Maritime cyber risk increasingly driven by human error – report

Marlink has released its Cyber Intelligence Report for Remote Operations 2026, with its analysis suggesting that structural weaknesses in connected environments are increasingly being exploited through user credentials rather than technical vulnerabilities.

The report, which is based on continuous monitoring from global Security Operations Centres (SOCs), indicates that 69% of observed risks are now linked to compromised identity and credentials. In contrast, only 12% of risks relate to technical flaws.

As digital dependency increases across remote environments, these vulnerabilities allow attackers to exploit trusted access pathways, making incidents more difficult to detect and increasing the likelihood of operational downtime.

The report notes that the convergence of Information Technology (IT) and Operational Technology (OT) is further expanding exposure across digitalised operations on ships and industrial sites. In 2025, Marlink found that over 70% of assessed sites had undocumented or poorly secured connections, and between 30 and 40% of OT assets were initially unmanaged.

“The data confirms a clear shift in how cyber threats materialise in remote environments,” said Nicolas Furgé, President, Marlink Cyber.

“Addressing these structural weaknesses requires more than additional tools. It demands an identity-first security model, stronger control of trusted access, and closer integration between cyber security and operational infrastructure.”

Phishing simulations conducted by the company revealed that 20% of users clicked on malicious links, while 11% disclosed credentials. Only 11% of users reported the incidents to their organisations.

Ransomware activity is also scaling within remote environments. Incidents detected across Marlink-monitored environments rose from 5,740 in 2024 to 7,793 in 2025, with more than half of these targeting transportation, energy, and manufacturing. In maritime settings, 82% of alerts were concentrated in crew network zones, confirming that user-facing systems are becoming the primary attack surface.

To improve resilience, the report recommends the implementation of an identity-first security model. Measures such as multi-factor authentication, network segmentation across IT and OT, continuous monitoring, and targeted user awareness programmes are highlighted as useful steps to reducing exposure and improving security.

The full report is available for download here.

Share this story

About the Author

Picture of Rob O'Dwyer
Rob O'Dwyer

Rob is Chief Network Officer and one of the founders of Smart Maritime Network. He also serves as Chairman of the Smart Maritime Council. Rob has worked in the maritime technology sector since 2005, managing editorial for a range of leading publications in the transport and logistics sector. Get in touch by email by clicking here, or on LinkedIn by clicking here.

Further Reading

News Archive