  • Impact: The potential effect of a compromise on vessel operations, safety and environmental performance.

CYTUR said these factors help explain why two systems with similar or very different CVE counts can have substantially different risk profiles.

For example, a system containing numerous known vulnerabilities may present a lower likelihood of attack if access is tightly restricted. Conversely, a system with relatively few CVEs could represent a higher risk if it has an exposed remote management function, is connected to other critical systems and performs a core vessel function.

Overall, CYTUR said the assessments show that ship equipment cybersecurity should move beyond simply identifying how many vulnerabilities exist.

The company’s analysis found that the practical risk depends on whether vulnerabilities can be reached, how equipment is connected within the vessel, what services are exposed and what consequences a compromise could have.

The company also emphasised that the objective of cybersecurity is not necessarily to eliminate all risk, but to understand remaining risks, justify their acceptance where necessary and continue managing them throughout the equipment’s operational lifecycle.

Content Original Link:

Original Source SAFETY4SEA www.safety4sea.com

" target="_blank">

Original Source SAFETY4SEA www.safety4sea.com

SILVER ADVERTISERS

BRONZE ADVERTISERS

Infomarine banners

Advertise in Maritime Directory

Publishers

Publishers