Publication:
Port cyberattacks from 2011 to 2023: a literature review and discussion of selected cases

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

Research Projects

Organizational Units

Journal Issue

Abstract

Cyberattacks pose a significant threat to seaports worldwide. While numerous scholars have endeavored to address these threats, their findings are often limited in practicality, applying to only a few ports. This paper aims to contribute to the extant literature by presenting and discussing 15 case studies of port cyberattacks that occurred from 2011 to 2023. These cases encompass six instances in Europe, six in America, two in Asia, and one in Africa. The study employs a twofold methodology, consisting of a comprehensive literature review and a personal assessment. Several key insights emerge. First, two primary motivations drive port cyberattacks: (a) the demand for ransom payments and (b) the desire to cause severe disruptions. Second, ransomware was the most common threat used to extort payments, followed by malware and DDoS attacks, which aimed to inflict operational disruption. Third, weaknesses in cybersecurity procedures and a lack of awareness among staff members emerged as significant contributors to cyber vulnerabilities. Forth, ports that quickly detected threats and implemented response measures were able to minimize operational impacts, ensuring the swift resumption of services and the maintenance of service continuity. Fifth, collaborative efforts with external partners and officials expedited response and recovery processes by facilitating threat investigation and solution identification. In light of these findings, it becomes imperative for all ports to develop comprehensive cyber disaster management plans, covering four key phases: preparedness, response, recovery, and mitigation. These plans should encompass three critical aspects of cybersecurity hygiene: human factors, procedural improvements, and infrastructure enhancements. Such practices are instrumental in bolstering a port’s resilience and mitigating the risks associated with cyberattacks.

Description

Keywords

Case studies, Cybersecurity, DDoS attack, Networks, Ransomware, Seaports, Systems, Vulnerability

Citation

Maritime Economics and Logistics, 26(1), 105-130, 2024

Collections

Endorsement

Review

Supplemented By

Referenced By